[OpenAFS] Re: mit kdc for windows auth

Jeffrey Altman jaltman@columbia.edu
Mon, 10 May 2004 21:01:07 -0400


This is a cryptographically signed message in MIME format.

--------------ms020102050008080002040707
Content-Type: multipart/alternative;
 boundary="------------020705050808030008020407"

This is a multi-part message in MIME format.
--------------020705050808030008020407
Content-Type: text/plain; charset=us-ascii; format=flowed
Content-Transfer-Encoding: 7bit

The answer is you can't do what you want.  If you use a non-MS realm
for authentication (without a Domain) you cannot use LDAP for 
authorization.
Windows requires that the authorization data be stored in the Kerberos
ticket.  This is done for you via Active Directory.

Jeffrey Altman


David Bear wrote:

>In all the reading I've done, I haven't found a way to use kerb only
>to authenticat windows 2000/xp machines.  I would really appreciate
>pointers.. My goal is to use kerberos for authentication, then ldap
>for authorization to groups.. If I have to I woundn't mind using samba
>to handle authorization groups. But that would put me back to using
>the NT 4 domain model... 
>
>
>On Mon, May 10, 2004 at 02:04:00PM -0700, Jason C. Wells wrote:
>
>>On Mon, 10 May 2004, David Bear wrote:
>>
>>
>>>I noticed in a note sent to the openafs list that you mit kdc for
>>>windows auth.  Does this mean you do not use active directory? or do
>>>you have a trust to you kdc...
>>>
>>>I'm very interested in NON-microsoft means of controlling and managing
>>>windows boxes..
>>>
>>I do not use active directory.  I do not use a trust to the KDC.  I use
>>the MIT KDC directly.  I do not have all the functionality of AD though.
>>I must have a user account on each box for example.
>>
>>I am working my way up to roaming profiles, LDAP, and other fun.
>>
>>Please post your questions to the list.
>>
>>Later,
>>Jason C. Wells
>>
>

--------------020705050808030008020407
Content-Type: text/html; charset=us-ascii
Content-Transfer-Encoding: 7bit

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
  <meta content="text/html;charset=ISO-8859-1" http-equiv="Content-Type">
  <title></title>
</head>
<body bgcolor="#ffffff" text="#000000">
<font face="Bitstream Cyberbit">The answer is you can't do what you
want.&nbsp; If you use a non-MS realm <br>
for authentication (without a Domain) you cannot use LDAP for
authorization. <br>
Windows requires that the authorization data be stored in the Kerberos <br>
ticket.&nbsp; This is done for you via Active Directory.<br>
<br>
Jeffrey Altman<br>
<br>
<br>
David Bear wrote:<br>
</font>
<blockquote cite="mid20040511005219.GV13131@asu.edu" type="cite">
  <pre wrap=""><font face="Bitstream Cyberbit">In all the reading I've done, I haven't found a way to use kerb only
to authenticat windows 2000/xp machines.  I would really appreciate
pointers.. My goal is to use kerberos for authentication, then ldap
for authorization to groups.. If I have to I woundn't mind using samba
to handle authorization groups. But that would put me back to using
the NT 4 domain model... 


On Mon, May 10, 2004 at 02:04:00PM -0700, Jason C. Wells wrote:
</font></pre>
  <blockquote type="cite">
    <pre wrap=""><font face="Bitstream Cyberbit">On Mon, 10 May 2004, David Bear wrote:

</font></pre>
    <blockquote type="cite">
      <pre wrap=""><font face="Bitstream Cyberbit">I noticed in a note sent to the openafs list that you mit kdc for
windows auth.  Does this mean you do not use active directory? or do
you have a trust to you kdc...

I'm very interested in NON-microsoft means of controlling and managing
windows boxes..
</font></pre>
    </blockquote>
    <pre wrap=""><font face="Bitstream Cyberbit">I do not use active directory.  I do not use a trust to the KDC.  I use
the MIT KDC directly.  I do not have all the functionality of AD though.
I must have a user account on each box for example.

I am working my way up to roaming profiles, LDAP, and other fun.

Please post your questions to the list.

Later,
Jason C. Wells
</font></pre>
  </blockquote>
  <pre wrap=""><!----><font face="Bitstream Cyberbit">
</font></pre>
</blockquote>
</body>
</html>

--------------020705050808030008020407--

--------------ms020102050008080002040707
Content-Type: application/x-pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIJOzCC
AvgwggJhoAMCAQICAwwjmjANBgkqhkiG9w0BAQQFADBiMQswCQYDVQQGEwJaQTElMCMGA1UE
ChMcVGhhd3RlIENvbnN1bHRpbmcgKFB0eSkgTHRkLjEsMCoGA1UEAxMjVGhhd3RlIFBlcnNv
bmFsIEZyZWVtYWlsIElzc3VpbmcgQ0EwHhcNMDQwNDE2MDIxODM0WhcNMDUwNDE2MDIxODM0
WjBGMR8wHQYDVQQDExZUaGF3dGUgRnJlZW1haWwgTWVtYmVyMSMwIQYJKoZIhvcNAQkBFhRq
YWx0bWFuQGNvbHVtYmlhLmVkdTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKyS
7eWrak81hbARkTT+lqX+uujXLK3tDmCn/6IQH9tDKYtf5A8/llZJdPYHUA9p1FH9hwk23iGY
scSkJq84FJenlWKOOqOsT6BlueWsrlKuseJCdMf9uhN28p+UnZvrcVhcLLTYfRvQT9OUw/k3
h4TzNdyAXbBJ3LnL1ySbFRaNVkq7cW/2ircAWpcyqHH4ZKstdSLbo6axsDHWRZL8yHUsI1Gz
esRSYQf2aUeUqvmGbEKEKFwbfqgfLwlBLiv1Lqib/++J3s5g3syhqWe3T8tUffmhdibUdX2W
umT2uiWl/WGEBvc1+o5k0T2JqWMNR9VgzPyk8P+iZRHl76Yb49ECAwEAAaNUMFIwDgYDVR0P
AQH/BAQDAgP4MBEGCWCGSAGG+EIBAQQEAwIFoDAfBgNVHREEGDAWgRRqYWx0bWFuQGNvbHVt
YmlhLmVkdTAMBgNVHRMBAf8EAjAAMA0GCSqGSIb3DQEBBAUAA4GBAGXYUcZvaLEqctXUsgt0
fUMFXukM3E5fpLBkk3+BbcY457WQE38ZM1AOvcYOHqB1xhJCxP1U0pSJu2Xfe9Z1M2mU4C4V
2w4sDcWkZteM9EW7VYbXzSCKCw0TKKp3Wl9TFIWFdiFwPvhOzhXUonGTdYbOvRuAXQuJdNQW
O4v2sQg1MIIC+DCCAmGgAwIBAgIDDCOaMA0GCSqGSIb3DQEBBAUAMGIxCzAJBgNVBAYTAlpB
MSUwIwYDVQQKExxUaGF3dGUgQ29uc3VsdGluZyAoUHR5KSBMdGQuMSwwKgYDVQQDEyNUaGF3
dGUgUGVyc29uYWwgRnJlZW1haWwgSXNzdWluZyBDQTAeFw0wNDA0MTYwMjE4MzRaFw0wNTA0
MTYwMjE4MzRaMEYxHzAdBgNVBAMTFlRoYXd0ZSBGcmVlbWFpbCBNZW1iZXIxIzAhBgkqhkiG
9w0BCQEWFGphbHRtYW5AY29sdW1iaWEuZWR1MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIB
CgKCAQEArJLt5atqTzWFsBGRNP6Wpf666Ncsre0OYKf/ohAf20Mpi1/kDz+WVkl09gdQD2nU
Uf2HCTbeIZixxKQmrzgUl6eVYo46o6xPoGW55ayuUq6x4kJ0x/26E3byn5Sdm+txWFwstNh9
G9BP05TD+TeHhPM13IBdsEncucvXJJsVFo1WSrtxb/aKtwBalzKocfhkqy11ItujprGwMdZF
kvzIdSwjUbN6xFJhB/ZpR5Sq+YZsQoQoXBt+qB8vCUEuK/UuqJv/74nezmDezKGpZ7dPy1R9
+aF2JtR1fZa6ZPa6JaX9YYQG9zX6jmTRPYmpYw1H1WDM/KTw/6JlEeXvphvj0QIDAQABo1Qw
UjAOBgNVHQ8BAf8EBAMCA/gwEQYJYIZIAYb4QgEBBAQDAgWgMB8GA1UdEQQYMBaBFGphbHRt
YW5AY29sdW1iaWEuZWR1MAwGA1UdEwEB/wQCMAAwDQYJKoZIhvcNAQEEBQADgYEAZdhRxm9o
sSpy1dSyC3R9QwVe6QzcTl+ksGSTf4FtxjjntZATfxkzUA69xg4eoHXGEkLE/VTSlIm7Zd97
1nUzaZTgLhXbDiwNxaRm14z0RbtVhtfNIIoLDRMoqndaX1MUhYV2IXA++E7OFdSicZN1hs69
G4BdC4l01BY7i/axCDUwggM/MIICqKADAgECAgENMA0GCSqGSIb3DQEBBQUAMIHRMQswCQYD
VQQGEwJaQTEVMBMGA1UECBMMV2VzdGVybiBDYXBlMRIwEAYDVQQHEwlDYXBlIFRvd24xGjAY
BgNVBAoTEVRoYXd0ZSBDb25zdWx0aW5nMSgwJgYDVQQLEx9DZXJ0aWZpY2F0aW9uIFNlcnZp
Y2VzIERpdmlzaW9uMSQwIgYDVQQDExtUaGF3dGUgUGVyc29uYWwgRnJlZW1haWwgQ0ExKzAp
BgkqhkiG9w0BCQEWHHBlcnNvbmFsLWZyZWVtYWlsQHRoYXd0ZS5jb20wHhcNMDMwNzE3MDAw
MDAwWhcNMTMwNzE2MjM1OTU5WjBiMQswCQYDVQQGEwJaQTElMCMGA1UEChMcVGhhd3RlIENv
bnN1bHRpbmcgKFB0eSkgTHRkLjEsMCoGA1UEAxMjVGhhd3RlIFBlcnNvbmFsIEZyZWVtYWls
IElzc3VpbmcgQ0EwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBAMSmPFVzVftOucqZWh5o
wHUEcJ3f6f+jHuy9zfVb8hp2vX8MOmHyv1HOAdTlUAow1wJjWiyJFXCO3cnwK4Vaqj9xVsuv
PAsH5/EfkTYkKhPPK9Xzgnc9A74r/rsYPge/QIACZNenprufZdHFKlSFD0gEf6e20TxhBEAe
ZBlyYLf7AgMBAAGjgZQwgZEwEgYDVR0TAQH/BAgwBgEB/wIBADBDBgNVHR8EPDA6MDigNqA0
hjJodHRwOi8vY3JsLnRoYXd0ZS5jb20vVGhhd3RlUGVyc29uYWxGcmVlbWFpbENBLmNybDAL
BgNVHQ8EBAMCAQYwKQYDVR0RBCIwIKQeMBwxGjAYBgNVBAMTEVByaXZhdGVMYWJlbDItMTM4
MA0GCSqGSIb3DQEBBQUAA4GBAEiM0VCD6gsuzA2jZqxnD3+vrL7CF6FDlpSdf0whuPg2H6ot
nzYvwPQcUCCTcDz9reFhYsPZOhl+hLGZGwDFGguCdJ4lUJRix9sncVcljd2pnDmOjCBPZV+V
2vf3h9bGCE6u9uo05RAaWzVNd+NWIXiC3CEZNd4ksdMdRv9dX2VPMYIDOzCCAzcCAQEwaTBi
MQswCQYDVQQGEwJaQTElMCMGA1UEChMcVGhhd3RlIENvbnN1bHRpbmcgKFB0eSkgTHRkLjEs
MCoGA1UEAxMjVGhhd3RlIFBlcnNvbmFsIEZyZWVtYWlsIElzc3VpbmcgQ0ECAwwjmjAJBgUr
DgMCGgUAoIIBpzAYBgkqhkiG9w0BCQMxCwYJKoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEPFw0w
NDA1MTEwMTAxMDdaMCMGCSqGSIb3DQEJBDEWBBS/UcLhOqjoWVKv6qyYK1Fomz3r0TBSBgkq
hkiG9w0BCQ8xRTBDMAoGCCqGSIb3DQMHMA4GCCqGSIb3DQMCAgIAgDANBggqhkiG9w0DAgIB
QDAHBgUrDgMCBzANBggqhkiG9w0DAgIBKDB4BgkrBgEEAYI3EAQxazBpMGIxCzAJBgNVBAYT
AlpBMSUwIwYDVQQKExxUaGF3dGUgQ29uc3VsdGluZyAoUHR5KSBMdGQuMSwwKgYDVQQDEyNU
aGF3dGUgUGVyc29uYWwgRnJlZW1haWwgSXNzdWluZyBDQQIDDCOaMHoGCyqGSIb3DQEJEAIL
MWugaTBiMQswCQYDVQQGEwJaQTElMCMGA1UEChMcVGhhd3RlIENvbnN1bHRpbmcgKFB0eSkg
THRkLjEsMCoGA1UEAxMjVGhhd3RlIFBlcnNvbmFsIEZyZWVtYWlsIElzc3VpbmcgQ0ECAwwj
mjANBgkqhkiG9w0BAQEFAASCAQAT7hi3nfdu/6v7n9znsXdD0cxXwPqwApvAyxDDhr3feAeg
JkkjMHMdUXErvPhpzqOyXmfmQnezSMEmPd5Y1UuvXTXGO22+iaLeu7MtE2rnODEiaoHGj0Xc
Ko8/TmjEIUjs9R/lWGY7P7Zq3v2uDYDAWzhqeG0o9WWWOh8QU0Ryc3VNRxx0Kv8BrpyiEuud
pkUdXsdFQNtMIz6fa6iQJC1Jh2qPgzoqZjP870FMvBavbKx08vRryqmgyeuX7gOnakf1Tavm
P30DsngmAajyTPP2py6uVt/uW0Yuj/3ZSnA/b5ISVXrRAi1xCK/7I7nUq0pJo7NjVfbq6Bdj
Rvlrvio+AAAAAAAA
--------------ms020102050008080002040707--