4 ms·
Unless I'm mistaken, you should be able to get working Windows Authentcation if you have Kerberos libs installed, a valid krb5.conf and a keytab or service acco
by nullify88 6y ago
Unless I'm mistaken, you should be able to get working Windows Authentcation if you have Kerberos libs installed, a valid krb5.conf and a keytab or service account credentials.
It was suprisingly easy to get working.
What Windows containers offers are Group Managed Service Accounts which reduces the administrative overhead managing service accounts for Linux containers and makes them completely transparent to the container.
- filleokus 6y agoYeah, we investigated that route, but on stateless containers it seemed really cumbersome? I don't remember exactly why now, but isn't there some problem with the ephemeral nature of the container? Like that each instance of the container needs their own service account or something? > What Windows containers offers are Group Managed Service Accounts which reduces the administrative overhead managing service accounts for Linux containers and makes them completely transparent to the container. Aah, yeah, that seems nice.
- nullify88 6y ago> Yeah, we investigated that route, but on stateless containers it seemed really cumbersome? I agree, it could be cumbersome without something to manage the secrets. I use OpenShift / k8s at work so injecting these secrets is trivial.
- GordonS 6y agoI think it gets more complex if you need to do kerberos constrained delegation. It's been a while since I looked into it and threw my hands up, but essentially I think it's the ephemeral nature of containers that is the problem, as machines need to be registered in AD and have delegation rights assigned.
- dogma1138 6y agoWindows authentication doesn’t use Kerberos. Windows authentication uses NTLM, if it’s backed by a directory such as an AD it’s then can be used by the server to authenticate or authorize the user. The Kerberos support in Active Directory is somewhat there due to legacy reasons when there were a lot of directory products on the market that spoke Kerberos and it’s was added to support applications that did not shoot NTLM. For the most part most Microsoft products don’t use it, and those which do don’t expose it to the users (SSO, tho there is now SSO with Windows principles too). To put it more simply if you login to the server directly using a username and password (For a Windows Principle) it’s never Kerberos, for Kerberos authentication you need to go to a Kerberos server and get a TGT then use that TGT to get a service ticket for a specific resource which again is done against the Kerberos server directly that service ticket is then presented to the resource you are trying to access.
- beatrobot 6y agoWindows authentication absolutely uses Kerberos, NTLM is more used as a fallback. Kerberos is way more secure than ntlmv2 and is the favored authentication method.