| |||
| [Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] |
Henry,
The PAC format is a Microsoft propriatory standard that they have documented for vendors to use if they wish. If Microsoft decide to change this, they can - they will then inform all MSDN members that changes have been made.
To implement your proposal - each KDC would have to construct that PAC field and place this into the appropriate tickets. The KDC would also have to manage principals such as ldap/host.name@REALM and cifs/server.name@REALM. The additional service principals would need to be created when a workstation becomes a member of a domain etc. I am sure there are many other complex implications here. Effectively what you are asking for is a non-MS kdc that is usable instead of MS AD for workstation user logon ?
One big issue, IMHO - What do you think Microsoft would think if it was possible to use a UNIX server with an LDAP server instead of Active Directory ? They would clearly not like this and they might decide to change licensing of PAC data (or some other action) to stop the UNIX KDC vendors from being able to offer this functionality ... Do you agree ?
Cheers, Tim.
-----Original Message-----
From: Henry B. Hotz [<mailto:email@hidden>mailto:email@hidden]
Sent: 11 February 2004 01:29
To: Tim Alsop; email@hidden; email@hidden; email@hidden
Cc: Dj Byrne
Subject: RE: Kerberos Feature Request
I want to enable that.
I'm suggesting that it would be nice if there were a MIT-independent and KTH-independent (and CyberSafe-independent ;-) mechanism that allowed you to do that. Given a KDC-neutral enabling mechanism I expect that an open-source project or 10 would spontaneously form to bridge the gap between the conformant KDCs and the LDAP server of your choice (including true blue AD).
I'd be happy if the agreement/standard/whatever just said that you do an ldap query for the "pac" attribute from the unique ID that matches the principal, with the obvious REALM to DC= translation.
Jeffrey Altman objects that I want an API, not an RFC, so IETF shouldn't be involved, but I think the example I just gave would be an RFC. I'm trying to limit my care-about's though. I just want a general way to make use of the feature, which is currently pretty inaccessible.
At 11:41 PM +0000 2/10/04, Tim Alsop wrote:Henry,
Are you proposing that the non-Microsoft KDC issues tickets containing
PAC data and gets the group membership information from the Active
Directory using LDAP ?
Thanks, Tim.
-----Original Message-----
From: Henry B. Hotz
[<<mailto:email@hidden>mailto:email@hidden><mailto:email@hidden>mailto:email@hidden]
Sent: 10 February 2004 18:27
To: email@hidden; Tim Alsop; email@hidden;
email@hidden
Cc: Dj Byrne
Subject: Kerberos Feature Request
I probably should send this to the IETF group, but I'm not on their
mailing lists. (Apologies if the cross-posting causes problems.) It
would be *nice* if all Kerberos distributions added this feature the
same way.
One of the famous things that Microsoft did in their AD Kerberos
implementation is added authorization data to the (supposedly
optional) PAC field that is necessary when using certain other
Microsoft functionality. AFAIK all of the information added is also
contained in the LDAP directory that AD also provides.
I do not think it makes any sense for a (non-Microsoft) Kerberos server
to directly maintain this data. Rather it should have a mechanism for
acquiring the data from an external source, such as an LDAP directory.
My request is that the Kerberos community agree on a standard external
interface to get that data. If the interface itself were standardized
then the work of connecting that interface to the appropriate AD
attributes could be done independently of any Kerberos server, and
could be updated as Microsoft updates their schema independent of
Kerberos versions. It would also make the use of PAC data in
non-Microsoft environments much easier to consider.
--
The opinions expressed in this message are mine, not those of Caltech,
JPL, NASA, or the US Government.
email@hidden, or email@hidden
--
The opinions expressed in this message are mine, not those of Caltech, JPL, NASA, or the US Government.
email@hidden, or email@hidden
| Home | Archives | FAQ | Terms/Conditions | Contact | RSS | Lists | About |
Visit the Apple Store online or at retail locations.
1-800-MY-APPLE
Contact Apple | Terms of Use | Privacy Policy
Copyright © 2007 Apple Inc. All rights reserved.