<html>
  <head>
    <meta content="text/html; charset=UTF-8" http-equiv="Content-Type">
  </head>
  <body text="#000000" bgcolor="#FFFFFF">
    <div class="moz-cite-prefix">On 03/24/2015 01:15 PM, Ben .T.George
      wrote:<br>
    </div>
    <blockquote
cite="mid:CA+C_GOV6b4OHLM3+CDA07qJe8Zd1ddTa0rVwce4EWF7aUTgkSw@mail.gmail.com"
      type="cite">
      <div dir="ltr">Hi
        <div><br>
        </div>
        <div>current stage is AD users can able to login to solaris box.
          But i don't up to what level i can control the user.</div>
        <div><br>
        </div>
        <div>i don't think to there is much pan modules in solaris.
          still i cannot able to make home directory with pam.</div>
      </div>
    </blockquote>
    <br>
    I think pam_groupdn (if available on Solaris) might help but I could
    not find a clear example to share with you here.<br>
    <br>
    <blockquote
cite="mid:CA+C_GOV6b4OHLM3+CDA07qJe8Zd1ddTa0rVwce4EWF7aUTgkSw@mail.gmail.com"
      type="cite">
      <div dir="ltr">
        <div><br>
        </div>
        <div><br>
        </div>
      </div>
      <div class="gmail_extra"><br>
        <div class="gmail_quote">On Tue, Mar 24, 2015 at 4:42 PM, Dmitri
          Pal <span dir="ltr"><<a moz-do-not-send="true"
              href="mailto:dpal@redhat.com" target="_blank">dpal@redhat.com</a>></span>
          wrote:<br>
          <blockquote class="gmail_quote" style="margin:0 0 0
            .8ex;border-left:1px #ccc solid;padding-left:1ex">
            <div text="#000000" bgcolor="#FFFFFF">
              <div>
                <div class="h5">
                  <div>On 03/24/2015 07:20 AM, Ben .T.George wrote:<br>
                  </div>
                  <blockquote type="cite">
                    <div dir="ltr">HI
                      <div><br>
                      </div>
                      <div>i am using IPA 3.3 and my client is solaris
                        10.</div>
                      <div><br>
                      </div>
                      <div>how can i give only some set of users to this
                        client without creating user group in ad?</div>
                      <div><br>
                      </div>
                      <div>thanks & Regards,</div>
                      <div>Ben</div>
                    </div>
                    <br>
                    <fieldset></fieldset>
                    <br>
                  </blockquote>
                  <br>
                </div>
              </div>
              You can create a group in IPA and make Solaris check that
              group at the access phase of PAM if Solaris is capable of
              checking groups this way.<span class="HOEnZb"><font
                  color="#888888"><br>
                  <br>
                  <pre cols="72">-- 
Thank you,
Dmitri Pal

Sr. Engineering Manager IdM portfolio
Red Hat, Inc.</pre>
                </font></span></div>
            <br>
            --<br>
            Manage your subscription for the Freeipa-users mailing list:<br>
            <a moz-do-not-send="true"
              href="https://www.redhat.com/mailman/listinfo/freeipa-users"
              target="_blank">https://www.redhat.com/mailman/listinfo/freeipa-users</a><br>
            Go to <a moz-do-not-send="true" href="http://freeipa.org"
              target="_blank">http://freeipa.org</a> for more info on
            the project<br>
          </blockquote>
        </div>
        <br>
      </div>
    </blockquote>
    <br>
    <br>
    <pre class="moz-signature" cols="72">-- 
Thank you,
Dmitri Pal

Sr. Engineering Manager IdM portfolio
Red Hat, Inc.</pre>
  </body>
</html>