Gentoo Archives: gentoo-server

From: Steven Williamson <steven43126@×××××.com>
To: gentoo-server@l.g.o
Subject: Re: [gentoo-server] manging windows
Date: Fri, 17 Feb 2006 19:23:21
Message-Id: 43F621B5.8000208@gmail.com
In Reply to: Re: [gentoo-server] manging windows by Georges Toth
1 Georges Toth wrote:
2 > Hi,
3 >
4 > Thanks for that description and links.
5 > I guess I will play with SSO sometime soon :-).
6 >
7 >
8 >> I have a system setup using OpenLDAP combined with Cyrus-SASL and Heimdal
9 >> kerberos. I have tied samba into it, and will eventually setup samba-tng
10 >> as an authentication head for samba. With samba, I may use NTLM
11 >> authentication to include more options for SSO.
12 >>
13 >> The way my setup works is samba has access to use LDAP for accounting and
14 >> simple binds (over SSL/TLS). Unfortunately, samba doesn't support kerberos
15 >> based authentication "(yet)". In this setup, the users sign on to their
16 >> desktop, and the same login is used to access network shares without prompt
17 >> for another password (this happens by default on most windows desktops)
18 >> using NTLM.
19 >>
20 >> Various applications using SPEGNO/GSSAPI can provide autologin
21 >> functionality using this same login if we chose to implement something to
22 >> that effect, but that depends entirely on the applications we might use.
23 >> For example, IE and Firefox support SPEGNO/GSSAPI, so enabled web
24 >> applications may use this to authenticate the client without additional
25 >> credentials. Another example may be squid, as it provides NTLM
26 >> authentication mechanisms.
27 >>
28 >> Even if kerberos or NTLM authentication isn't possible I can still
29 >> integrate other services such as pam, Jabber, samba, AND Outlook
30 >> addressbook into LDAP using SSL/TLS and simple binds. This makes my setup
31 >> more of a flexible centralized authentication system, than simply an SSO
32 >> server. In the end, it all comes down to what auth mechanisms the apps
33 >> you're using support in your ability to perform SSO.
34 >>
35 >> I have referenced a lot of these links for my setup. With them, there
36 >> should be enough information to create a setup truly exact to your needs:
37 >>
38 >> Centralized authentication howtos:
39 >> http://www.openinput.com/auth-howto/
40 >> http://www.bayour.com/LDAPv3-HOWTO.html
41 >>
42 >> Samba (TNG) and authentication:
43 >> http://www.mami.net/univr/tng-ldap/howto/
44 >> http://www.deschner.de/gd/dual_samba.html
45 >> http://www.mami.net/univr/tng-ldap/howto/sambausermapping.html
46 >> http://www.samba-tng.org/docs/tng-arch/tng-arch.html
47 >>
48 >> Other misc resources:
49 >> http://acctsync.sourceforge.net/
50 >> http://www.cmf.nrl.navy.mil/CCS/people/kenh/kerberos-faq.html
51 >> "Making the big boys play nice..." (one of my favorites)
52 >> http://pgina.xpasystems.com/?page_id=3
53 >>
54 >>
55 >> In a sense, I have been trying to work toward SSO for a while. There are
56 >> still many things that require a password on our network though. By
57 >> centralizing authentication, I feel that I am one step closer. Anyway, I
58 >> hope this helps.
59 >>
60 >> Regards,
61 >>
62 >>
63 >> Robert Larson
64 >>
65 >
66 >
67 Many thanks for the links a great help. I will be experimenting with a
68 few setups, if I manage something useful i'll let you know.
69
70 Steve.
71 --
72 gentoo-server@g.o mailing list