4 ms·
Not really. AD is krb5 mutual auth backed by an LDAP datastore. LDAP is also used for storing various bits of other metadata. You can (with much pain and sad
by jmj42 13y ago
Not really. AD is krb5 mutual auth backed by an LDAP datastore. LDAP is also used for storing various bits of other metadata. You can (with much pain and sadness) implement a AD-like system using MIT Kerberos5 and OpenLDAP (I've done it)
In fact, even saying that the LDAP portion is extended is a bit misleading. In fact, AD implements a fully compliant LDAP interface. It does lack the more common LDAP Schemas (though they can be installed if you wish), and relies on a schema that MS developed, but the LDAP server is not, itself, extended.