Re: Debian-LAN: installing a complete network environment

Nico Kadel-Garcia <[email protected]> Sat, 5 Oct 2013 00:59:57 -0400
Newsgroups gmane.linux.debian.user,gmane.linux.debian.fai,gmane.linux.debian.devel.custom,gmane.linux.debian.science,gmane.linux.debian.devel.nonprofit
Message-ID <CAOCN9rwiJXqfXuS2sPFCUa4ZoPSoCnVsydWrB+mGUS0tAQe76Q@mail.gmail.com>
--001a11c3f4006296a604e7f74a8b
Content-Type: text/plain; charset=ISO-8859-1

I've been working with both Kerberos and Samba for 20 years. Writing "Yet
Another Authentication Management Tool(tm)" sounds unappealing, since there
are so many well established and tested ones. I'm actually curious what you
found inadequate about Samba, especially if you used the 4.0.x releases
which have stabilized the LDAP/Kerberos interactions in effective
cross-platform ways.

Now, if our friends over in Debian wanted to improve an underlying Kerberos
tool that's used for both Debian and Scientific Linux and other red Hat
based systems, I'd look at the "authconfig" tool and its /etc/pam.d
interactions, which are very flexible and not well managed. *Try* using
"authconfig" to delete the default enabled "example.com" Kerberos domain
from /etc/krb5.conf, or to manage integraiton with upstream Kerberos
domains, I dare you, Or try preventing "authconfig" from resetting values
which you didn't put in the command line, or getting it to load from an
actual configuration file, or to enable local password expiration. It gets
crazy out there!

But that's not a Kerberos problem, that's an authconfig and pam.d managemnt
problem.


On Fri, Oct 4, 2013 at 11:13 PM, Darko Gavrilovic <[email protected]>wrote:


> To each his own. I actually like the post and his project idea. Also,
> claiming that Samba is the be all and end all to all enterprise client
> scenarios out there is a little over stating it. On more a few times
> have we have to drop Samba as it proved to be inadequate for the
> situation.
>

--001a11c3f4006296a604e7f74a8b
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div><div>I&#39;ve been working with both Kerberos and Sam=
ba for 20 years. Writing &quot;Yet Another Authentication Management Tool(t=
m)&quot; sounds unappealing, since there are so many well established and t=
ested ones. I&#39;m actually curious what you found inadequate about Samba,=
 especially if you used the 4.0.x releases which have stabilized the LDAP/K=
erberos interactions in effective cross-platform ways.<br>
<br></div>Now, if our friends over in Debian wanted to improve an underlyin=
g Kerberos tool that&#39;s used for both Debian and Scientific Linux and ot=
her red Hat based systems, I&#39;d look at the &quot;authconfig&quot; tool =
and its /etc/pam.d interactions, which are very flexible and not well manag=
ed. *Try* using &quot;authconfig&quot; to delete the default enabled &quot;=
<a href=3D"http://example.com">example.com</a>&quot; Kerberos domain from /=
etc/krb5.conf, or to manage integraiton with upstream Kerberos domains, I d=
are you, Or try preventing &quot;authconfig&quot; from resetting values whi=
ch you didn&#39;t put in the command line, or getting it to load from an ac=
tual configuration file, or to enable local password expiration. It gets cr=
azy out there!<br>
<br></div>But that&#39;s not a Kerberos problem, that&#39;s an authconfig a=
nd pam.d managemnt problem.<br><div><div><div><div class=3D"gmail_extra"><b=
r><br><div class=3D"gmail_quote">On Fri, Oct 4, 2013 at 11:13 PM, Darko Gav=
rilovic <span dir=3D"ltr">&lt;<a href=3D"mailto:[email protected]" tar=
get=3D"_blank">[email protected]</a>&gt;</span> wrote:<br>
<div>=A0</div><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;=
border-left:1px #ccc solid;padding-left:1ex">
To each his own. I actually like the post and his project idea. Also,<br>
claiming that Samba is the be all and end all to all enterprise client<br>
scenarios out there is a little over stating it. On more a few times<br>
have we have to drop Samba as it proved to be inadequate for the<br>
situation.<br>
</blockquote></div><br></div></div></div></div></div>

--001a11c3f4006296a604e7f74a8b--