![]() |
Hello and Welcome from United States to the UNIX and Linux Forums! Thank You for Visiting and Joining Our Global Community.
|
|
google unix.com
|
|||||||
| Forums | Register | Forum Rules | Links | Albums | FAQ | Members List | Calendar | Search | Today's Posts | Mark Forums Read |
| SuSE SUSE Linux is a major operating system. The developer rights are owned by Novell, Inc. |
More UNIX and Linux Forum Topics You Might Find Helpful
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| LDAP user password reset script | em23 | SUN Solaris | 1 | 12-29-2008 07:02 AM |
| Configuring WebSphere Process Server with OpenDS Ldap User Repository | iBot | Solaris BigAdmin RSS | 0 | 10-14-2008 09:20 PM |
| local user ip | naushad | UNIX for Dummies Questions & Answers | 9 | 09-15-2008 01:07 AM |
| local user ip | naushad | UNIX for Dummies Questions & Answers | 1 | 09-14-2008 02:36 AM |
| How to prevent local root from su to an NIS user? | nfw | UNIX for Advanced & Expert Users | 3 | 01-08-2008 01:38 PM |
![]() |
|
|
LinkBack | Thread Tools | Search this Thread | Rate Thread | Display Modes |
|
|
|
||||
|
I am implementing LDAP on Linux based system using openldap.
My management objects to the idea that all individual users will authenticate against an LDAP server because “what if it is not available” Their suggestion is that we run in parallel a set of local configured users and a set of LDAP configured users and both methods can coexist without conflicts. I think it is a very bad idea but I cannot think of any good justification why it should be the case. Besides the obvious that it is going to be very hard to maintain two separate methods for user management on multiple servers (about 20) and that it can create confusion when creating new users or disabling users. Just to clarify, we have a cluster for the LDAP server and we have high availability. Also, generic users that are required by the application or the database will stay on the local files. I am talking about having some individual users managed locally in /etc/shadow and some using the LDAP server no synchronization between the two. I know it sounds a horrible idea but I need to come up with some strong arguments to convince my “old fashioned” management. I will appreciate any argument either way. thanks |
![]() |
| Bookmarks |
| Thread Tools | Search this Thread |
| Display Modes | Rate This Thread |
|
|