Re: Samba 4 with separate kdcen?

Andrew Bartlett <[email protected]>
Newsgroups gmane.comp.encryption.kerberos.heimdal.general
Message-ID <1323839840.2216.15.camel@obed>
On Thu, 2011-11-17 at 12:17 +0100, Harald Barth wrote:
> > Its not really possible today since the samba database provides the
> > keys to the KDC and its the other dce-rpc services that write the
> > keys and passwords into the database.
> 
> That's kind of a pity. Just a thought: What about propagation (iprop)
> in some direction?

I recently added the ability to load our hdb layer as a plugin for
Heimdal - hdb_samba4.so.  But this doesn't really help - if you read the
keys out, then any KDC using it would not do proper PAC processing etc.
If you want a migration from Samba or AD to traditional Heimdal then I
guess this helps, but it would be one way, and no longer be AD.  Inbound
migration was actually the goal, but this hasn't been done yet.

Similarly, you must run our kpasswd, and all the AD components are very
closely tied together, so separating out the components makes no real
sense (and does not help with the security isolation you might have been
hoping for).

I know the monolithic AD thing bothers folks, particularly those who
have an existing infrastructure, but sadly the architecture is dictated
by what the Windows clients expect, and they expect everything in one
place. 

Andrew Bartlett

-- 
Andrew Bartlett                                http://samba.org/~abartlet/
Authentication Developer, Samba Team           http://samba.org
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.