LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Other *NIX Forums > Solaris / OpenSolaris
User Name
Password
Solaris / OpenSolaris This forum is for the discussion of Solaris, OpenSolaris, OpenIndiana, and illumos.
General Sun, SunOS and Sparc related questions also go here. Any Solaris fork or distribution is welcome.

Notices


Reply
  Search this Thread
Old 11-10-2010, 04:04 PM   #1
gatsby
Member
 
Registered: Jan 2006
Posts: 59

Rep: Reputation: 16
LDAP for logon authorization


I'm trying to get my Solaris 10 machine to use Kerberos/LDAP to authenticate users. The Kerberos is supposed to handle the user passwords, while LDAP handles the user information. I have both these elements working and can log in to my Solaris machine.

Problem is, I want to limit who can login to my Solaris 10 machine. At the moment anyone with a username/password in the KDC can login to the Solaris 10 machine, which is undesirable. I have created a group in the LDAP directory that contains the people I want to be able to login to the machine, but I can't initialize the LDAP client in a way that this group successfully keeps anyone with an account on the KDC from logging in. I'm using the native Solaris ldapclient.

I'm not that familiar with LDAP, so I may be missing something pretty basic. If you could point me in the right direction I would appreciate it. Thanks in advance.


The command I'm using to initialize the client is:

ldapclient -v manual -a credentialLevel=anonymous -a defaultSearchBase=dc=test,dc=com -a domainName=sub.test.com -a defaultServerList=192.168.1.2 -a "serviceSearchDescriptor=groups: ou=groups,dc=test,dc=com?one?&(cn=my_test_group)"


The nsswitch.conf file looks like this:

passwd: files ldap
group: files ldap

hosts: dns ldap [NOTFOUND=return] files

ipnodes: dns ldap [NOTFOUND=return] files

networks: ldap [NOTFOUND=return] files
protocols: ldap [NOTFOUND=return] files
rpc: ldap [NOTFOUND=return] files
ethers: ldap [NOTFOUND=return] files
netmasks: ldap [NOTFOUND=return] files
bootparams: ldap [NOTFOUND=return] files
publickey: ldap [NOTFOUND=return] files

netgroup: ldap

automount: files ldap
aliases: files ldap

services: files ldap

printers: user files ldap

auth_attr: files ldap
prof_attr: files ldap

project: files ldap

tnrhtp: files ldap
tnrhdb: files ldap
 
Old 11-11-2010, 01:38 AM   #2
jlliagre
Moderator
 
Registered: Feb 2004
Location: Outside Paris
Distribution: Solaris 11.4, Oracle Linux, Mint, Debian/WSL
Posts: 9,789

Rep: Reputation: 492Reputation: 492Reputation: 492Reputation: 492Reputation: 492
The netgroups map is used to control what hosts users are allowed to connect to.

http://docs.sun.com/app/docs/doc/816...=en&n=1&a=view
http://www.theillien.com/Sys_Admin_v...v13/i05/a1.htm
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] ldap authorization fails: IHS7 (apache2)+php5+ldap olegk25 Linux - Networking 4 08-03-2010 02:49 AM
wireless authentication prior to ldap logon njpruess Linux - Wireless Networking 3 11-30-2007 09:29 AM
LXer: Apache authentication and authorization using LDAP LXer Syndicated Linux News 0 10-31-2007 03:50 PM
OS Authentication and Authorization Using LDAP nileshp Linux - Software 1 10-09-2006 12:53 AM
ldap SASL GSSAPI , unknown authorization mechanism mesh2005 Linux - Networking 0 11-20-2005 08:16 AM

LinuxQuestions.org > Forums > Other *NIX Forums > Solaris / OpenSolaris

All times are GMT -5. The time now is 06:59 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration