Gentoo Archives: gentoo-user

From: Bryan Whitehead <driver@×××××××××.net>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] NIS configuration
Date: Sun, 27 Aug 2006 08:45:15
Message-Id: Pine.LNX.4.64.0608270139060.25343@beavis.megahappy.net
In Reply to: [gentoo-user] NIS configuration by Leandro Melo de Sales
1 If you are worried about the users getting the ldap bind password - then
2 why on earth would you bother with NIS? NIS has no password to block
3 binding at all! At least ldap has a binding password...
4
5 On Tue, 22 Aug 2006, Leandro Melo de Sales wrote:
6
7 > Hi!
8 >
9 > I configured my gentoo server box to authenticate users through LDAP
10 > (nsswicth+pam_ldap). Everything are working fine and now I want to run
11 > a ypserv and as a result I want the nis clients authenticating against
12 > my server. I following the instructions in
13 > http://gentoo-wiki.com/HOWTO_Setup_NIS but the clients (gentoo and
14 > ubuntu boxes) don't find the ypserver, any clue?
15 > I was planning to make the clients authentication directly to LDAP
16 > server, but in this case I have to install pam_ldap and create a
17 > /etc/ldap.conf and put ldap bindpw into this file or in
18 > /etc/ldap.secret. Even if I protect it with 600 the use can get this
19 > file installing a windows application (the client machines have dual
20 > boot) that read ext3 partitions and read the files, finally getting
21 > the bindpw. Any comment about this? Am I thinking wrong about that?
22 >
23 > Thank you. BTW, all suggestion will be greatfully accepted.
24 >
25 > Leandro.
26 >
27 >
28
29 --
30 Bryan Whitehead
31 Email:driver@×××××××××.net
32 --
33 gentoo-user@g.o mailing list