09-19-2007
Password database
Quote:
Originally Posted by
cassj
What are you wanting to accomplish with this...
1. just store all kinds of passwords securely in a database for users to retrieve.
Basically yes.
This database is for use by a support group maintaining routers, switches, servers, etc. Of course all users should not have access to everything so I need to be able to limit their access to passwords based on the group they are in. From my limited database knowledge I believe this would be considered a view.
2. Or does the database need to feed to passwords to applications? That of course is more involved.
Nope, not needed.
2. Server as a central authentication point for infrastructure access? In that case, ONE option would be to look at LDAP, such as OpenLDAP
OpenLDAP
No, not trying to set up something like a PKI, that's too complicated for me.
Thanks
thumper
8 More Discussions You Might Find Interesting
1. Programming
HI i need to delete an entry in /etc/security/passwd.
can't find a way to do it with userpw.h api ( AIX ).
the passwd file i delete like this.
Write all entrys to passwd file except the one we are removing.
can't find any function that works like getspent / getpwent do
in AIX userpw api.... (4 Replies)
Discussion started by: nighter
4 Replies
2. Shell Programming and Scripting
Hi,
I need to connect to DB through my shell script. but I dont want to hardcode my db password in the script. Is there a way to do it?
Thanks
---------- Post updated at 07:42 PM ---------- Previous update was at 04:54 PM ----------
:(Guys..please help me with this:( (1 Reply)
Discussion started by: agrawal.prachi
1 Replies
3. Shell Programming and Scripting
Hi there,
This is my first post, so as you have probably guessed I am looking for some help.
Currently we have close to 1000 ksh scripts operating on HPUX servers that call either isql or bcp to connect to Sybase databases. Problem being that the db passwords are appearing in the job log... (3 Replies)
Discussion started by: kdk_irl
3 Replies
4. Solaris
I installed Oracle 10 software on Solaris 11 Express, everything was fine execpt I can't create database using dbca.rsp file. I populated file with following options.
OPERATION_TYPE = "createDatabase"
GDBNAME = "solaris_user.domain.com"
SID = "solaris_user"
TEMPLATENAME = "General... (0 Replies)
Discussion started by: solaris_user
0 Replies
5. Shell Programming and Scripting
Hi All,
I want to validate the Production Database password at the time of login through script. If incorrect password entererd by the user, the script will ask again for the password.
Below is the sample of my script...
#########################
# Unix Code Starts here #... (6 Replies)
Discussion started by: saps19
6 Replies
6. Shell Programming and Scripting
I have a reseller account with hostgator, which means i have WHM and Cpanel. I have set up a staging environment for one of my wordpress installations (client website), which is essentially sitting at staging.domain.com (live site is at domain.com). The staging website is a complete copy of the... (1 Reply)
Discussion started by: nzrobert
1 Replies
7. UNIX for Beginners Questions & Answers
Hello everybody,
I need to modify 200 files using a patern matching, I would like to do it with sed but it's not working with the following syntax:
sed -e 's/DATABASE_PASSWORD.*oldpass/DATABASE_PASSWORD__', 'newpass/g' config.php
need to find:
define("__DATABASE_PASSWORD__", ... (6 Replies)
Discussion started by: dco
6 Replies
8. Forum Support Area for Unregistered Users & Account Problems
I was unable to login and so used the "Forgotten Password' process. I was sent a NEWLY-PROVIDED password and a link through which my password could be changed. The NEWLY-PROVIDED password allowed me to login.
Following the provided link I attempted to update my password to one of my own... (1 Reply)
Discussion started by: Rich Marton
1 Replies
LEARN ABOUT CENTOS
rlm_pap
rlm_pap(5) FreeRADIUS Module rlm_pap(5)
NAME
rlm_pap - FreeRADIUS Module
DESCRIPTION
The rlm_pap module authenticates RADIUS Access-Request packets that contain a User-Password attribute. The module should also be listed
last in the authorize section, so that it can set the Auth-Type attribute as appropriate.
When a RADIUS packet contains a clear-text password in the form of a User-Password attribute, the rlm_pap module may be used for authenti-
cation. The module requires a "known good" password, which it uses to validate the password given in the RADIUS packet. That "known good"
password must be supplied by another module (e.g. rlm_files, rlm_ldap, etc.), and is usually taken from a database.
CONFIGURATION
The only relevant configuration item is:
auto_header
If set to "yes", the module will look inside of the User-Password attribute for the headers {crypt}, {clear}, etc., and will auto-
matically create the appropriate attribute, with the correct value.
This module understands many kinds of password hashing methods, as given by the following table.
Header Attribute Description
------ --------- -----------
{clear} Cleartext-Password clear-text passwords
{cleartext} Cleartext-Password clear-text passwords
{crypt} Crypt-Password Unix-style "crypt"ed passwords
{md5} MD5-Password MD5 hashed passwords
{smd5} SMD5-Password MD5 hashed passwords, with a salt
{sha} SHA-Password SHA1 hashed passwords
{ssha} SSHA-Password SHA1 hashed passwords, with a salt
{nt} NT-Password Windows NT hashed passwords
{x-nthash} NT-Password Windows NT hashed passwords
{lm} LM-Password Windows Lan Manager (LM) passwords.
The module tries to be flexible when handling the various password formats. It will automatically handle Base-64 encoded data, hex
strings, and binary data, and convert them to a format that the server can use.
It is important to understand the difference between the User-Password and Cleartext-Password attributes. The Cleartext-Password attribute
is the "known good" password for the user. Simply supplying the Cleartext-Password to the server will result in most authentication meth-
ods working. The User-Password attribute is the password as typed in by the user on their private machine. The two are not the same, and
should be treated very differently. That is, you should generally not use the User-Password attribute anywhere in the RADIUS configura-
tion.
For backwards compatibility, there are old configuration parameters which may be work, although we do not recommend using them.
SECTIONS
authorize authenticate
FILES
/etc/raddb/radiusd.conf
SEE ALSO
radiusd(8), radiusd.conf(5)
AUTHOR
Alan DeKok <aland@freeradius.org>
6 June 2008 rlm_pap(5)