Gentoo Archives: gentoo-server

From: "Andrew D. Fant" <andrew.fant@×××××.edu>
To: gentoo-server@l.g.o
Subject: Re: [gentoo-server] LDAP authentication in pieces
Date: Tue, 05 Sep 2006 16:21:05
Message-Id: 44FDA307.9060404@tufts.edu
In Reply to: Re: [gentoo-server] LDAP authentication in pieces by rdmurray@bitdance.com
1 rdmurray@××××××××.com wrote:
2 > On Tue, 5 Sep 2006 at 17:51, Nicolas MASS� wrote:
3 >> On Tuesday 05 September 2006 17:35, Andrew D. Fant wrote:
4 >>> I know that there is an NIS emulation mode for ldap, but is there a more
5 >>> elegant way to have a local password file, where logins are checked
6 >>> first
7 >>> against the directory, and if there is no ldap entry for the user,
8 >>> falling
9 >>> back to the local files?
10 >>
11 >> In /etc/nsswitch.conf, you can have an entry like this :
12 >>
13 >> passwd: ldap files
14 >> shadow: ldap files
15 >> group: ldap files
16 >
17 > I don't know much about this, but given Andrew's constraints and what
18 > the nsswitch.conf man page says I'd think he just wants:
19 >
20 > shadow: ldap files
21 >
22 > without the other two, since he said that he doesn't want everyone
23 > in the enterprise to have access to the gentoo boxes, and that the
24 > group structure is different.
25 >
26
27 Thanks to both of you for the quick response, I'll give these a try soon and see
28 how they go. By the end of the week, I'll try for a follow up to let everyone
29 know how it went.
30
31 Thanks again
32
33 --
34 Andrew Fant | The lion and the calf shall lie | Disclaimer:
35 andrew.fant@×××××.edu | down together, but the calf won't | Do you REALLY
36 TCCS/USG | get much sleep. | think I can
37 Tufts University | W. Allen | speak for Tufts?
38 --
39 gentoo-server@g.o mailing list