Or external LDAP authentication into vBulletin for it to work in our company environment. Can anyone tell me if this has been done (authentication against an external OSX LDAP or (preferably) OSX kerberos server)?
If not, can someone provide an estimate for the cost of getting this modification performed? I have attempted to post this request into the "services requested" forums, but as I have not yet bought the software I see that I cannot post to that forum.
Why the hell do you want to do this? why not just secure the server?
I appreciate the effort that you put into your response to my post. If you were familiar with external authentication in general, Radius, LDAP or Kerberos specifically, you would understand that these systems are not only about server security. My specific BB environment has nothing to do with the BB server security. In an enterprise environment, consolidation or usernames, group memberships, access to network services and especially passwords is a critical task of the IT dept. In a fully "kerberized" envirnoment, a user would log into the network one time (into the kerberos server) with one password and not need to enter their username or password again to access any of the other network services to which they had permissions. All of those transactions happen between the kerberos server and any of the servers or services that have been subscribed by the sys admn. This also allows the sys admin to manage the users in a single database. Big time savings.
I appreciate the effort that you put into your response to my post. If you were familiar with external authentication in general, Radius, LDAP or Kerberos specifically, you would understand that these systems are not only about server security. My specific BB environment has nothing to do with the BB server security. In an enterprise environment, consolidation or usernames, group memberships, access to network services and especially passwords is a critical task of the IT dept. In a fully "kerberized" envirnoment, a user would log into the network one time (into the kerberos server) with one password and not need to enter their username or password again to access any of the other network services to which they had permissions. All of those transactions happen between the kerberos server and any of the servers or services that have been subscribed by the sys admn. This also allows the sys admin to manage the users in a single database. Big time savings.
Mattospork, i know the devs are looking into this at some point for vB3, i cant say when or if it will ever bee released, and i belive they are looking at LDAP. however i dont and cant say much more. I do understand the want and need for single point administration
I'd certainly be interested in something along these lines - we want to be able to reduce the amount of usernames and passwords our users have to remember and use on our network and some kind of external authentication would be marvellous.
yeah, some ldap integration would be really cool. we do have all accounts in our ldap servers, even active directory is syncronised with ldap. so holding userdata in mysql is not really a choice.. but we have to do it