ldap vs kerberos authentication for idpv3

Paul B. Henson henson at cpp.edu
Wed Feb 10 14:58:21 EST 2016


> From: Cantor, Scott
> Sent: Wednesday, February 10, 2016 11:48 AM
> 
> If the KDC check fails, it won't let you login, but that won't suddenly stop
> working in production. Rod tried to make it work with AD and couldn't, and I
> had no quick way to try it and lots of more important things to get done for
> the release, so I just tested MIT and left it there.

Cool; we use Kerberos, not Merberos ;), so we should be good to go.

> I'm not aware of any, but the new native flow essentially reuses the JAAS
> module to do TGT acquisition as of 3.2, so in effect they're one and the same
> if you skip the KDC check now. The JAAS module is certainly used at scale
> now.

Great, thanks…

--
Paul B. Henson  |  (909) 979-6361  |  http://www.cpp.edu/~henson/
Operating Systems and Network Analyst  |  henson at cpp.edu
California State Polytechnic University  |  Pomona CA 91768




More information about the users mailing list