access control with ldap authentication

Boris Glawe boris at boris-glawe.de
Tue May 23 13:52:22 UTC 2006


hello,

we are authenticating most of our users with NIS and some of our users 
with ldap.

On some machines we'd like to allow acces to a certain group of users 
only. These users are authenticated with LDAP.

Where do you control whether or not a user/group may login or not if you 
use LDAP?

thanks in advance

Boris

Here is our /etc/pam.d/system-auth, which is included in most of all 
configuration files in /etc/pam.d

################################################################
#%PAM-1.0
# This file is auto-generated.
# User changes will be destroyed the next time authconfig is run.
auth        required      /lib/security/$ISA/pam_env.so
auth        sufficient    /lib/security/$ISA/pam_unix.so likeauth nullok
auth        sufficient    /lib/security/$ISA/pam_ldap.so use_first_pass
auth        required      /lib/security/$ISA/pam_deny.so

account     required      /lib/security/$ISA/pam_unix.so broken_shadow
account     sufficient    /lib/security/$ISA/pam_succeed_if.so uid < 100 
quiet
account     [default=bad success=ok user_unknown=ignore] 
/lib/security/$ISA/pam_ldap.so
account     required      /lib/security/$ISA/pam_permit.so

password    requisite     /lib/security/$ISA/pam_cracklib.so retry=3
password    sufficient    /lib/security/$ISA/pam_unix.so nullok 
use_authtok md5 shadow nis
password    sufficient    /lib/security/$ISA/pam_ldap.so use_authtok
password    required      /lib/security/$ISA/pam_deny.so

session     required      /lib/security/$ISA/pam_limits.so
session     required      /lib/security/$ISA/pam_unix.so
session     optional      /lib/security/$ISA/pam_ldap.so



################################################################


here is the relevant part of our /etc/nsswitch.conf:

passwd:     files ldap nis
shadow:     files ldap nis
group:      files ldap nis

################################################################




More information about the users mailing list