SUMMARY: LDAP lookups for user/acct info

Dave Zwieback (zwieback_dave@timeplex.com)
Wed, 18 Feb 1998 10:05:09 -0500

This is a multi-part message in MIME format.

--Boundary_(ID_eOvP2azl6x3Gnv1dRKWF9w)
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7bit

Managers,

The original question was:
Has anyone gotten Solaris to work with LDAP? That is, to store all the
passwd/group info in LDAP, and have Solaris refer to it? Any suggestions on
how to get this to work, in practice?

The answers were:

Daniel J. Gregor Jr., <dj@gregor.com>:

Check out the attached message. I've used this NSS module for
LDAP on a Solaris 2.5.1 box, and it works fine. It is missing performance
enhancements, but that wasn't a major problem for me. The biggest "bug"
that you might have is that if you use it for authenticating users, they
will no longer be able to change their password with the standard Solaris
passwd program, because it doen't know how to deal with LDAP. You'll
either have to make all the users change their password some other way,
or find or write a password program that can work with LDAP.

A new release of nss_ldap is available from:

http://www.xedoc.com.au/~lukeh/ldap/nss_ldap.tar.gz

This version is compatible with the new hosts and networks schema in
draft-howard-nis-schema-02.txt, to be published shortly.

-----

David Wolfskill <david@xtend.net>

Robert Harker gave a talk at BayLISA a few months ago on LDAP & sendmail
interaction. There should be some information on what he said & what
he's figured out since at http://www.harker.com/.

----

Robert Bannocks <R.Bannocks@kingston.ac.uk>

You will need either the ldap pam module for 2.6 or the NSS module
for solaris before 2.6. I have tried the pam module and it works.
However, note it works in a diffrent way to the nss module.

look at http://redhat.com/pam for pam. Most of the pam
modules will compile under solaris as well as Linux.

----

Thanks to all who contributed!

Dave.

--Boundary_(ID_eOvP2azl6x3Gnv1dRKWF9w)
Content-type: text/x-vcard; name=vcard.vcf; charset=us-ascii
Content-description: Card for Dave Zwieback
Content-disposition: attachment; filename=vcard.vcf
Content-transfer-encoding: 7bit

begin: vcard
fn: Dave Zwieback
n: Zwieback;Dave
org: TimePlex
adr;dom: 400 Chestnut Ridge Road$Woodcliff Lake, NJ 07675;;;;;;
email;internet: Zwieback_Dave@timeplex.com
title: Unix Systems Administrator
tel;work: 391-41263
tel;fax: 201-391-0308
x-mozilla-cpt: ;0
x-mozilla-html: FALSE
version: 2.1
end: vcard

--Boundary_(ID_eOvP2azl6x3Gnv1dRKWF9w)--