[1694] in athena10

home help back first fref pref prev next nref lref last post

Re: nss: hesiod -> ldap for groups?

daemon@ATHENA.MIT.EDU (Geoffrey Thomas)
Sun Mar 15 05:02:16 2009

Date: Sun, 15 Mar 2009 05:01:19 -0400 (EDT)
From: Geoffrey Thomas <geofft@MIT.EDU>
To: Jacob Morzinski <morzinski@mit.edu>
cc: athena10@mit.edu
In-Reply-To: <w6m63k0sglr.fsf@horobi.mit.edu>
Message-ID: <alpine.DEB.2.00.0903150458410.6214@geminorum.mit.edu>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII; format=flowed

Hm, did we ever get anywhere on this discussion, e.g. getting either 
ldap.mit.edu or win.mit.edu's LDAP servers to give us GIDs? One more 
comment is below...

On Tue, 27 Jan 2009, Jacob Morzinski wrote:

> Geoffrey Thomas <geofft@MIT.EDU> writes:
>> Hm, I'm not familiar with MIT's AD setup. Is the LDAP server
>> win.mit.edu, or something else? I'm not sure how to bind to it to
>> query and poke at it; there's no ldap/win.mit.edu keytab, and it
>> seems not to accept simple authentication (-x).
>
> My first impression is that AD on win.mit.edu does a better job
> of holding useful information than ldap.mit.edu does.
> Unfortunately, AD on win.mit.edu is awkward to access.
>
> I had to build a local kerberized ldapsearch (actually, a local libsasl)
> and hack my machine's krb5.conf to know that .win.mit.edu = WIN.MIT.EDU;
> but this was a few years ago, and I've forgotten the precise details
> of the bugs/warts I was working around.

I believe we're going to need to be able to do simple binds without 
privileges against whatever server stores MIT accounts: cluster machines, 
before you log in, simply do not have any Kerberos principals on them to 
authenticate with.

-- 
Geoffrey Thomas
geofft@mit.edu

home help back first fref pref prev next nref lref last post