FDS / PAM Integration Questions

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Hi All,
I am interested in switching from MIT Kerberos5 (GSSAPI/SASL), OpenLDAP to FDS.  Primarily, I'm looking for authentication and authorization for fedora / centos console logins (via PAM).

Currently I have a cron job that keeps a kerberos service principal alive to allow slapd to bind to openldap (as I've also disabled anonymous binds).  I also have startTLS running w/o client authentication (just server certificates and the local client has the CA pub cert).  

I then have nsswitch/pam configured to use these for console (console,ssh,etc) logins.
I'm currently using the pam_sasl_mech GSSAPI and pam_groupdn features of the /etc/ldap.conf (/etc/openldap/ldap.conf) to manage authorization to the local system (by pointint to a posix group dn).

I was able to setup FDS to for console sessions with cleartext and nsswitch.  I'm not sure which route to take in terms of locking down FDS with a pure linux environment.  The straight SSL certificate approach seems to want the user to enter a password before a bind, so I'm not sure that's compatible with PAM.   Is TLS a better option for this?  The last option seems to be to keep Kerberos / GSSAPI, but I've read some posts where you can't easily do this.  I've tried to make the SASL mapping as the docs show, but was unsuccessful.

Can anyone point me in the right direction for the best way to accomplish secure PAM / FDS integraion?  Any help would be greatly appreciated.
Many thanks!
Jonathan




[Index of Archives]     [Fedora User Discussion]     [Older Fedora Users]     [Fedora Announce]     [Fedora Package Announce]     [EPEL Announce]     [Fedora News]     [Fedora Cloud]     [Fedora Advisory Board]     [Fedora Education]     [Fedora Security]     [Fedora Scitech]     [Fedora Robotics]     [Fedora Maintainers]     [Fedora Infrastructure]     [Fedora Websites]     [Anaconda Devel]     [Fedora Devel Java]     [Fedora Legacy]     [Fedora Desktop]     [Fedora Fonts]     [ATA RAID]     [Fedora Marketing]     [Fedora Management Tools]     [Fedora Mentors]     [Fedora Package Review]     [Fedora R Devel]     [Fedora PHP Devel]     [Kickstart]     [Fedora Music]     [Fedora Packaging]     [Centos]     [Fedora SELinux]     [Fedora Legal]     [Fedora Kernel]     [Fedora QA]     [Fedora Triage]     [Fedora OCaml]     [Coolkey]     [Virtualization Tools]     [ET Management Tools]     [Yum Users]     [Tux]     [Yosemite News]     [Yosemite Photos]     [Linux Apps]     [Maemo Users]     [Gnome Users]     [KDE Users]     [Fedora Tools]     [Fedora Art]     [Fedora Docs]     [Maemo Users]     [Asterisk PBX]     [Fedora Sparc]     [Fedora Universal Network Connector]     [Fedora ARM]

  Powered by Linux