[29476] in Kerberos
RE: login restriction
daemon@ATHENA.MIT.EDU (Edgecombe, Jason)
Wed Mar 12 13:21:23 2008
Content-class: urn:content-classes:message
MIME-Version: 1.0
Date: Wed, 12 Mar 2008 08:41:39 -0400
Message-ID: <A01ABA2A211C644596549C5FF91C50E41DA78A4B@EXEVS02.its.uncc.edu>
In-Reply-To: <fr87om$mj9$1@news.onet.pl>
From: "Edgecombe, Jason" <jwedgeco@uncc.edu>
To: "Marcin N" <nichu@nospam.onet.pl>, <kerberos@mit.edu>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu
Try looking at pam_list pam module if you run unix.
Jason Edgecombe
Solaris & Linux Administrator
Mosaic Computing Group, College of Engineering
UNC-Charlotte
Phone: (704) 687-3514
-----Original Message-----
From: kerberos-bounces@mit.edu [mailto:kerberos-bounces@mit.edu] On
Behalf Of Marcin N
Sent: Wednesday, March 12, 2008 5:29 AM
To: kerberos@mit.edu
Subject: login restriction
Hello again
I'm wondering if it is possible to make restriction on which hosts users
authorized by kerberos can log on.
For now only users who have local account (so they are in /etc/password
and /etc/shadow) can log in to the machine.
But is there possibility to control it via any kind of access list or
something like that - which would be managed on kdc?
i would like to have all users local accounts on every machine and
decide which user can log to specific machine by setting it on kdc...
is it possible?
Regards
nichu
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos
________________________________________________
Kerberos mailing list Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos