RE: LDAP in Unix



Dubaisans,

I think you are on the right track. You still will need local copies of
/etc/passwd and /etc/shadow but they will only be used as a fall back
mechanism when LDAP authentication is not available.



-----Original Message-----
From: listbounce@xxxxxxxxxxxxxxxxx [mailto:listbounce@xxxxxxxxxxxxxxxxx]
On Behalf Of dubaisans dubai
Sent: Wednesday, September 27, 2006 2:57 AM
To: focus-sun@xxxxxxxxxxxxxxxxx
Subject: LDAP in Unix

I have 100 + unix servers primarily Linux and solaris.

I am new to LDAP.

I would like to use Sun ONE Directory server and centralise the user

creation. Once I have LDAP based Directory server is the following
true?

1. Whenever a new user has to be created I will create on the SunOne

server and say it is valid only on this host(s).There is no need to
create the user at the host

2. There is no /etc/passwd and /etc/shadow files on the individual
hosts

anymore or they are not of any importance. All the passwords are

stored only in the Directory server.

3. As a later stage I would like to give RSA securID authentication to
selected set of high privilege users.

Is LDAP and Sun one the right direction?



Relevant Pages

  • Re: LDAP Client Setup on Solaris 8
    ... LDAP servers etc. ... directory server, and SunONE directory server doesn't need read access for ... The native AIX LDAP client upto and including AIX 5.2 do need ... "<attribute2 you choose>" with the value of the DN of the proxyagent-account ...
    (comp.unix.solaris)
  • RE: LDAP in Unix
    ... Subject: LDAP in Unix ... Solaris and AIX. ... If you want to limit which hosts a user can access, ... I would like to use Sun ONE Directory server and centralise the user ...
    (Focus-SUN)
  • Secure Ldap call not working due to IUSR/IWAM permissions?
    ... I am trying to get LDAP working so that I can authenticate web users against ... If I replace the hostname in the opendsobject call with the ip address, ... everything works properly (calling the directory server ...
    (Focus-Microsoft)
  • Re: Solaris 9 LDAP
    ... > tryint to set up a Sun ONE Directory Server 5.2 server to provide user ... Doing an LDAP search for the new user versus one ... > with sufficient priveleges to do LDAP passwd changes. ... Check nsswitch.conf for the proper entries on passwd ...
    (comp.unix.solaris)
  • Re: Solaris 9 LDAP
    ... > tryint to set up a Sun ONE Directory Server 5.2 server to provide user ... Doing an LDAP search for the new user versus one ... > with sufficient priveleges to do LDAP passwd changes. ... Check nsswitch.conf for the proper entries on passwd ...
    (comp.sys.sun.admin)