Choose a KDC Package
If you are establishing a new Kerberos realm, you’ll need to start by choosing a Kerberos implementation for your KDC. There are many different KDCs available from different vendors, both commercial and open source. Each KDC implementation is different, with advantages and disadvantages over the others. Let’s start by reviewing each KDC package we’ll cover in detail.
Don’t ignore your existing infrastructure. If you’re a large organization or you’ve got an existing Windows domain, chances are that you already have a Kerberos KDC available. By the same token, if you’re a predominantly Windows-based shop, you should strongly consider a Windows 2000 or 2003-based KDC, and vice versa for a Unix shop. The different implementations have enough of the essential features in common that the choice comes down to familiarity and comfort with the platform required to run the software.
Unlike Kerberos clients, you can’t mix Kerberos KDC implementations. An MIT Kerberos KDC, for example, cannot replicate against a Windows domain controller (yet). In addition, each Kerberos implementation uses a different administration protocol. That is, the administrative interface contained with the MIT KDC cannot be used, for example, to add users to a Heimdal KDC, and vice versa.
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access