In this instance, user passwords are stored in our LDAP server
(OpenLDAP), hashed. All our services currently validate user credentials
by attempting an LDAP bind either directly or via another protocol implementation (Shibboleth IdP, FreeRADIUS, Keycloak etc).
So my question is, is there a way to implement kerberos without
knowledge of the plaintext passwords, or do we have to somehow capture
the credentials during users' login to other services and then sync them
to the kdc db?
| Sysop: | Amessyroom |
|---|---|
| Location: | Fayetteville, NC |
| Users: | 64 |
| Nodes: | 6 (0 / 6) |
| Uptime: | 492944:09:21 |
| Calls: | 842 |
| Files: | 1,304 |
| D/L today: |
8 files (19,649K bytes) |
| Messages: | 261,765 |