Re: NSS+LDAP+SSH setup with /home shared across several servers
[
Date Prev][
Date Next]
[
Thread Prev][
Thread Next]
Re: NSS+LDAP+SSH setup with /home shared across several servers
- From: Rafael Laboissiere <rafael [at] laboissiere.net>
- To: Thomas Orgis <thomas.orgis [at] uni-hamburg.de>
- Cc: nss-pam-ldapd-users [at] lists.arthurdejong.org
- Subject: Re: NSS+LDAP+SSH setup with /home shared across several servers
- Date: Thu, 7 May 2015 12:34:44 +0200
* Thomas Orgis <thomas.orgis@uni-hamburg.de> [2015-05-07 12:05]:
Am Thu, 7 May 2015 11:08:04 +0200
schrieb Rafael Laboissiere <rafael@laboissiere.net>:
How can an SSH key-pair authentication succeed without knowing
which is the user's home directory?
[snip]
If sshd does authentication itself, it still has the LDAP information
via NSS. Trust me, it works;-) [snip]
Ok, I trust you! :-)
I will try it, anyway.
Also, if you want to fetch the SSH keys via LDAP, you can hook any
source into OpenSSH via AuthorizedKeysCommand (`man sshd_config`).
No, I am not planning to do this, since the /home directories will be
shared and the .ssh/auhorized_keys files will be available everywhere.
Thanks for the discussion, sehr hilfreich.
Best,
Rafael
--
To unsubscribe send an email to
nss-pam-ldapd-users-unsubscribe@lists.arthurdejong.org or see
http://lists.arthurdejong.org/nss-pam-ldapd-users/