Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #242901

Re: using pam-ldap to allow ssh logins from only *some* ldap accounts (and not all)

From Alex Mestiashvili <amestia@rsh2.donotuse.de>
Newsgroups linux.debian.user
Subject Re: using pam-ldap to allow ssh logins from only *some* ldap accounts (and not all)
Date 2021-12-10 14:00 +0100
Message-ID <DsNFf-6wB-9@gated-at.bofh.it> (permalink)
References <DsMzv-5Ul-1@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On 12/10/21 12:31 PM, charlie derr wrote:
> Hi again everyone,
> 
> Having gotten an excellent (and quite simple) response to my query about automatic homedir creation upon ssh login, i'm going to push my luck (expecting @ any moment to receive responses with RTFM or somethings close to that sentiment in them).
> 
> Our goal is to allow not just *any* LDAP user in our openldap (version 2.4.40) directory, but only those specified as members of a particular group (in our LDAP). We have a custom LDAP attribute (groupSR) that is attached directly to the user's entry (ou=People,uid=<user-login-name>) or we could easily also populate a "more standard" (cn=<groupname>) entry (with memeberUID attributes corresponding to the "allowed SSH users") in the ou=Group branch of our directory.
> 
> Pretty sure this was set up quite some time ago here, but the colleagues who I collaborated with to do it are no longer working with me, and I can't for the life of me remember how exactly it was done...
> 
> 
>      as always, thanks so much for any assistance, as well as for all that everyone does for debian,
>               ~c
> 

Using pam_mkhomedir too, if you mean that.
I've switched years ago to libpam-ldapd and libnss-ldapd with nslcd.
See how one can restrict the access group-wise with nslcd:
https://wiki.debian.org/LDAP/PAM#Allowing_logins_on_a_per-group_basis

Back to linux.debian.user | Previous | Next — Previous in thread | Find similar | Unroll thread


Thread

using pam-ldap to allow ssh logins from only *some* ldap accounts  (and not all) charlie derr <charlie@emergencyguild.org> - 2021-12-10 12:50 +0100
  Re: using pam-ldap to allow ssh logins from only *some* ldap  accounts (and not all) Roberto C. Sánchez <roberto@debian.org> - 2021-12-10 13:40 +0100
  Re: using pam-ldap to allow ssh logins from only *some* ldap accounts  (and not all) Alex Mestiashvili <amestia@rsh2.donotuse.de> - 2021-12-10 14:00 +0100

csiph-web