[1694] in athena10
Re: nss: hesiod -> ldap for groups?
daemon@ATHENA.MIT.EDU (Geoffrey Thomas)
Sun Mar 15 05:02:16 2009
Date: Sun, 15 Mar 2009 05:01:19 -0400 (EDT)
From: Geoffrey Thomas <geofft@MIT.EDU>
To: Jacob Morzinski <morzinski@mit.edu>
cc: athena10@mit.edu
In-Reply-To: <w6m63k0sglr.fsf@horobi.mit.edu>
Message-ID: <alpine.DEB.2.00.0903150458410.6214@geminorum.mit.edu>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII; format=flowed
Hm, did we ever get anywhere on this discussion, e.g. getting either
ldap.mit.edu or win.mit.edu's LDAP servers to give us GIDs? One more
comment is below...
On Tue, 27 Jan 2009, Jacob Morzinski wrote:
> Geoffrey Thomas <geofft@MIT.EDU> writes:
>> Hm, I'm not familiar with MIT's AD setup. Is the LDAP server
>> win.mit.edu, or something else? I'm not sure how to bind to it to
>> query and poke at it; there's no ldap/win.mit.edu keytab, and it
>> seems not to accept simple authentication (-x).
>
> My first impression is that AD on win.mit.edu does a better job
> of holding useful information than ldap.mit.edu does.
> Unfortunately, AD on win.mit.edu is awkward to access.
>
> I had to build a local kerberized ldapsearch (actually, a local libsasl)
> and hack my machine's krb5.conf to know that .win.mit.edu = WIN.MIT.EDU;
> but this was a few years ago, and I've forgotten the precise details
> of the bugs/warts I was working around.
I believe we're going to need to be able to do simple binds without
privileges against whatever server stores MIT accounts: cluster machines,
before you log in, simply do not have any Kerberos principals on them to
authenticate with.
--
Geoffrey Thomas
geofft@mit.edu