[svlug] Need help with an argument.

Luke S Crawford lsc at prgmr.com
Fri Feb 13 18:36:41 PST 2009


James Sparenberg <james at linuxrebel.org> writes:
> My thoughts on this would be if one uses Kerberos I might as well go 
> with Samba and authenticate to the AD. 

If you trust the people running your AD, you can do that.   I haven't done
it, but I believe the current LDAP pam modules support authenticating from
active directory.   It would certainly be better than YP from a security
perspective.   

> Not to mention the problem of 
> disconnected data centers.  (Earthquake in CA so corp is down and Data 
> Centers need to float on their own.)

you would, of course, need to put a secondary kerberos server in every 
data center.  

You would have this same problem with YP/Nis, AD, and every other centralized
authentication system.   




More information about the svlug mailing list