Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #242895 > unrolled thread

using pam-ldap to allow ssh logins from only *some* ldap accounts (and not all)

Started bycharlie derr <charlie@emergencyguild.org>
First post2021-12-10 12:50 +0100
Last post2021-12-10 14:00 +0100
Articles 3 — 3 participants

Back to article view | Back to linux.debian.user


Contents

  using pam-ldap to allow ssh logins from only *some* ldap accounts  (and not all) charlie derr <charlie@emergencyguild.org> - 2021-12-10 12:50 +0100
    Re: using pam-ldap to allow ssh logins from only *some* ldap  accounts (and not all) Roberto C. Sánchez <roberto@debian.org> - 2021-12-10 13:40 +0100
    Re: using pam-ldap to allow ssh logins from only *some* ldap accounts  (and not all) Alex Mestiashvili <amestia@rsh2.donotuse.de> - 2021-12-10 14:00 +0100

#242895 — using pam-ldap to allow ssh logins from only *some* ldap accounts (and not all)

Fromcharlie derr <charlie@emergencyguild.org>
Date2021-12-10 12:50 +0100
Subjectusing pam-ldap to allow ssh logins from only *some* ldap accounts (and not all)
Message-ID<DsMzv-5Ul-1@gated-at.bofh.it>
Hi again everyone,

Having gotten an excellent (and quite simple) response to my query about automatic homedir creation upon ssh login, i'm going to push my luck (expecting @ any moment to receive responses with RTFM or somethings close to that sentiment in them).

Our goal is to allow not just *any* LDAP user in our openldap (version 2.4.40) directory, but only those specified as members of a particular group (in our LDAP). We have a custom LDAP attribute (groupSR) that is attached directly to the user's entry (ou=People,uid=<user-login-name>) or we could easily also populate a "more standard" (cn=<groupname>) entry (with memeberUID attributes corresponding to the "allowed SSH users") in the ou=Group branch of our directory.

Pretty sure this was set up quite some time ago here, but the colleagues who I collaborated with to do it are no longer working with me, and I can't for the life of me remember how exactly it was done...


    as always, thanks so much for any assistance, as well as for all that everyone does for debian,
             ~c

[toc] | [next] | [standalone]


#242899 — Re: using pam-ldap to allow ssh logins from only *some* ldap accounts (and not all)

FromRoberto C. Sánchez <roberto@debian.org>
Date2021-12-10 13:40 +0100
SubjectRe: using pam-ldap to allow ssh logins from only *some* ldap accounts (and not all)
Message-ID<DsNlU-6pD-1@gated-at.bofh.it>
In reply to#242895
On Fri, Dec 10, 2021 at 11:31:55AM +0000, charlie derr wrote:
> Hi again everyone,
> 
> Having gotten an excellent (and quite simple) response to my query about automatic homedir creation upon ssh login, i'm going to push my luck (expecting @ any moment to receive responses with RTFM or somethings close to that sentiment in them).
> 
> Our goal is to allow not just *any* LDAP user in our openldap (version 2.4.40) directory, but only those specified as members of a particular group (in our LDAP). We have a custom LDAP attribute (groupSR) that is attached directly to the user's entry (ou=People,uid=<user-login-name>) or we could easily also populate a "more standard" (cn=<groupname>) entry (with memeberUID attributes corresponding to the "allowed SSH users") in the ou=Group branch of our directory.
> 
> Pretty sure this was set up quite some time ago here, but the colleagues who I collaborated with to do it are no longer working with me, and I can't for the life of me remember how exactly it was done...
> 
I don't use pam-ldap any longer (I switched to sssd a few years ago).
But, looking at my old configurations, I had this in pam_ldap.conf:

pam_filter |(loginGroup=group1)(loginGroup=group2)

The | joins the parenthetical expressions with a logical OR.  I think
you could use & instead to achieve an AND joining (never tried that).

As another option, assuming you are using libnss-ldap as well, you can
add to libnss-ldap.conf something like this:

nss_base_passwd ou=Accounts,dc=example,dc=com?one?|(loginGroup=group1)(loginGroup=group2)

That would prevent the user even appearing in the output of getent, for
instance, unless the specified criteria are met.

In the event that you decide to switch to sssd (I recommend it, as it is
more flexible and less buggy than the PAM and NSS solution), then its
configuration provides explicit options for filtering specific users
and/or groups.

Regards,

-Roberto

-- 
Roberto C. Sánchez

[toc] | [prev] | [next] | [standalone]


#242901

FromAlex Mestiashvili <amestia@rsh2.donotuse.de>
Date2021-12-10 14:00 +0100
Message-ID<DsNFf-6wB-9@gated-at.bofh.it>
In reply to#242895
On 12/10/21 12:31 PM, charlie derr wrote:
> Hi again everyone,
> 
> Having gotten an excellent (and quite simple) response to my query about automatic homedir creation upon ssh login, i'm going to push my luck (expecting @ any moment to receive responses with RTFM or somethings close to that sentiment in them).
> 
> Our goal is to allow not just *any* LDAP user in our openldap (version 2.4.40) directory, but only those specified as members of a particular group (in our LDAP). We have a custom LDAP attribute (groupSR) that is attached directly to the user's entry (ou=People,uid=<user-login-name>) or we could easily also populate a "more standard" (cn=<groupname>) entry (with memeberUID attributes corresponding to the "allowed SSH users") in the ou=Group branch of our directory.
> 
> Pretty sure this was set up quite some time ago here, but the colleagues who I collaborated with to do it are no longer working with me, and I can't for the life of me remember how exactly it was done...
> 
> 
>      as always, thanks so much for any assistance, as well as for all that everyone does for debian,
>               ~c
> 

Using pam_mkhomedir too, if you mean that.
I've switched years ago to libpam-ldapd and libnss-ldapd with nslcd.
See how one can restrict the access group-wise with nslcd:
https://wiki.debian.org/LDAP/PAM#Allowing_logins_on_a_per-group_basis

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web