Scarpozzi
Lifer
I'm wanting to setup LDAP Authentication using PAM & OpenLDAP. I configured a server to run OpenLDAP and have it working with my ldap browser (ssl on 636). I made a few accounts and want to use them to authenticate some linux accounts local to about 10 servers.
We have a password policy that requires 10 accounts across about 15 systems(and growing) to be changed once a month. I'm trying to come up with a way to make this pw change as streamlined as possible with less chance of me making a typo somewhere and locking accounts (including root). If I can configure LDAP auth, I'm at least centralizing any problems for the common user accounts as long as the client-auth works and the ldap server/servers are up.
Does anyone have any direct configuration documentation on how to do this easily? I've been reading up and haven't found a good guide yet. I'm running RHEL(LDAP PAM Clients)& CentOS (OpenLDAP Server)
If you have good/bad experiences with this kind of configuration, send me stories too. I'm a little reluctant to use this full time unless I can use ldap to update the local accounts dynamically without server restarts and to know that the users can still access the local server accounts when LDAP is unavailable.
Thanks-
We have a password policy that requires 10 accounts across about 15 systems(and growing) to be changed once a month. I'm trying to come up with a way to make this pw change as streamlined as possible with less chance of me making a typo somewhere and locking accounts (including root). If I can configure LDAP auth, I'm at least centralizing any problems for the common user accounts as long as the client-auth works and the ldap server/servers are up.
Does anyone have any direct configuration documentation on how to do this easily? I've been reading up and haven't found a good guide yet. I'm running RHEL(LDAP PAM Clients)& CentOS (OpenLDAP Server)
If you have good/bad experiences with this kind of configuration, send me stories too. I'm a little reluctant to use this full time unless I can use ldap to update the local accounts dynamically without server restarts and to know that the users can still access the local server accounts when LDAP is unavailable.
Thanks-