Re: Restricting client access using pam_groupdn with dynamic groups : Was[Re: restrict host login based on group]

2010-06-14 Thread Adam Hough
On Mon, Jun 14, 2010 at 12:32 AM, Shamika Joshi shamika.jo...@gmail.comwrote: Ya here it is ...output of slapcat attached. Please let me knw if u could see anything missing from this. Thanks regards Shamika Howard, I will remember that. I always use the ldap commands normally since I

Re: Restricting client access using pam_groupdn with dynamic groups : Was[Re: restrict host login based on group]

2010-06-11 Thread Shamika Joshi
Hi Adam, sorry coz of workload it took me while to revisit my configuration verify things you mentioned. As far as I could understand things look quite in place. I have pasted my configurations mapping exactly yours. Could you kindly take a look at it for me pls? PWD=/etc/openldap/slapd.d # ls

Re: Restricting client access using pam_groupdn with dynamic groups : Was[Re: restrict host login based on group]

2010-06-11 Thread Howard Chu
Shamika Joshi wrote: Hi Adam, sorry coz of workload it took me while to revisit my configuration verify things you mentioned. As far as I could understand things look quite in place. I have pasted my configurations mapping exactly yours. Could you kindly take a look at it for me pls?

Re: Restricting client access using pam_groupdn with dynamic groups : Was[Re: restrict host login based on group]

2010-06-04 Thread Adam Hough
My guess is that your config on the server is not right. So it looks like you are using the slap.d which is what i am using as well. (I need to upload some updated rpms I think to gradientzero as well). I used this site to help me get my configuration working

Re: restrict host login based on group

2009-12-11 Thread Adam Hough
I am guessing you are either using RHEL5, Centos5 or some other RHEL5 based distro. I replaced the openldap that was on my centos5 machines with an newer version at 2.4.16+patches. I have uploaded the rpms and srpms of what I used which you can do a drop in replacement of the RHEL5 based

Re: restrict host login based on group

2009-12-10 Thread Adam Hough
There are other ways to populate the pam_groupdn that you have associated with each machine but those all correspond to some attribute in the user's profile. I have pam_groupdn setup like this /etc/ldap.conf: pam_groupdn cn=GROUP_NAME,ou=Systems,dc=domain,dc=com pam_member_attribute member

Re: restrict host login based on group

2009-12-10 Thread Shamika Joshi
Hi Adam, This is interesting, and I went ahead to try it out but I'm getting some hickups here, when I enter following in my slapd.conf overlay dynlist dynlist-attrset groupOfNames labeledURI member it throws me following error: [r...@xrh3 /]# service ldap start Checking configuration files for

Re: restrict host login based on group

2009-12-04 Thread Shamika Joshi
Hi all, I'm stuck in the same issue as Serge Fonville. I have created new Auxiliary objectclass 'testobj' with 'host' attribute added it to the ou=Groups.Then created 2 entries under Groups as below assigned members to those groups. dn: cn=qagroup,ou=Groups,dc=test,dc=com cn: qagroup gidNumber: