Michael,

Andrew didn't say anything about using SPNEGO--just Kerberos authentication to AD.  In my experience this never required a special AD account.

Adam

Michael Ströder wrote:
Andrew Ralph Feller, afelle1 wrote:
  
Have you looked into using AD + Kerberos instead of AD + LDAP?  We have
done AD + LDAP in the past and currently do AD + Kerberos due to our AD
administrators preferences; also it doesn’t require us to use a service
account.
    

IMO SPNEGO/Kerberos requires a service account for the CAS server.

Ciao, Michael.
_______________________________________________
Yale CAS mailing list
[email protected]
http://tp.its.yale.edu/mailman/listinfo/cas
  
begin:vcard
fn:Adam Rybicki
n:Rybicki;Adam
org:Unicon, Inc.;Professional Services
adr:Suite 113;;3140 North Arizona Avenue;Chandler;AZ;85225;United States
email;internet:[EMAIL PROTECTED]
tel;work:+1-480-558-2400
tel;home:+1-310-265-8286
tel;cell:+1-310-980-2758
x-mozilla-html:FALSE
url:http://www.unicon.net/
version:2.1
end:vcard

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature

_______________________________________________
Yale CAS mailing list
[email protected]
http://tp.its.yale.edu/mailman/listinfo/cas

Reply via email to