Subject: Re: Centralized User and Password Management
To: Pavel Cahyna <pavel.cahyna@st.mff.cuni.cz>
From: Luke Mewburn <lukem@NetBSD.org>
List: netbsd-users
Date: 11/24/2004 21:38:59
--AAxWdR3COjAeVN+/
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable
On Wed, Nov 24, 2004 at 09:48:50AM +0100, Pavel Cahyna wrote:
| On Wed, 24 Nov 2004 05:44:10 +0000, Luke Mewburn wrote:
|=20
| > On Wed, Nov 24, 2004 at 12:18:43AM -0500, Chuck Swiger wrote:
| > | Thomas T. Thai wrote:
| > | >I'm curious what people are using to centralize authentication a=
nd
| > | >user, password, and services management. What are your thoughts =
on
| > | >each? I'm aware of these Open Source solutions:
| > | >
| > | >- NIS (YP) - insecure
| > | >- Hesiod + Kerberos
| > |=20
| > | The next two candidates would be LDAP and maybe even Apple's NetI=
nfo.
| >=20
| > Another possibility in the near future:
| > Active Directory Services from a Microsoft Windows 200x Server
| > It's implemented on top of LDAP + Kerberos 5. You can use kinit to get
| > krb5 tickets from an ADS server in NetBSD.
|=20
| Please, is it already possible to have the nss_ldap module on NetBSD to
| use any LDAP server as the user database?
No; unless someone else has ported nss_ldap.so to NetBSD-current.
Note that I recently changed the API between get{pw,gr}* and
the NSS backends to make it easier to implement third party
nss_foo modules like LDAP & Winbind.
I intend to port PADL's nss_ldap.so to NetBSD and/or write one from
scratch, sometime in the future.
--AAxWdR3COjAeVN+/
Content-Type: application/pgp-signature
Content-Disposition: inline
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.6 (NetBSD)
iD8DBQFBpGTCpBhtmn8zJHIRAtYaAKCvadX9JsRDUtwqJbEMThr+rIMlywCfQTjA
QulfaJCGLz2ZchydSk40avw=
=LRm8
-----END PGP SIGNATURE-----
--AAxWdR3COjAeVN+/--