Re: Samba 4 with separate kdcen?
Andrew Bartlett <[email protected]>
| Newsgroups | gmane.comp.encryption.kerberos.heimdal.general |
|---|---|
| Message-ID | <1323839840.2216.15.camel@obed> |
On Thu, 2011-11-17 at 12:17 +0100, Harald Barth wrote: > > Its not really possible today since the samba database provides the > > keys to the KDC and its the other dce-rpc services that write the > > keys and passwords into the database. > > That's kind of a pity. Just a thought: What about propagation (iprop) > in some direction? I recently added the ability to load our hdb layer as a plugin for Heimdal - hdb_samba4.so. But this doesn't really help - if you read the keys out, then any KDC using it would not do proper PAC processing etc. If you want a migration from Samba or AD to traditional Heimdal then I guess this helps, but it would be one way, and no longer be AD. Inbound migration was actually the goal, but this hasn't been done yet. Similarly, you must run our kpasswd, and all the AD components are very closely tied together, so separating out the components makes no real sense (and does not help with the security isolation you might have been hoping for). I know the monolithic AD thing bothers folks, particularly those who have an existing infrastructure, but sadly the architecture is dictated by what the Windows clients expect, and they expect everything in one place. Andrew Bartlett -- Andrew Bartlett http://samba.org/~abartlet/ Authentication Developer, Samba Team http://samba.org