[Freeipa-users] Keberos and LDAP password

2014-01-13 Thread Bob
I'm very new to IPA. I run a ODSEE and I need to add in krb5. ODSEE allows
us to store the KRB5 data in ldap, but there is no easy means of keeping
the LDAP and Kerberos password in sync for a given account.

I understand that IPA supplies Kerberos services. But is the krb5 password
the same password that a LDAP bind would use. Meaning I have many
applications that can not use Kerberos, but can use LDAP. Can these
applications use IPA and expect that a given user account will have the
LDAP password kept in sync with the krb5 password?

thanks,

Bob
___
Freeipa-users mailing list
Freeipa-users@redhat.com
https://www.redhat.com/mailman/listinfo/freeipa-users

Re: [Freeipa-users] Keberos and LDAP password

2014-01-13 Thread Christian Hernandez
From what I understand I use currently...

You can use just LDAP...I'm currently using LDAP/KRB where
supported...and just straight LDAP on applications that don't support KRB


Thank you,

Christian Hernandez
1225 Los Angeles Street
Glendale, CA 91204
Phone: 877-782-2737 ext. 4566
Fax: 818-265-3152
christi...@4over.com mailto:christi...@4over.com
www.4over.com http://www.4over.com


On Mon, Jan 13, 2014 at 2:04 PM, Bob harv...@gmail.com wrote:

 I'm very new to IPA. I run a ODSEE and I need to add in krb5. ODSEE allows
 us to store the KRB5 data in ldap, but there is no easy means of keeping
 the LDAP and Kerberos password in sync for a given account.

 I understand that IPA supplies Kerberos services. But is the krb5 password
 the same password that a LDAP bind would use. Meaning I have many
 applications that can not use Kerberos, but can use LDAP. Can these
 applications use IPA and expect that a given user account will have the
 LDAP password kept in sync with the krb5 password?

 thanks,

 Bob

 ___
 Freeipa-users mailing list
 Freeipa-users@redhat.com
 https://www.redhat.com/mailman/listinfo/freeipa-users

___
Freeipa-users mailing list
Freeipa-users@redhat.com
https://www.redhat.com/mailman/listinfo/freeipa-users

Re: [Freeipa-users] Keberos and LDAP password

2014-01-13 Thread Dmitri Pal
On 01/13/2014 05:04 PM, Bob wrote:
 I'm very new to IPA. I run a ODSEE and I need to add in krb5. ODSEE
 allows us to store the KRB5 data in ldap, but there is no easy means
 of keeping the LDAP and Kerberos password in sync for a given account.

 I understand that IPA supplies Kerberos services. But is the krb5
 password the same password that a LDAP bind would use. Meaning I have
 many applications that can not use Kerberos, but can use LDAP. Can
 these applications use IPA and expect that a given user account will
 have the LDAP password kept in sync with the krb5 password?

Yes. It is the same. You can use IPA with Kerberos and/or LDAP clients.


 thanks,

 Bob


 ___
 Freeipa-users mailing list
 Freeipa-users@redhat.com
 https://www.redhat.com/mailman/listinfo/freeipa-users


-- 
Thank you,
Dmitri Pal

Sr. Engineering Manager for IdM portfolio
Red Hat Inc.


---
Looking to carve out IT costs?
www.redhat.com/carveoutcosts/



___
Freeipa-users mailing list
Freeipa-users@redhat.com
https://www.redhat.com/mailman/listinfo/freeipa-users