An NMAS method for Kerberos was developed back when the OES client was Novell client32 version 4.83. Support for this: an NMAS login by referral to an external Kerberos system was not continued and today it is not possible with the current client.

Please restore this functionality so that environments with a centralised enterprise kerberos system can make use of this to offer a single sign-on capability.

Those who run eDirectory within a federated organisation providing kerberos as a centralised service would like to consume kerberos credentials to login to eDirectory. Other methods of password synchronisation (Identity Manager for example) may not be possible for political reasons.

Comments

  • Those running AD are easily able to achieve this by setting up a cross-realm trust and given that this is so it makes it that bit harder to fly the flag for continued use of eDirectory

  • We're using DSFW. When a Windows client is already logged into that, it doesn't seem to be possible to single sign on with the Novell Client through the NMAS kerberos method using the already acquired ticket.