Re: password synchronization
ke, 2010-05-12 kello 16:22 +0200, Andreas B. Mundt kirjoitti:
> On Wed, May 05, 2010 at 04:41:41PM +0300, Veli-Matti Lintu wrote:
> > ma, 2010-05-03 kello 21:47 +0200, Andreas B. Mundt kirjoitti:
> > > The critical point in using kerberos is the synchronization
> > > i.e. integration of all passwords: posix, samba and kerberos.
> > We've been figuring out for a while what to do with this syncing problem
> > and we just finished smbkrb5pwd for MIT kerberos. Its implementation
> Many thanks for these links. I am currently investigating pros and
> cons of the various methods used to achive synchronized passwords.
> Do you know of any activities to get this package into mainline
We haven't looked into getting it in mainline or in OpenLDAP yet as we
are still testing it. There have been some issues in multi-realm
kdc/kadmin setups, but those should be fixed now in the Launchpad
version. We should get out tools to setup ldap+kerberos and manage users
with the overlay really soon now. I hope to be able to think about
packaging after that.
Do you see any problems with the approach used in smbkrb5pwd?