[29468] in Kerberos

home help back first fref pref prev next nref lref last post

Re: login restriction

daemon@ATHENA.MIT.EDU (Franco Milicchio)
Wed Mar 12 06:58:49 2008

Message-Id: <D71624C3-3654-468A-BCD3-1C69930CC71A@mac.com>
From: Franco Milicchio <senseiwa@mac.com>
To: "=?ISO-8859-1?Q?Roberto_C._S=E1nchez?=" <roberto@connexer.com>
In-Reply-To: <20080312104308.GA24013@connexer.com>
Mime-Version: 1.0 (Apple Message framework v919.2)
Date: Wed, 12 Mar 2008 11:57:52 +0100
Cc: kerberos@mit.edu
Content-Type: text/plain; charset="iso-8859-1"
Errors-To: kerberos-bounces@mit.edu
Content-Transfer-Encoding: 8bit


On Mar 12, 2008, at 11:43 AM, Roberto C. Sánchez wrote:

> On Wed, Mar 12, 2008 at 10:29:07AM +0100, Marcin N wrote:
>> Hello again
>> I'm wondering if it is possible to make restriction on which hosts  
>> users
>> authorized by kerberos can log on.
>> For now only users who have local account (so they are in /etc/ 
>> password
>> and /etc/shadow) can log in to the machine.
>> But is there possibility to control it via any kind of access list or
>> something like that - which would be managed on kdc?
>> i would like to have all users local accounts on every machine and
>> decide which user can log to specific machine by setting it on kdc...
>> is it possible?
>>
> Kerberos is for authentication, not authorization.  You use something
> like LDAP for authorization.

Or use PAM with groups (either on LDAP or in /etc).
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos


home help back first fref pref prev next nref lref last post