Operating System - HP-UX
1755363 Members
3894 Online
108832 Solutions
New Discussion

Re: Kerberos authentication vs LDAP-UX

 
Ramesh Donti
Frequent Advisor

Kerberos authentication vs LDAP-UX

Hi,
I am planning to implement kerberos authentication in all HP-UX 11.x servers againt WIN2K ADS.
We don't have unique uidnumbers for users across all the unix servers. So, I am planning to user kerberos authentication and still use the /etc/passwd file for passwd attributes (eg:shell, home directory, UID, GID, etc).

I can implement the same using LDAP-UX and scale it later to use it for central account management in the future when we are ready with uniqe UID/GID's. I know that LDAP-UX sends passwords in clear text to WIN2k ADS for authentication.

Now the question is..
Are there any issues in using kerberos authentication (using PAM) against WIN2K ADS?

Are there any issues in using Kerberos for authentication and LDAP for account management? --> This way, I can start with Kerberos authentication and later use LDAP-UX integration for account management.
Always Keep Smiling
1 REPLY 1
Steven E. Protter
Exalted Contributor

Re: Kerberos authentication vs LDAP-UX

There are significant issues, but it should at least be possible to integrate LDAP/UX with a Windows 2000 ADS environment. Here are some docuemnts.

http://docs.hp.com/hpux/onlinedocs/internet/ADSLDUX.pdf

http://docs.hp.com/hpux/onlinedocs/internet/intpaper.pdf

http://docs.hp.com/cgi-bin/otsearch/getfile?id=/hpux/onlinedocs/internet/uxint.html&searchterms=Windows%7c2000%7cIntegration%7cLDAP&queryid=20031020-231527

These will get you started.

SEP
Steven E Protter
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com