[Date Prev][Date Next]
[Chronological]
[Thread]
[Top]
Re: LDAPS and ssh public key
- To: Клеусов Владимир Сергеевич <Kleusov.Vladimir@wildberries.ru>, openldap-technical@openldap.org
- Subject: Re: LDAPS and ssh public key
- From: Quanah Gibson-Mount <quanah@symas.com>
- Date: Fri, 14 Feb 2020 10:09:56 -0800
- Content-disposition: inline
- Dkim-filter: OpenDKIM Filter v2.10.3 zmcc-2-mta-1.zmailcloud.com 1DDFFC0A40
- Dkim-signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=symas.com; s=37C7994C-28CA-11EA-A30F-68F90BB9D764; t=1581703795; bh=Kas0iC3HcdJbf7P2a/t1fyjiyeYbfAjdmbwtjA94xgg=; h=Date:From:To:Message-ID:MIME-Version; b=eMwRUvv1WZzxHbvlnbvrPR2ZAWE3EnW5tLMW+iOOu+iz73t84tDLVCQ7Itf7TADCZ jvcC106NnDu9420S4Lug3Kx1n0ffnj6MdE/wB18Sr64pVc21n+zxOS/t+gr4hsV7uX uD+/wBhnKPHZvbK1fxv4aSPNEGUD0uBBCZG9BiXeP42auIyTWREXFXJtkgxFF9F2N2 NMF8jv9eOnIOt8hjKqU9F4D4KNusuYWhDW/vIMtqAcLZG/suwsSocDeSDuUWC4xc6O iLIpGTn+iYOWbFd3F6VB70CwldDAkTWQiAQPuGrC62SoYrVeZS+HzSZEfgemgdtu1a lzdXsExMiQ0zA==
- In-reply-to: <96FBD3ED-02D2-44A5-AA5D-A68ED0B2FB92@wildberries.ru>
- References: <96FBD3ED-02D2-44A5-AA5D-A68ED0B2FB92@wildberries.ru>
--On Friday, February 14, 2020 10:41 AM +0000 Клеусов
Владимир Сергеевич <Kleusov.Vladimir@wildberries.ru> wrote:
Hi
I use ldaps . Will I be able to set up authentication using the SSH
public key ? I use LDAP account Manager
(https://www.ldap-account-manager.org/lamcms/) Here
https://www.ldap-account-manager.org/static/doc/manual/ch04s02.html now
You can manage your public keys for SSH in Lam if you have installed the
LPK patch for SSH or configured AUTHORIZEDKEYSCOMMAND& What does OR mean
? Google says that i need to download the scheme for SSH keys and add the
script to AUTHORIZEDKEYSCOMMAND. But in
https://code.google.com/archive/p/openssh-lpk/wikis/Main.wiki written To
use lpk you must either use standard ldap (not recommended) or LDAP +
TLS. ldaps:// URLs will not work. So in the end ssh key +LDAPS will not
work ? Or is there a way to use ssh key +LDAPS ?
OpenSSH incorporated the patch with OpenSSH 6.2 or later, so patching
OpenSSH is no longer necessary.
The openssh-lpk script I have can be used with ldaps w/o issue
(<https://gitlab.symas.net/quanah/ldap-tools/blob/master/ssh/openssh-lpk>).
You will need to have the correct schema for SSH, such as
<http://pig.made-it.com/ldap-openssh/openssh-ldap.schema>
Regards,
Quanah
--
Quanah Gibson-Mount
Product Architect
Symas Corporation
Packaged, certified, and supported LDAP solutions powered by OpenLDAP:
<http://www.symas.com>