[1700] in athena10

home help back first fref pref prev next nref lref last post

Re: nss: hesiod -> ldap for groups?

daemon@ATHENA.MIT.EDU (Mitchell E Berger)
Sun Mar 15 17:36:29 2009

Message-Id: <200903152135.n2FLZVL4023980@byte-me.mit.edu>
To: Geoffrey Thomas <geofft@MIT.EDU>
cc: Jacob Morzinski <morzinski@MIT.EDU>, athena10@MIT.EDU
In-Reply-To: Your message of "Sun, 15 Mar 2009 05:01:19 EDT."
             <alpine.DEB.2.00.0903150458410.6214@geminorum.mit.edu> 
Date: Sun, 15 Mar 2009 17:35:31 -0400
From: Mitchell E Berger <mitchb@MIT.EDU>

> Hm, did we ever get anywhere on this discussion, e.g. getting either 
> ldap.mit.edu or win.mit.edu's LDAP servers to give us GIDs? One more 
> comment is below...

We're talking about this in the context of being able to log in based
on moira/afs/whatever group membership?  I thought after some conversation
at least you and I became convinced that it'd be not too hard to have
a PAM module query the AFS protection database for membership in the
enumerated access.conf groups, and that sidestepped the issue of figuring
out whether the various LDAP domains would be willing to change their
promised support levels.

On a related topic, though, something it won't solve is a use case I'm
presently stuck with.  I have a Debathena server (-graphical-login-to-be)
on which I want to restrict access to some local files (they really do
need to be local) to a subset of users.  I don't really care much whether
I have to enumerate the users locally on the machine or put them on
a moira list.  But as far as I understand, I basically can't do this at
all if any of the users are affected by the hesiod grplist length issue.
If I use an NFS group to control it, some people (nondeterministically)
won't have the bits they need, and if I do what we did on the Athena 9
implementation of this server (create a local group and enumerate the
users in /etc/group{.local}) nss-nonlocal will punt the users from the
group when they log in with their Athena account.  Is there either a
current correct way to cope with this, or a way to tell nss-nonlocal
to leave a given local group's nonlocal membership alone?  I guess
maybe I can punt nss-nonlocal from the PAM config... will that just
work, or am I going to get bitten elsewhere?

Mitch


home help back first fref pref prev next nref lref last post