[29476] in Kerberos

home help back first fref pref prev next nref lref last post

RE: login restriction

daemon@ATHENA.MIT.EDU (Edgecombe, Jason)
Wed Mar 12 13:21:23 2008

Content-class: urn:content-classes:message
MIME-Version: 1.0
Date: Wed, 12 Mar 2008 08:41:39 -0400
Message-ID: <A01ABA2A211C644596549C5FF91C50E41DA78A4B@EXEVS02.its.uncc.edu>
In-Reply-To: <fr87om$mj9$1@news.onet.pl>
From: "Edgecombe, Jason" <jwedgeco@uncc.edu>
To: "Marcin N" <nichu@nospam.onet.pl>, <kerberos@mit.edu>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu

Try looking at pam_list pam module if you run unix.

Jason Edgecombe
Solaris & Linux Administrator
Mosaic Computing Group, College of Engineering
UNC-Charlotte
Phone: (704) 687-3514
 

-----Original Message-----
From: kerberos-bounces@mit.edu [mailto:kerberos-bounces@mit.edu] On
Behalf Of Marcin N
Sent: Wednesday, March 12, 2008 5:29 AM
To: kerberos@mit.edu
Subject: login restriction

Hello again
I'm wondering if it is possible to make restriction on which hosts users

authorized by kerberos can log on.
For now only users who have local account (so they are in /etc/password 
and /etc/shadow) can log in to the machine.
But is there possibility to control it via any kind of access list or 
something like that - which would be managed on kdc?
i would like to have all users local accounts on every machine and 
decide which user can log to specific machine by setting it on kdc...
is it possible?

Regards
nichu
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post