The UNIX and Linux Forums  
Hello and Welcome from United States to the UNIX and Linux Forums! Thank You for Visiting and Joining Our Global Community.

Go Back   The UNIX and Linux Forums > Operating Systems > Linux > SuSE
.
google unix.com



SuSE SUSE Linux is a major operating system. The developer rights are owned by Novell, Inc.

More UNIX and Linux Forum Topics You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
LDAP user password reset script em23 SUN Solaris 1 12-29-2008 07:02 AM
Configuring WebSphere Process Server with OpenDS Ldap User Repository iBot Solaris BigAdmin RSS 0 10-14-2008 09:20 PM
local user ip naushad UNIX for Dummies Questions & Answers 9 09-15-2008 01:07 AM
local user ip naushad UNIX for Dummies Questions & Answers 1 09-14-2008 02:36 AM
How to prevent local root from su to an NIS user? nfw UNIX for Advanced & Expert Users 3 01-08-2008 01:38 PM

Closed Thread
English Japanese Spanish French German Portuguese Italian Dutch Swedish Russian Norwegian Hungarian Hebrew Danish Powered by Powered by Google
 
LinkBack Thread Tools Search this Thread Rate Thread Display Modes
  #1 (permalink)  
Old 01-15-2009
scampi scampi is offline
Registered User
  
 

Join Date: Feb 2007
Posts: 2
Unhappy user management - LDAP and local files

I am implementing LDAP on Linux based system using openldap.
My management objects to the idea that all individual users will authenticate against an LDAP server because “what if it is not available”
Their suggestion is that we run in parallel a set of local configured users and a set of LDAP configured users and both methods can coexist without conflicts.
I think it is a very bad idea but I cannot think of any good justification why it should be the case.
Besides the obvious that it is going to be very hard to maintain two separate methods for user management on multiple servers (about 20) and that it can create confusion when creating new users or disabling users.
Just to clarify, we have a cluster for the LDAP server and we have high availability.
Also, generic users that are required by the application or the database will stay on the local files.
I am talking about having some individual users managed locally in /etc/shadow and some using the LDAP server no synchronization between the two.
I know it sounds a horrible idea but I need to come up with some strong arguments to convince my “old fashioned” management.
I will appreciate any argument either way.
thanks
  #2 (permalink)  
Old 02-05-2009
otheus's Avatar
otheus otheus is offline Forum Staff  
Moderator ala Mode
  
 

Join Date: Feb 2007
Location: Innsbruck, Austria
Posts: 1,884
Quote:
Their suggestion is that we run in parallel a set of local configured users and a set of LDAP configured users and both methods can coexist without conflicts.
That sounds like a bad idea; however, it could be a good idea if the local files are updated regularly from the LDAP files. Your servers should have both a "pull" and a "push" mechanism. Password information changes should always be against the master LDAP server. These changes should be pushed right away.

The biggest risk is if you have a user who is fired/terminated, and you need to shut off their account right away. That's another reason why you need the "push".

LDAP supports replication, so what you can do is run an LDAP mirroring service on each server. Each service is basically a slave to the master one. I believe this supports the push/pull thing I'm talking about, but I'm not 100% sure.
Closed Thread

Bookmarks

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT -4. The time now is 08:19 PM.


Powered by: vBulletin, Copyright ©2000 - 2006, Jelsoft Enterprises Limited. Language Translations Powered by .
vBCredits v1.4 Copyright ©2007 - 2008, PixelFX Studios
The UNIX and Linux Forums Content Copyright ©1993-2009. All Rights Reserved.Ad Management by RedTyger

Content Relevant URLs by vBSEO 3.2.0