Re: [osol-discuss] Account only available when LDAP is not?

2008-10-28 Thread Milan Jurik
Johan Hartzenberg píše v Út 28. 10. 2008 v 16:16 +0200: > > > On Tue, Oct 28, 2008 at 1:10 PM, Milan Jurik <[EMAIL PROTECTED]> > wrote: > > > > Login is not cached and it's pam.conf relevant (mostly). > > I fail to see how this is more relevant to pam.conf than

Re: [osol-discuss] Account only available when LDAP is not?

2008-10-28 Thread Johan Hartzenberg
On Tue, Oct 28, 2008 at 1:10 PM, Milan Jurik <[EMAIL PROTECTED]> wrote: > > > Login is not cached and it's pam.conf relevant (mostly). > I fail to see how this is more relevant to pam.conf than to name services, seeing as the OP asked for a solution which makes a local name service entry only ava

Re: [osol-discuss] Account only available when LDAP is not?

2008-10-28 Thread Milan Jurik
Hi Johan, Johan Hartzenberg píše v Po 27. 10. 2008 v 20:20 +0200: > > > On Mon, Oct 27, 2008 at 6:25 PM, Josh Rivel <[EMAIL PROTECTED]> > wrote: > Does not seem to work and then local accounts (i.e. root) are > not seen as valid ones unless LDAP is down (which is not what >

Re: [osol-discuss] Account only available when LDAP is not?

2008-10-28 Thread Moritz Willers
have you tried thinking about the problem in terms of pam.conf instead of nsswitch.conf? You seem to me more concerned about the authentication process than the name resolution. - mo On 27 Oct 2008, at 6:20 pm, Johan Hartzenberg wrote: > > > On Mon, Oct 27, 2008 at 6:25 PM, Josh Rivel <[EMAI

Re: [osol-discuss] Account only available when LDAP is not?

2008-10-27 Thread Johan Hartzenberg
On Mon, Oct 27, 2008 at 6:25 PM, Josh Rivel <[EMAIL PROTECTED]> wrote: > Does not seem to work and then local accounts (i.e. root) are not seen as > valid ones unless LDAP is down (which is not what we need) We just need a > single account to only be able to login if LDAP is down. I suppose I co

Re: [osol-discuss] Account only available when LDAP is not?

2008-10-27 Thread Josh Rivel
Does not seem to work and then local accounts (i.e. root) are not seen as valid ones unless LDAP is down (which is not what we need) We just need a single account to only be able to login if LDAP is down. I suppose I could put something into that users .profile checking for the LDAP server and

Re: [osol-discuss] Account only available when LDAP is not?

2008-10-24 Thread Ian Collins
Josh Rivel wrote: > I would like to have a local admin type account on ~700 Open Solaris snv_81 > boxes that can only be used when LDAP is *not* working. > > When the network is up and running we would like all access to be only for > LDAP users, but if LDAP is down, there is a "backdoor" in via

[osol-discuss] Account only available when LDAP is not?

2008-10-24 Thread Josh Rivel
I would like to have a local admin type account on ~700 Open Solaris snv_81 boxes that can only be used when LDAP is *not* working. When the network is up and running we would like all access to be only for LDAP users, but if LDAP is down, there is a "backdoor" in via the router that the OpenSo