1 |
Robert Larson wrote: |
2 |
> I have a system setup using OpenLDAP combined with Cyrus-SASL and Heimdal |
3 |
> kerberos. I have tied samba into it, and will eventually setup samba-tng as |
4 |
> an authentication head for samba. With samba, I may use NTLM authentication |
5 |
> to include more options for SSO. |
6 |
Why do you need samba-tng? |
7 |
|
8 |
> |
9 |
> The way my setup works is samba has access to use LDAP for accounting and |
10 |
> simple binds (over SSL/TLS). Unfortunately, samba doesn't support kerberos |
11 |
> based authentication "(yet)". |
12 |
To be a bit more specific, samba(3) cannot hand tickets to windows |
13 |
clients (yet) ;) |
14 |
|
15 |
In this setup, the users sign on to their |
16 |
> desktop, and the same login is used to access network shares without prompt |
17 |
> for another password (this happens by default on most windows desktops) using |
18 |
> NTLM. |
19 |
So this is a normal windows domain with a samba PDC? |
20 |
|
21 |
> |
22 |
> Various applications using SPEGNO/GSSAPI can provide autologin functionality |
23 |
> using this same login if we chose to implement something to that effect, but |
24 |
> that depends entirely on the applications we might use. For example, IE and |
25 |
> Firefox support SPEGNO/GSSAPI, so enabled web applications may use this to |
26 |
> authenticate the client without additional credentials. |
27 |
As long as you don't get tickets for your (windows) clients, this is out |
28 |
of scope. |
29 |
|
30 |
cheers |
31 |
Paul |
32 |
|
33 |
BTW: Does anyone know a site tracking security flaws for kernel 2.6 and |
34 |
the relevant fixes? |
35 |
|
36 |
|
37 |
|
38 |
-- |
39 |
gentoo-server@g.o mailing list |