logo       

Re: RE: [pamldap] if ldap server is down - no ssh prompt or local logins wo: msg#00002

ldap.padl.nss

Subject: Re: RE: [pamldap] if ldap server is down - no ssh prompt or local logins work

"Mike Burns" <mburns@xxxxxxx> writes:

> Use pam_succeed_if to limit what accounts are checked via LDAP
>
> -----
> account required /lib/security/$ISA/pam_unix.so broken_shadow
> account sufficient /lib/security/$ISA/pam_localuser.so
> account sufficient /lib/security/$ISA/pam_succeed_if.so uid < 100
> quiet
> account [ default=ok user_unknown=ignore service_err=ignore
> system_err=ignore ] /lib/security/$ISA/pam_ldap.so

Interesting.

Why is the pam_localuser needed - isn't pam_unix enough?

\EF
--
Erik Forsberg OpenSource-based Thin Client Technology
Cendio AB Phone: +46-13-21 46 00
Web: http://www.cendio.com




<Prev in Thread] Current Thread [Next in Thread>
Google Custom Search

News | FAQ | advertise