[29467] in Kerberos
Re: login restriction
daemon@ATHENA.MIT.EDU (Roberto =?iso-8859-1?Q?C=2E_S=E1nc)
Wed Mar 12 06:44:12 2008
Date: Wed, 12 Mar 2008 06:43:08 -0400
From: Roberto =?iso-8859-1?Q?C=2E_S=E1nchez?= <roberto@connexer.com>
To: kerberos@mit.edu
Message-ID: <20080312104308.GA24013@connexer.com>
Mail-Followup-To: kerberos@mit.edu
MIME-Version: 1.0
In-Reply-To: <fr87om$mj9$1@news.onet.pl>
Content-Type: multipart/mixed; boundary="===============0078316364=="
Errors-To: kerberos-bounces@mit.edu
--===============0078316364==
Content-Type: multipart/signed; micalg=pgp-sha1;
protocol="application/pgp-signature"; boundary="k1lZvvs/B4yU6o8G"
Content-Disposition: inline
--k1lZvvs/B4yU6o8G
Content-Type: text/plain; charset=iso-8859-1
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable
On Wed, Mar 12, 2008 at 10:29:07AM +0100, Marcin N wrote:
> Hello again
> I'm wondering if it is possible to make restriction on which hosts users=
=20
> authorized by kerberos can log on.
> For now only users who have local account (so they are in /etc/password=
=20
> and /etc/shadow) can log in to the machine.
> But is there possibility to control it via any kind of access list or=20
> something like that - which would be managed on kdc?
> i would like to have all users local accounts on every machine and=20
> decide which user can log to specific machine by setting it on kdc...
> is it possible?
>=20
Kerberos is for authentication, not authorization. You use something
like LDAP for authorization.
Regards,
-Roberto
--=20
Roberto C. S=E1nchez
http://people.connexer.com/~roberto
http://www.connexer.com
--k1lZvvs/B4yU6o8G
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature
Content-Disposition: inline
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iD8DBQFH17O85SXWIKfIlGQRAq8iAKCuE9C6z1iUiK7M9KFLqpuJy4w++ACeNmD8
uXburPJTp9D6N5q4czLVC3I=
=5Uyv
-----END PGP SIGNATURE-----
--k1lZvvs/B4yU6o8G--
--===============0078316364==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos
--===============0078316364==--