<html><body><div style="color:#000; background-color:#fff; font-family:bookman old style, new york, times, serif;font-size:13px"><div><span></span></div>Ah I would love to help but have only been a Unix sysadmin for a couple years now (came from Windows side of house) and have little coding ability. Still happy to  help in any way I can though if you can find a place/need for me. You have all been very helpful to me so I would like to give back if I can.<br>  <div id="yui_3_16_0_1_1440008615329_2672" style="font-family: bookman old style, new york, times, serif; font-size: 13px;"> <div id="yui_3_16_0_1_1440008615329_2671" style="font-family: HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif; font-size: 16px;"> <div id="yui_3_16_0_1_1440008615329_2670" dir="ltr"> <hr size="1" id="yui_3_16_0_1_1440008615329_2669">  <font face="Arial" size="2"> <b><span style="font-weight: bold;">From:</span></b> Jakub Hrozek <jhrozek@redhat.com><br> <b><span style="font-weight: bold;">To:</span></b> Martin Kosek <mkosek@redhat.com> <br><b><span style="font-weight: bold;">Cc:</span></b> Freeipa-users <freeipa-users@redhat.com> <br> <b><span style="font-weight: bold;">Sent:</span></b> Wednesday, August 19, 2015 12:23 AM<br> <b><span style="font-weight: bold;">Subject:</span></b> Re: [Freeipa-users] HBAC rules not applying to Solaris clients<br> </font> </div> <div class="y_msg_container" id="yui_3_16_0_1_1440008615329_2686"><br>On Tue, Aug 18, 2015 at 09:05:14PM +0200, Martin Kosek wrote:<br clear="none">> On 08/15/2015 07:05 PM, Natxo Asenjo wrote:<br clear="none">> ><br clear="none">> ><br clear="none">> >On Sat, Aug 15, 2015 at 5:24 PM, Rob Crittenden <<a href="mailto:rcritten@redhat.com" shape="rect" ymailto="mailto:rcritten@redhat.com">rcritten@redhat.com</a><br clear="none">> ><mailto:<a href="mailto:rcritten@redhat.com" shape="rect" ymailto="mailto:rcritten@redhat.com">rcritten@redhat.com</a>>> wrote:<br clear="none">> ><br clear="none">> >    sipazzo wrote:<br clear="none">> ><br clear="none">> ><br clear="none">> >        and my users are able to authenticate to the directory but the hbac<br clear="none">> >        rules are not being applied. Any user whether given access or not can<br clear="none">> >        login to the Solaris systems. The "allow-all" rule has been disabled, my<br clear="none">> >        nsswitch.conf file looks good and I have tried different configs of<br clear="none">> >        pam.d, including the provided example to try to resolve the issue. Am I<br clear="none">> >        missing some steps?<br clear="none">> ><br clear="none">> ><br clear="none">> >    HBAC enforcement is provided by sssd so doesn't work in Solaris.<br clear="none">> ><br clear="none">> ><br clear="none">> >one might try using solaris' RBAC system:<br clear="none">> ><br clear="none">> ><a id="yui_3_16_0_1_1440008615329_2687" href="http://www.oracle.com/technetwork/systems/security/custom-roles-rbac-jsp-140865.html" target="_blank" shape="rect">http://www.oracle.com/technetwork/systems/security/custom-roles-rbac-jsp-140865.html</a><br clear="none">> ><br clear="none">> >You would have to distribute your changes to all solaris systems.<br clear="none">> ><br clear="none">> >There is a RBAC ldap schema<br clear="none">> ><a href="http://docs.oracle.com/cd/E19455-01/806-5580/6jej518q5/index.html" target="_blank" shape="rect">http://docs.oracle.com/cd/E19455-01/806-5580/6jej518q5/index.html </a>for solaris,<br clear="none">> >but I have never tried using it with freeipa.<br clear="none">> ><br clear="none">> >--<br clear="none">> >Groeten,<br clear="none">> >natxo<br clear="none">> <br clear="none">> Alternatively, you can also contribute to Jakub Hrozek's pam_hbac project:<br clear="none">> <br clear="none">> <a href="https://github.com/jhrozek/pam_hbac" target="_blank" shape="rect">https://github.com/jhrozek/pam_hbac</a><br clear="none"><br clear="none">btw I have quite a few changes from the last weeks, so yes, I'm still<br clear="none">working on this, but the progress is slow, RHEL maintenance tends to eat<br clear="none">most time..<div class="qtdSeparateBR"><br><br></div><div class="yqt2864356393" id="yqtfd98516"><br clear="none"><br clear="none">-- <br clear="none">Manage your subscription for the Freeipa-users mailing list:<br clear="none"><a href="https://www.redhat.com/mailman/listinfo/freeipa-users" target="_blank" shape="rect">https://www.redhat.com/mailman/listinfo/freeipa-users</a><br clear="none">Go to <a href="http://freeipa.org/" target="_blank" shape="rect">http://freeipa.org </a>for more info on the project<br clear="none"></div><br><br></div> </div> </div>  </div></body></html>