ldap vs kerberos authentication for idpv3
Paul B. Henson
henson at cpp.edu
Wed Feb 10 14:58:21 EST 2016
> From: Cantor, Scott
> Sent: Wednesday, February 10, 2016 11:48 AM
>
> If the KDC check fails, it won't let you login, but that won't suddenly stop
> working in production. Rod tried to make it work with AD and couldn't, and I
> had no quick way to try it and lots of more important things to get done for
> the release, so I just tested MIT and left it there.
Cool; we use Kerberos, not Merberos ;), so we should be good to go.
> I'm not aware of any, but the new native flow essentially reuses the JAAS
> module to do TGT acquisition as of 3.2, so in effect they're one and the same
> if you skip the KDC check now. The JAAS module is certainly used at scale
> now.
Great, thanks…
--
Paul B. Henson | (909) 979-6361 | http://www.cpp.edu/~henson/
Operating Systems and Network Analyst | henson at cpp.edu
California State Polytechnic University | Pomona CA 91768
More information about the users
mailing list