docs(adr-0023): record making Kerberos authoritative for the identity tenant #300

Closed
opened 2026-08-08 13:29:41 +02:00 by dominik.polakovics · 0 comments

Design record for #299. Documentation only — no configuration change, nothing to deploy.

ADR-0022 decision 3 fixed Kerberos as additive and LDAP userPassword as authoritative, booking "two password stores… nothing keeps them in sync" as accepted debt. The widening to a reference architecture, plus the discovery that the divergence is already wired into the config, makes that worth revisiting as a decision rather than leaving as a footnote.

New ADR rather than an amendment, because it reverses a numbered decision rather than adding to one.

Records: the partition model; that string-to-key makes silent migration impossible and why that forces per-user cutover; that tickets cannot be revoked and max_life is therefore a security setting; why FreeIPA and Samba AD are ruled out by multi-tenancy; why Heimdal + smbk5pwd, LTB, a CredentialInputUpdater SPI and mail-token reset were each rejected; and the consequences of keeping one KDC.

Design record for #299. Documentation only — no configuration change, nothing to deploy. ADR-0022 decision 3 fixed Kerberos as additive and LDAP `userPassword` as authoritative, booking "two password stores… nothing keeps them in sync" as accepted debt. The widening to a reference architecture, plus the discovery that the divergence is already wired into the config, makes that worth revisiting as a decision rather than leaving as a footnote. New ADR rather than an amendment, because it reverses a numbered decision rather than adding to one. Records: the partition model; that string-to-key makes silent migration impossible and why that forces per-user cutover; that tickets cannot be revoked and `max_life` is therefore a security setting; why FreeIPA and Samba AD are ruled out by multi-tenancy; why Heimdal + `smbk5pwd`, LTB, a `CredentialInputUpdater` SPI and mail-token reset were each rejected; and the consequences of keeping one KDC.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
Cloonar/nixos#300
No description provided.