[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Questions about LDAP, Heimdal and 2003 Server




On Jan 31, 2008, at 8:53 AM, Timothy J Miller wrote:

> On Jan 30, 2008, at 8:54 PM, Henry B. Hotz wrote:
>
>> You can deploy a Windows Domain with a cross-realm trust to  
>> Kerberos, but the LDAP information for Windows will be on the  
>> Domain controller.
>>
>> You might be able to replace your W2K3 server with a Samba 4  
>> server (which bundles a version of Heimdal), but this isn't the  
>> place to ask about that.
>
> Also, recall that Windows services require authorization-data to be  
> populated in the ticket, something that most KDCs don't do.
>
> -- Tim

The authz-data is populated by the DC in the service tickets in the  
cross-realm case.  That's why you need to buy a license based on the  
number of non-Windows Kerberos entries.  (No, there's no authz-data  
in the original tgt, or the cross-realm tgt, but the service never  
sees those.)

In the Samba 4 case I believe they have implemented extensions for  
the authz-data in their version of Heimdal.

------------------------------------------------------------------------
The opinions expressed in this message are mine,
not those of Caltech, JPL, NASA, or the US Government.
Henry.B.Hotz@jpl.nasa.gov, or hbhotz@oxy.edu