Hi !
I am thinking of setting up an environment of debian machines with multiple users logging into each of them.

I understand that pam-ldapd will allow me to
- do the user management and authentication on a central ldap server
- mount the users ~home directory from a central nfs/samba server

Now, as far as i have understood users have to use username:password combos to log into the machines via pam-ldapd right ? I would really want to have users authenticated by a private key on a usb stick, with/without a password.

This seems to be what pam-usb does for local users. Do you think it would be possible to somehow get the pam-usb functionality into pam-ldapd ?

