Re: LDAPv3: The OpenLDAP/Kerberos/SASL soup (was Kerberos andDIGEST-MD5)

--On Thursday, July 29, 2004 11:52 PM +0200 Andreas Schuldei <andreas@schuldei.org> wrote:

* Tony Earnshaw (tonye@billy.demon.nl) [040729 22:20]:
Because this one chose Heimdal?

can someone please comment on the MIT vs Heimdal question? i hear Heimdal is able to distribute principals and keys over ldap.

We have a network with differnt services (imap, samba, soon AFS,
ldap, terminal servers, ...) which would need own kerberos keys

Using Heimdal and ldap would solve our distribution problem.
But people tell me that this idea is against the spirit of
kerberos. (An alternative idea for MIT Kerberos would be ssh keys
without passphrases for every server and automatic distribution
over ssh.)

could someone comment, and tell me how they solved this problem?

We wrote our own utility that downloads the keys over an encrypted channel to the target system. It validates the calls using the user's Kerberos principal. It allows for multiple people to be on the ACL for a keytab, and it allows for multiple groups (which can contain multiple people) to be on the ACL for a keytab.


