LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-15-2009, 09:07 AM   #1
geek.ksa
Member
 
Registered: Jan 2009
Location: Dhahran, Saudi Arabia
Distribution: RHEL 5
Posts: 42

Rep: Reputation: 17
Linux LDAP vs. Kerberos Authentication with Microsoft ActiveDirectory


Hello all,,

i just wanted to consult you on which is better for authenticating Linux clients against Active Directory. LDAP or Kerberos agents??

let's discuss that in terms of pros and cons.

After some research and experimenting, I've come to the following:

Kerberos:
========
pros: 1) easy to set up 2) Encrypted authentication by default.
cons: hard-coding KDCs to bind to. This is a problem if all KDCs go down.


LDAP:
====
pros: N/A
cons: 1) requires server SSL certificate installed on clients in order to provide encrypted authentication.


Do you guys agree with this or have comments/advices?

Thanks in advance,
 
Old 11-15-2009, 12:43 PM   #2
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
Well you've got a bit of a gap here in that kerberos is ONLY for authentication, whereas LDAP will do both authentication AND user information. If you're going to use as the user infomation repository and access it via LDAP, then you'll have already done the "cons" work anyway. Where else would your users come from? Getting your own SSL certs really isn't exactly tricky either, and more self-reliant. One of the main benefits of kerberos is that it leads to the possibility of generic single sign on, which LDAP doesn't, as it only takes you as far as a generic one-shot credential check. Whilst it's simple to set up it can be confusing debugging KRB5 ticket statuses and such - per login LDAP worked or it didn't.
 
Old 11-16-2009, 04:38 AM   #3
geek.ksa
Member
 
Registered: Jan 2009
Location: Dhahran, Saudi Arabia
Distribution: RHEL 5
Posts: 42

Original Poster
Rep: Reputation: 17
Thanks Acid,

You did point out something I missed, which Kerberos SSO. That's a pro over LDAP authentication.

Thanks,
 
Old 11-22-2009, 03:35 PM   #4
sundialsvcs
LQ Guru
 
Registered: Feb 2004
Location: SE Tennessee, USA
Distribution: Gentoo, LFS
Posts: 10,659
Blog Entries: 4

Rep: Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941
Most importantly, choose one system and use it corporation-wide.

These kinds of things are never "either/or decisions," where any sort of "bright-line rule" applies.
 
Old 11-22-2009, 04:29 PM   #5
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
kerberos is easy to set up. but it can be a right bugger after that. I'm studying for my RHCA exams, and can't for the life of me work out why kpropd isn't working. DAMN YOU KERBEROS!!!
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
CentOS 5.2 LDAP/kerberos authentication fails against Active Directory ccaum Linux - Server 14 03-24-2010 11:15 AM
Kerberos, LDAP, THEN Local authentication? cckid Linux - Server 2 10-20-2009 01:41 PM
Linux LDAP Authentication? LinuxCowboy03 Linux - Networking 5 02-13-2009 02:59 PM
HOW TO: SUSE Linux Enterprise Desktop SLED10 LDAP / Kerberos Authentication to Active Directory / Windows Server 2003 R2 Shannon_VanWagner LinuxAnswers Discussion 2 06-13-2007 09:29 AM
HOW TO: SUSE Linux Enterprise Desktop SLED10 LDAP / Kerberos Authentication to Active Directory / Windows Server 2003 R2 Shannon_VanWagner LinuxAnswers Discussion 0 03-23-2007 02:22 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:03 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration