Sponsored Content
Full Discussion: PAM_LDAP and NSS_LDAP
Operating Systems AIX PAM_LDAP and NSS_LDAP Post 302507552 by zaxxon on Thursday 24th of March 2011 07:15:39 AM
Old 03-24-2011
Thanks for your answer.

Yes, "AIX for LDAP" is a term I tend to use when at least secldapclntd is involved on the client side. Sorry if I confused you. I use it that way to make a clear difference between it and OpenLDAP which is also used on Linux boxes in our environment.

For administrative accounts, we have a similar layout as you have in your environment. DBAs connect with ssh (your hosts.equiv/rlogin is not encrypted) to the DB box, authenticate against LDAP, su to a local account, since these can be members of local groups according the IBM Redbook "Integrating AIX into heterogenous LDAP Environment" (sg247165). They are also allowed to sudo su to informix.

Our problem is, that normal users use a Windows application which connects to the database and the database will check for the local credential, which are just local. So this PAM_LDAP thing would have been a way to implement an authentication via LDAP for every user.
Changing the user's application to authenticate vs LDAP first is sadly not an option.
 

2 More Discussions You Might Find Interesting

1. Solaris

nss_ldap by padl on Solaris 10

Hi all! (I don't know whether this question should go here or not. I'm newbie on forum) So, i have trouble using nss_ldap by padl with Openldap database. I've installed nss_ldap by padl(padl.com) and i think it installed ok. It was not easy because i had to fix some source files a little by... (0 Replies)
Discussion started by: kukuruku
0 Replies

2. Debian

nss_ldap failed to bind to LDAP server

Hi every body! I have an debian lenny server with samba and openldap on it. 1. Problem: i can not login ldap user auth.log: nss_ldap: could not connect to any LDAP server as cn=admin,dc=innsbruck,dc=sti,dc=at - Can't contact LDAP server 2. Problem: auth.log: nss_ldap: failed to bind to... (1 Reply)
Discussion started by: magge
1 Replies
pam_ldap(8)						      System Manager's Manual						       pam_ldap(8)

NAME
pam_ldap - PAM module for LDAP-based authentication SYNOPSIS
pam_ldap.so [...] DESCRIPTION
This is a PAM module that uses an LDAP server to verify user access rights and credentials. OPTIONS
use_first_pass Specifies that the PAM module should use the first password provided in the authentication stack and not prompt the user for a pass- word. try_first_pass Specifies that the PAM module should use the first password provided in the authentication stack and if that fails prompt the user for a password. nullok Specifying this option allows users to log in with a blank password. Normally logins without a password are denied. ignore_unknown_user Specifies that the PAM module should return PAM_IGNORE for users that are not present in the LDAP directory. This causes the PAM framework to ignore this module. ignore_authinfo_unavail Specifies that the PAM module should return PAM_IGNORE if it cannot contact the LDAP server. This causes the PAM framework to ig- nore this module. no_warn Specifies that warning messages should not be propagated to the PAM application. use_authtok This causes the PAM module to use the earlier provided password when changing the password. The module will not prompt the user for a new password (it is analogous to use_first_pass). debug This option causes the PAM module to log debugging information to syslog(3). minimum_uid=UID This option causes the PAM module to ignore the user if the user id is lower than the specified value. This can be used to bypass LDAP checks for system users (e.g. by setting it to 1000). MODULE SERVICES PROVIDED
All services are provided by this module but currently sessions changes are not implemented in the nslcd daemon. FILES
/etc/pam.conf the main PAM configuration file /etc/nslcd.conf The configuration file for the nslcd daemon (see nslcd.conf(5)) SEE ALSO
pam.conf(5), nslcd(8), nslcd.conf(5) AUTHOR
This manual was written by Arthur de Jong <arthur@arthurdejong.org>. Version 0.8.10 Jun 2012 pam_ldap(8)
All times are GMT -4. The time now is 05:54 AM.
Unix & Linux Forums Content Copyright 1993-2022. All Rights Reserved.
Privacy Policy