multihost master.passwd sync

Andy Harrison ah60 at httpsite.com
Tue May 27 12:10:43 PDT 2003


-----BEGIN PGP SIGNED MESSAGE-----


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
On 27-May-2003, Michael Collette wrote message "Re: multihost master.passwd
sync"
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
> Why not just preconfigure SSH keys between the boxes and scp the file across?
> Seems like a lot of extra work to bring PGP into the mix.

Because we don't allow root login remotely, mandated from above.

> Personally, I'm real curious about utilizing an LDAP backend to replace NIS. 
> Read a bit about it, but haven't had a chance to play with it just yet.  It 
> sounds like a far more elegant solution for what you're looking to do as 
> well.  Assuming it all works as advertised that is.

The problem is that while it allows authentication, it doesn't integrate
seamlessly allowing you to own files as a user that only exists in the ldap.



~~ 
Andy Harrison
ah##@httpsite.com
ICQ: 123472  AIM/Y!: AHinMaine
[full headers for details]

-----BEGIN PGP SIGNATURE-----
Version: PGP 6.5.8

iQCVAwUBPtO4P1PEkLgodAWVAQF15QQAsPRwL67UjAy3CxhhxT/qrYAnXgenJv2f
p1gRYI+jsQQTjMhuK0F7wlP/tkEYq8ATUjGo2c/42Cv6TKhJju6Z+9ZrY/+rJ9D/
GHwYuW1FE9cLbrEQZMHM5y0piHHGGvf6EX5EpIZQ3H5oKaO2vN+xSe+WQjAkp1Kv
aARSDBzB0v8=
=6jPd
-----END PGP SIGNATURE-----


More information about the freebsd-security mailing list