Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #242901
| From | Alex Mestiashvili <amestia@rsh2.donotuse.de> |
|---|---|
| Newsgroups | linux.debian.user |
| Subject | Re: using pam-ldap to allow ssh logins from only *some* ldap accounts (and not all) |
| Date | 2021-12-10 14:00 +0100 |
| Message-ID | <DsNFf-6wB-9@gated-at.bofh.it> (permalink) |
| References | <DsMzv-5Ul-1@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
On 12/10/21 12:31 PM, charlie derr wrote: > Hi again everyone, > > Having gotten an excellent (and quite simple) response to my query about automatic homedir creation upon ssh login, i'm going to push my luck (expecting @ any moment to receive responses with RTFM or somethings close to that sentiment in them). > > Our goal is to allow not just *any* LDAP user in our openldap (version 2.4.40) directory, but only those specified as members of a particular group (in our LDAP). We have a custom LDAP attribute (groupSR) that is attached directly to the user's entry (ou=People,uid=<user-login-name>) or we could easily also populate a "more standard" (cn=<groupname>) entry (with memeberUID attributes corresponding to the "allowed SSH users") in the ou=Group branch of our directory. > > Pretty sure this was set up quite some time ago here, but the colleagues who I collaborated with to do it are no longer working with me, and I can't for the life of me remember how exactly it was done... > > > as always, thanks so much for any assistance, as well as for all that everyone does for debian, > ~c > Using pam_mkhomedir too, if you mean that. I've switched years ago to libpam-ldapd and libnss-ldapd with nslcd. See how one can restrict the access group-wise with nslcd: https://wiki.debian.org/LDAP/PAM#Allowing_logins_on_a_per-group_basis
Back to linux.debian.user | Previous | Next — Previous in thread | Find similar | Unroll thread
using pam-ldap to allow ssh logins from only *some* ldap accounts (and not all) charlie derr <charlie@emergencyguild.org> - 2021-12-10 12:50 +0100 Re: using pam-ldap to allow ssh logins from only *some* ldap accounts (and not all) Roberto C. Sánchez <roberto@debian.org> - 2021-12-10 13:40 +0100 Re: using pam-ldap to allow ssh logins from only *some* ldap accounts (and not all) Alex Mestiashvili <amestia@rsh2.donotuse.de> - 2021-12-10 14:00 +0100
csiph-web