Unix Technical Forum

LDAP client services & Win2000 AD

This is a discussion on LDAP client services & Win2000 AD within the HP-UX Operating System forums, part of the Unix Operating Systems category; --> Hi, I'm trying to transfer the system administration of several HP-UX server's over to Windows 2000 Active Directory by ...


Go Back   Unix Technical Forum > Unix Operating Systems > HP-UX Operating System

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 01-16-2008, 04:45 PM
jean qiong he
 
Posts: n/a
Default LDAP client services & Win2000 AD

Hi,

I'm trying to transfer the system administration of several HP-UX
server's over to Windows 2000 Active Directory by installing LDAP-UX
client Services on the unix boxes.
Right, I've gotten two boxes to successfully bind to Active Directory to
authenticate users when they are logging in.
However, I don't know how I can control the user access of the two unix
boxes. In other words, when I create a new user in Active Directory, what
do I have to do so that I can control which box the user can log into?
Should I add the user to a certain group, ie "unixBox1", and then would I
have to change the login script of each unix box to check whether the user
that's trying to login has a certain memberOf attribute therefore belongs
to a certain group?
Thanks in advance,
Jean

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 01-16-2008, 04:45 PM
Alan Johnson
 
Posts: n/a
Default Re: LDAP client services & Win2000 AD

jean qiong he wrote:
> Hi,
>
> I'm trying to transfer the system administration of several HP-UX
> server's over to Windows 2000 Active Directory by installing LDAP-UX
> client Services on the unix boxes.
> Right, I've gotten two boxes to successfully bind to Active Directory to
> authenticate users when they are logging in.
> However, I don't know how I can control the user access of the two unix
> boxes. In other words, when I create a new user in Active Directory, what
> do I have to do so that I can control which box the user can log into?
> Should I add the user to a certain group, ie "unixBox1", and then would I
> have to change the login script of each unix box to check whether the user
> that's trying to login has a certain memberOf attribute therefore belongs
> to a certain group?
> Thanks in advance,
> Jean
>

Although I have not had to deal with it (yet...) I believe there is a
PAM module for that, dont know for sure though.

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT. The time now is 12:23 PM.


Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0
www.UnixAdminTalk.com