Hi,
We have the current challenge to introduce Macs into a rather Windows based backend environment. We decided to not join them to the AD domain (neither the users nor the machines) for various reasons, so users will authenticate to their Mac devices with a local user id and then get a Kerberos ticket for accessing internal applications.
Now, I would like to ask the community for best practices (and tools) how to handle Kerberos tickets in such a scenario.
What we would like to achieve (which might be unrealistic, but, you know, the sky is the limit ;-) :
- AD account password expiration notice
- Password synchronization of the local user account and the AD account (user ids are equal)
- automatically claim and renew (our Kerberos tickets are valid for 10h) a Kerberos ticket when on the company network (direct or via VPN)
Tools we already looked at:
- Apple Enterprise Connect: seems to would solve all our problems, but unfortunately not available outside the US (we are sitting in Europe)
- NoMAD: promising, but does not work with our AD domain setup
- KerbMinder: could help claim tickets automatically
- ADPassMon: seems only to work properly for domain joined machines (am I right?)
any other ideas highly welcome!
Thanks
Marcus.
