pam_krb5/ldap access control with Active Directory

Scott Ruckh sruckh at gemneye.org
Thu Sep 14 19:23:01 UTC 2006


How do you control access?

For example,  say you have 3 groups (A, B, and C).  Users of Group A
should have access to all servers, Group B should have access to only a
few servers, and Group C will have access to a few servers.

Obviously each server's ldap.conf file could contain configurations using
different AD containers to limit access, but how would you handle access
for the below situation?

Severs: Groups that have access

Server 1:  Group A, Group B, and Group C
Server 2:  Group A
Server 3:  Group A and Group C

Thanks.
-- 
Scott





More information about the Pam-list mailing list