Re: SASL/Kerberos5 question

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



koniczynek wrote:
Hello,
I'm fairly new to the FDS (one week maybe). Earlier I've been using
OpenLDAP and now I want to migrate from OL to FDS. Everything looks
great (schema conversion and ldif transfer) but I have one problem. Old
setup was constructed more or less that the passwords weren't stored in
LDAP but in Kerberos and in 'userPassword' field in clear text was
'uid@xxxxxxxxx'
Now when using FDS I can't find any configuration option, that would
make it possible to use Kerberos for storing passwords and still to use
FDS to authenticate user. Maybe SASL Mappings are for that and you only
have to configure them right.
Right. For clients that can do SASL/GSSAPI BIND (i.e. Kerberos), you just need to configure the SASL Mapping to find the user's DN based on the Kerberos principal.

For clients that cannot use SASL but must use simple username/password bind, you can use the PAM passthrough plug-in.
Is there anyone who knows how to do it?
Thanks in advance.

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature

--
Fedora-directory-users mailing list
Fedora-directory-users@xxxxxxxxxx
https://www.redhat.com/mailman/listinfo/fedora-directory-users

[Index of Archives]     [Fedora Directory Users]     [Fedora Directory Devel]     [Fedora Announce]     [Fedora Legacy Announce]     [Kernel]     [Fedora Legacy]     [Share Photos]     [Fedora Desktop]     [PAM]     [Red Hat Watch]     [Red Hat Development]     [Big List of Linux Books]     [Gimp]     [Yosemite News]

  Powered by Linux