[email protected] (Bill Johnson) writes:
> We are trying to sync up (and expand) our mainframe passwords to match
> what the user has in active directory. So far so good. The problem is
> when the AD password is longer than 8 characters. Anyone shed some
> light as to how this can be handled?

active directory trivia ... based on kerberos
http://technet.microsoft.com/en-us/library/bb742516.aspx

original implementation for active directory was done under contract by
one of the companies providing commercial kerberos products.

over the years ... active directory drifted from kerberos base ...  some
discussion on interoperability
http://www.centrify.com/blogs/tomkemp/integrating_mit_kerberos_with_active_directory.asp

kerberos
http://en.wikipedia.org/wiki/Kerberos_%28protocol%29

part pf MIT's project athena
http://en.wikipedia.org/wiki/Project_Athena

with joint funding by DEC and IBM to the tune of $25M each. started in
the early day's of IBM's ACIS and getting much more active with
universities.  we use to drop by Project Athena periodically as part of
corporate review of what was going on (was there for early discussions
on how multiple relm interoperability would work).

article about kerberos on mainframe (seamless interoperability with
RACF)
http://www.mainframezone.com/it-management/kerberos-on-z-os-teaching-an-old-dog-new-tricks/P2

much later at presentation for a SAML product multi-relm deployment
(coalition forces) ... and happened to observe/mention that SAML
messages & message flows look nearly the same as Kerberos (with the
format of the message contents being XML)
http://en.wikipedia.org/wiki/SAML_2.0

the speaker was somewhat defensive saying that there are only a limited
number of ways to do multi-relm implementation.

-- 
virtualization experience starting Jan1968, online at home since Mar1970

----------------------------------------------------------------------
For IBM-MAIN subscribe / signoff / archive access instructions,
send email to [email protected] with the message: GET IBM-MAIN INFO
Search the archives at http://bama.ua.edu/archives/ibm-main.html

Reply via email to