lists.arthurdejong.org
RSS feed

Re: NSS+LDAP+SSH setup with /home shared across several servers

[Date Prev][Date Next] [Thread Prev][Thread Next]

Re: NSS+LDAP+SSH setup with /home shared across several servers



* Thomas Orgis <thomas.orgis@uni-hamburg.de> [2015-05-07 12:05]:

Am Thu, 7 May 2015 11:08:04 +0200 schrieb Rafael Laboissiere <rafael@laboissiere.net>:

How can an SSH key-pair authentication succeed without knowing which is the user's home directory?

[snip]

If sshd does authentication itself, it still has the LDAP information via NSS. Trust me, it works;-) [snip]

Ok, I trust you! :-)

I will try it, anyway.

Also, if you want to fetch the SSH keys via LDAP, you can hook any source into OpenSSH via AuthorizedKeysCommand (`man sshd_config`).

No, I am not planning to do this, since the /home directories will be shared and the .ssh/auhorized_keys files will be available everywhere.

Thanks for the discussion, sehr hilfreich.

Best,

Rafael
--
To unsubscribe send an email to
nss-pam-ldapd-users-unsubscribe@lists.arthurdejong.org or see
http://lists.arthurdejong.org/nss-pam-ldapd-users/