LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Red Hat
User Name
Password
Red Hat This forum is for the discussion of Red Hat Linux.

Notices


Reply
  Search this Thread
Old 04-21-2011, 07:18 AM   #1
wilslm
LQ Newbie
 
Registered: Apr 2011
Posts: 17

Rep: Reputation: 0
PAM LDAP: Kerberos vs SSL (LDAP SSL)


Guys, I am confused with the concept of Kerberos and LDAP SSL. I am in the midst of integrating my Unix box with the Active Directory hence the use of PAM_LDAP method.

I understand that since it's non-secure transmission hence We use Kerberos to authenticate. If we already used kerberos to authenticate i.e. it means that the username/password is not transmitted in clear text.

Why we still need LDAP SSL? What is the benefit?
 
Old 04-21-2011, 02:25 PM   #2
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
The two certainly don't clash at all. Kerberos is only for authentication whilst ldap can be used for authentication , authorization and information. So even if you are not authenticating with it there is still plenty of data worth protecting.

Note though that kerberos doesn't ever send your password anywhere, only tickets encoded with it. And leap over SSL on 636 is largely obsolete in preference of using starttls on 389.
 
Old 04-22-2011, 08:07 AM   #3
wilslm
LQ Newbie
 
Registered: Apr 2011
Posts: 17

Original Poster
Rep: Reputation: 0
acid = thanks for the info.

However in my case since PAM_LDAP Kerberos is used for authentication only, there are no extra benefit of having SSL enabled? since most of the query would be authentication.

Am I correct to say this? or there is hidden benefit of having SSL enabled? I can appreciate if LDAP is being used to store say employee information and the client requires to retrieve the information from the LDAP often.
 
Old 04-22-2011, 08:50 AM   #4
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
Wtf? If you're only using "ldap and kerberos " for authentication then you aren't surely using ldap at all. Otherwise my above answer stands and encryption is always a responsible thing to use.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
nrpe ldap and ssl scottrych Linux - Server 3 02-10-2010 12:33 AM
LDAP SSL and Non-SSL port open? your_shadow03 Linux - Newbie 3 01-14-2010 05:57 PM
[SOLVED] LDAP with SSL sbapotikar Red Hat 4 11-16-2009 11:21 PM
ldap does not run with SSL mesh2005 Linux - Networking 2 11-27-2005 02:53 AM
Active Directory, Kerberos, LDAP, PAM, and nsswitch PenguinPwrdBox Linux - Security 1 06-04-2005 09:56 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Red Hat

All times are GMT -5. The time now is 07:28 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration