lists.arthurdejong.org
RSS feed

libnss-ldapd: Stretch Client authenticating to Openldap without hosting user password in local file

[Date Prev][Date Next] [Thread Prev][Thread Next]

libnss-ldapd: Stretch Client authenticating to Openldap without hosting user password in local file



Hello,

As a proof of concept, i would like to improve the security level of Debian client machines which users are ldap users,
by having the users's password not being synchronized onto the machine passwd file.

(Just to let you know the authentication with password synchronization works perfectly.)

To do so i ended up using libnss-ldapd and i tried to shut nscd and/or nslcd and also to manipulate configuration files to achieve this.

Yet the only thing i managed to do was to have it working for the time the cache memory of the password still stick (by default 10 mins).

So in the end i would like to know:
 - First: is this achievement possible with libnss-ldapd ?
 - Second: if this is possible, would be so kind to gimme some clues about it ?
 - Third: if this isnt possible with libnss-ldapd, with which tool do you think that may be possible and would you have some hints about this ?

PS: for any further investigation, i will gladly provide exhaustive configuration of the client/server.

Regards,

Denis
-- 
To unsubscribe send an email to
nss-pam-ldapd-users-unsubscribe@lists.arthurdejong.org or see
https://lists.arthurdejong.org/nss-pam-ldapd-users/