PostgreSQL LDAP \ Kerberos

Previous Topic Next Topic
 
classic Classic list List threaded Threaded
2 messages Options
Reply | Threaded
Open this post in threaded view
|

PostgreSQL LDAP \ Kerberos

Pierre Ochsenbein-2
Guys,

Somebody can give me Feedback about PostgreSQL Authentication with LDAP and Kerberos.

Actually I use LDAP authentication and I would like to test automatically authentication  with Kerberos... 

It's easy to implement and works fine, no bugs in perspective?

Thanks for your feedback


Reply | Threaded
Open this post in threaded view
|

Re: PostgreSQL LDAP \ Kerberos

Stephen Frost
Greetings,

* Pierre Ochsenbein ([hidden email]) wrote:
> Somebody can give me Feedback about PostgreSQL Authentication with LDAP and
> Kerberos.

You should use Kerberos for authentication, using LDAP isn't a good idea
because the PG server will see the user's password.

> Actually I use LDAP authentication and I would like to test automatically
> authentication  with Kerberos...
>
> It's easy to implement and works fine, no bugs in perspective?

Yes, it works fine, just generate a keytab and copy it to somewhere that
the PG server can see it.  If you're in an active directory environment
then this requires a bit more than just an addprinc/ktadd, there's a
blog post I wrote about doing it here:

https://info.crunchydata.com/blog/windows-active-directory-postgresql-gssapi-kerberos-authentication

Thanks,

Stephen

signature.asc (836 bytes) Download Attachment