Unix Technical Forum

Re: Question on Ldap

This is a discussion on Re: Question on Ldap within the lucky.openbsd.tech forums, part of the OpenBSD category; --> Thorsten Glaser wrote: > Nicholas Basila dixit: > > >>more roles and I think pam is a better choice ...


Go Back   Unix Technical Forum > Unix Operating Systems > OpenBSD > lucky.openbsd.tech

Register FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 02-22-2008, 11:15 AM
Matthieu Herrb
 
Posts: n/a
Default Re: Question on Ldap

Thorsten Glaser wrote:
> Nicholas Basila dixit:
>
>
>>more roles and I think pam is a better choice for the long run. Having

>
>
> Up to the point that you _cannot_ statically link ksh on GNU/Linux
> because it needs the nsswitch/pam libraries dlopen'd at run time, hah!
>
> I think it's best as-is. I can live with the requirement to have
> pseudo-users in /etc/master.passwd now.
>
> Maybe an YP-like kludge would solve that.


In the OpenBSD world we'll stick to BSD auth for authentification. But a
better ldap integration than just auth_ldap is needed. With it, a good
name service switch is needed too. When you have dozens of machines, you
can't maintain pseudo-users in master.passwd and group.

It's too early to tell if a name service switch implementation will
require shared libs or not. There's nothing in the technology that
requires it to be implemented using dlopen'able modules. The list of
possible sources can be static (files, yp, dns, ldap).

There are several steps to be done, which are equally important. The
first one is to have a BSD-licensed ldap client library, and have
auth_ldap working with it.
--
Matthieu

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT. The time now is 05:11 PM.


Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0
www.UnixAdminTalk.com