ldap vs kerberos authentication for idpv3

Paul B. Henson henson at cpp.edu
Wed Feb 10 14:21:42 EST 2016


> From: Cantor, Scott
> Sent: Tuesday, February 09, 2016 4:13 PM
> 
> Clarifying, V3 includes native Kerberos, separate from JAAS. Kerberos and
> LDAP can both be used via native back-ends or via JAAS.

Which is currently considered the preferred method?

Based on the wiki:

"The 3.2 release will include the additional capability to prevent a rogue KDC from spoofing responses by validating its knowledge of a service principal key configured locally in a keytab file. At that point, it will be strongly recommended that this method be used in place of the JAAS module, which lacks this feature."

With the release of 3.2 it would seem to be the new native mechanism; however, that does not necessarily jibe with the comment you made in your previous email "The latest version has a very poorly tested rewrite that should support service accounts for KDC verification", as "poorly tested"/"should support" and "strongly recommended" typically don't go together ;).

Which one are you using in production :)?

Thanks…


--
Paul B. Henson  |  (909) 979-6361  |  http://www.cpp.edu/~henson/
Operating Systems and Network Analyst  |  henson at cpp.edu
California State Polytechnic University  |  Pomona CA 91768




More information about the users mailing list