Howard Chu wrote:
You can of course choose to dedicate one LDAP server to back your KDC, but if you're going to isolate it from any other usage in this manner, then you're no longer getting any special benefit from using LDAP.
Even if you isolate your LDAP server solely to back your KDC you gain at least a better replication mechanism.
Ciao, Michael.