docs(adr-0023): record making Kerberos authoritative for the identity tenant #300
Labels
No labels
bug
enhancement
in-progress
needs-info
needs-triage
p0
ready-for-agent
ready-for-human
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
Cloonar/nixos#300
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Design record for #299. Documentation only — no configuration change, nothing to deploy.
ADR-0022 decision 3 fixed Kerberos as additive and LDAP
userPasswordas authoritative, booking "two password stores… nothing keeps them in sync" as accepted debt. The widening to a reference architecture, plus the discovery that the divergence is already wired into the config, makes that worth revisiting as a decision rather than leaving as a footnote.New ADR rather than an amendment, because it reverses a numbered decision rather than adding to one.
Records: the partition model; that string-to-key makes silent migration impossible and why that forces per-user cutover; that tickets cannot be revoked and
max_lifeis therefore a security setting; why FreeIPA and Samba AD are ruled out by multi-tenancy; why Heimdal +smbk5pwd, LTB, aCredentialInputUpdaterSPI and mail-token reset were each rejected; and the consequences of keeping one KDC.