[Date Prev][Date Next] [Chronological] [Thread] [Top]

Re: Linux: OpenLdap, PAM in cluster enviroment



Frank,
	Your looking to port your current
/etc/passwd:/etc/shadow:/etc/group information into the LDAP
datbase?   Am I correct?

This can be done.  You can you the LDAPADD and LDAPMOD tools that come
with PADL or other LDAP areas.  You'll need to somehow stream the
information from your current files to the LDAP database.  

a crude way to do this is with Sun's Directory Services which comes with
Solaris7 and Solaris8. (free).  It has an NIS/LDAP conversion tool that
will take /etc/passwd:/etc/shadow: and I think /etc/group and port them
into the SDS for NIS/LDAP/RADIUS.   It's not the best way, but it all
depends on what you want to get, your enviornment, and how you want to
attack the issue.

Good luck.


> > I try to explain what I want to do.
> 
> I got a webcluster of 6 nodes. All run Debian GNU/Linux 2.2. I run
> suExec with Apache so that cgi:s will run as the users owning the
> script. I also share the homedirectorys over NFS. 
> Now I want the useraccounts to have the same
> uid and gids on all cluster nodes (web servers) so that suExec will work. 
> I have been looking around and found this:
> 
> nss_ldap:       http://www.padl.com/nss_ldap.html
> pam_ldap:       http://www.padl.com/pam_ldap.html
> 
> Very litte documentation.
> 
> I tried the tools at: http://www.padl.com/tools.html
> Read the debian documentation and tried. But no luck.
> I don't use MD5 passwords. I use shadowpasswords.
> 
> I only need to have the /etc/passwd, /etc/shadow, /etc/group into the
> LDAP. I'm really stuck and need help.
> If I get this to work I will put up a step by step guide for this on
> my homepage and faqmatic so that other can benefit from your help.
> 
> -- 
> Regards, Fredrik Steen
> 
> 


<(/|\-/|\-/|\-/|\-/|\/-\|/-\|/-\|/|\-/|\-/|/-\|/|\-/|\-/|\/-\|/-\|/-\)>

   Sellers , Chris G.		
   Scientific Programmer Analyst 	
    Information & Instructional Technology 
    Oakland University - Rochester, Michigan 48309-4401	
    Phone: (248) 370.2016    FAX: (248) 370.4251