Quote:
Originally Posted by Milorad
Why the hell do you want to do this? why not just secure the server?
|
I appreciate the effort that you put into your response to my post. If you were familiar with external authentication in general, Radius, LDAP or Kerberos specifically, you would understand that these systems are not only about server security. My specific BB environment has nothing to do with the BB server security. In an enterprise environment, consolidation or usernames, group memberships, access to network services and especially passwords is a critical task of the IT dept. In a fully "kerberized" envirnoment, a user would log into the network one time (into the kerberos server) with one password and not need to enter their username or password again to access any of the other network services to which they had permissions. All of those transactions happen between the kerberos server and any of the servers or services that have been subscribed by the sys admn. This also allows the sys admin to manage the users in a single database. Big time savings.