10-08-2018
Hi,
Thanks bgstack15 for your answer.
i use sssd , the allow_simple_group use groups from the AD or local group ?
Vincent
10 More Discussions You Might Find Interesting
1. UNIX for Dummies Questions & Answers
how can i find my own ip address from unix. command like who -x .this would provide all the ip address but i need to list only current user ip address. who am i command does not display the ip. (1 Reply)
Discussion started by: naushad
1 Replies
2. UNIX for Dummies Questions & Answers
how can i find my own ip address from unix. command like who -x .this would provide all the ip address but i need to list only current user ip address. who am i command does not display the ip. (9 Replies)
Discussion started by: naushad
9 Replies
3. UNIX for Dummies Questions & Answers
Thanks
AVKlinux (3 Replies)
Discussion started by: avklinux
3 Replies
4. OS X (Apple)
Hi,
I'm brand new here and looking for a solution:
I'm using mail or mailx. The default reply address is «myshortusername@mylongusername.local» which makes absolutely no sense for anybody receiving my emails.
But how do I change it? There seem to be many solutions but none for Mac OS X.... (0 Replies)
Discussion started by: gczychi
0 Replies
5. UNIX for Advanced & Expert Users
Besides doing some shell-script which loops through /etc/passwd, I was wondering if there was some command that would tell me, like an enhanced version of getent.
The Operating system is Solaris 10 (recent-ish revision) using Sun DS for LDAP. (5 Replies)
Discussion started by: ckmehta
5 Replies
6. Shell Programming and Scripting
Hi Gurus,
I have a script that requires me to switch from local user to root. Anyone who has an idea on this since when i switch user to root it requires me to input root password.
It seems that i need to use expect module here, but i don't know how to create the object for this.
... (1 Reply)
Discussion started by: linuxgeek
1 Replies
7. Solaris
Here is the log im pasting for verbose ssh:
-bash-2.05b$ ssh -v qa_fnp@10.41.11.23
OpenSSH_3.6.1p2, SSH protocols 1.5/2.0, OpenSSL 0x0090701f
debug1: Reading configuration data /etc/ssh/ssh_config
debug1: Applying options for *
debug1: Rhosts Authentication disabled, originating port will... (5 Replies)
Discussion started by: kirtikjr
5 Replies
8. UNIX for Dummies Questions & Answers
How to fetch only local user without duplication from /etc/passwd using scripting?? (4 Replies)
Discussion started by: AhmedLakadkutta
4 Replies
9. Red Hat
Hi
We have these specific requirements for a bunch of servers we have and cannot seem to get pam to behave in this way. We would like:
PAM locks accounts if pam tally reaches 10.
PAM unlocks the account after 30mins from locking it, and resets the pam_tally.
The key is that we don't... (0 Replies)
Discussion started by: snoop2048
0 Replies
10. Shell Programming and Scripting
Hi,
I need to switch from local user to root user in a shell script.
I need to make it automated so that it doesn't prompt for the root password.
I heard the su command will do that work but it prompt for the password.
and also can someone tell me whether su command spawns a new shell or... (1 Reply)
Discussion started by: Little
1 Replies
LEARN ABOUT CENTOS
sssd-simple
SSSD-SIMPLE(5) File Formats and Conventions SSSD-SIMPLE(5)
NAME
sssd-simple - the configuration file for SSSD's 'simple' access-control provider
DESCRIPTION
This manual page describes the configuration of the simple access-control provider for sssd(8). For a detailed syntax reference, refer to
the "FILE FORMAT" section of the sssd.conf(5) manual page.
The simple access provider grants or denies access based on an access or deny list of user or group names. The following rules apply:
o If all lists are empty, access is granted
o If any list is provided, the order of evaluation is allow,deny. This means that any matching deny rule will supersede any matched allow
rule.
o If either or both "allow" lists are provided, all users are denied unless they appear in the list.
o If only "deny" lists are provided, all users are granted access unless they appear in the list.
CONFIGURATION OPTIONS
Refer to the section "DOMAIN SECTIONS" of the sssd.conf(5) manual page for details on the configuration of an SSSD domain.
simple_allow_users (string)
Comma separated list of users who are allowed to log in.
simple_deny_users (string)
Comma separated list of users who are explicitly denied access.
simple_allow_groups (string)
Comma separated list of groups that are allowed to log in. This applies only to groups within this SSSD domain. Local groups are not
evaluated.
simple_deny_groups (string)
Comma separated list of groups that are explicitly denied access. This applies only to groups within this SSSD domain. Local groups are
not evaluated.
Specifying no values for any of the lists is equivalent to skipping it entirely. Beware of this while generating parameters for the simple
provider using automated scripts.
Please note that it is an configuration error if both, simple_allow_users and simple_deny_users, are defined.
EXAMPLE
The following example assumes that SSSD is correctly configured and example.com is one of the domains in the [sssd] section. This examples
shows only the simple access provider-specific options.
[domain/example.com]
access_provider = simple
simple_allow_users = user1, user2
SEE ALSO
sssd(8), sssd.conf(5), sssd-ldap(5), sssd-krb5(5), sssd-simple(5), sssd-ipa(5), sssd-ad(5), sssd-sudo(5),sss_cache(8), sss_debuglevel(8),
sss_groupadd(8), sss_groupdel(8), sss_groupshow(8), sss_groupmod(8), sss_useradd(8), sss_userdel(8), sss_usermod(8), sss_obfuscate(8),
sss_seed(8), sssd_krb5_locator_plugin(8), sss_ssh_authorizedkeys(8), sss_ssh_knownhostsproxy(8),pam_sss(8).
AUTHORS
The SSSD upstream - http://fedorahosted.org/sssd
SSSD
06/17/2014 SSSD-SIMPLE(5)