adding an attribute, howto?

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



I would like to use the pam_passthru plugin to use kerberos  
authentication via pam_krb5, but am running into a few issues.  I  
need to specify an attribute to use, as I have multiple realms--my  
uid is just a login name, for the kerberos to work I need  
<uid>@<realm>.  I wasn't sure what to use for the attribute, and was  
thinking of hijacking the 'description' attribute for this purpose.   
However another posting to this list gave me the idea of just  
extending the schema with an additional attribute in 99user.ldif.  I  
would likely want to copy the definition for 'uid' from, say class  
posixaccount, but rename it to krb5uid or something.  Can anyone  
point me to detailed instructions?  Is this trivial or difficult?  I  
looked at the current schema files and was not sure what I wold need  
to copy to make it work, and how to add the new attribute explicitly  
to the class schema as an optional attribute.

What are the consequences of adding such an attribute when  
replication is occurring?  I assume I must extend the schema on each  
server, what happens if I neglect to extend the schema on one server  
and it receives replica info that has this new attribute populated  
for some users?

I would also entertain the idea of having an attribute with just the  
realm (or a proxy for the realm), and constructing the krbuid  
equivalent via some operational attribute that constructs it via uid  
+ "@" + realm on the fly, if this is possible.  I might even be able  
to do this using existing location attribute or another existing  
attribute, I can easily  determine the correct realm from  
corresponding location-specific info associated with each user.  But,  
I don't know how to do this in practice.

Also, if anyone has an example pam ldapserver file they could share,  
I would appreciate it.

-Marty


-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.fedoraproject.org/pipermail/389-users/attachments/20061220/2504a137/attachment.html 


[Index of Archives]     [Fedora User Discussion]     [Older Fedora Users]     [Fedora Announce]     [Fedora Package Announce]     [EPEL Announce]     [Fedora News]     [Fedora Cloud]     [Fedora Advisory Board]     [Fedora Education]     [Fedora Security]     [Fedora Scitech]     [Fedora Robotics]     [Fedora Maintainers]     [Fedora Infrastructure]     [Fedora Websites]     [Anaconda Devel]     [Fedora Devel Java]     [Fedora Legacy]     [Fedora Desktop]     [Fedora Fonts]     [ATA RAID]     [Fedora Marketing]     [Fedora Management Tools]     [Fedora Mentors]     [Fedora Package Review]     [Fedora R Devel]     [Fedora PHP Devel]     [Kickstart]     [Fedora Music]     [Fedora Packaging]     [Centos]     [Fedora SELinux]     [Fedora Legal]     [Fedora Kernel]     [Fedora QA]     [Fedora Triage]     [Fedora OCaml]     [Coolkey]     [Virtualization Tools]     [ET Management Tools]     [Yum Users]     [Tux]     [Yosemite News]     [Yosemite Photos]     [Linux Apps]     [Maemo Users]     [Gnome Users]     [KDE Users]     [Fedora Tools]     [Fedora Art]     [Fedora Docs]     [Maemo Users]     [Asterisk PBX]     [Fedora Sparc]     [Fedora Universal Network Connector]     [Fedora ARM]

  Powered by Linux