> Thanks for the info, the sshd_config file may be the way to go. ?We > already use cfengine so it would be fairly easy to implement and push > out to all our servers. Speaking of cfengine, I would like to use this to push out the /etc/pam.d/system-auth and other files required for ldap authentication and user information. Are there any other files on the client machines that will be required to make this work? I used the GUI tool (system-config-authentication) to flip on LDAP auth on my test machine.