OpenSSH, PAM, and NSS
Once the pam_ldap and nss_ldap shared libraries have been installed and /etc/ldap.conf has been configured, you can configure individual services to use the new PAM module. We’ll start with the SSH daemon, sshd . Here’s how to set up OpenSSH (http://www.openssh.com/ ) on a Linux system, which uses a separate PAM configuration file per service. (Note that other systems may use a single PAM file for all services; for example, Solaris uses /etc/pam.conf.) Make sure that PAM is enabled when you compile the sshd daemon; otherwise, you will be wasting your time.
The following
/etc/pam.d/sshd
configuration file defines
the pam_ldap library to be used for authentication
(auth) and account management
(account). The account management library checks
for password aging according to the attribute types defined for the
shadowAccount object class and verifies any
host-based access rules (covered in the next section). The
session module type is ignored by the pam_ldap
library. While user password changes are supported by the pam_ldap
library, these are not relevent to this example.
## /etc/pam.d/sshd ## PAM configuration file for OpenSSH server auth required /lib/security/pam_nologin.so auth sufficient /lib/security/pam_ldap.so auth required /lib/security/pam_unix.so shadow nullok use_first_pass account sufficient /lib/security/pam_ldap.so account required /lib/security/pam_unix.so password required /lib/security/pam_cracklib.so password required /lib/security/pam_unix.so ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access