[Date Prev][Date Next]
[Chronological]
[Thread]
[Top]
Re: SSH groups
- To: Dave Macias <davama@gmail.com>
- Subject: Re: SSH groups
- From: Michael Ströder <michael@stroeder.com>
- Date: Wed, 19 Feb 2020 19:38:20 +0100
- Autocrypt: addr=michael@stroeder.com; prefer-encrypt=mutual; keydata= mQENBFbdnRoBCADj0vYA4aRwKJ6AE4mf8oElLgMT/1eLNKpJ2FYBWcwj9d8dTk5/p9b8DRxy S/qQIUUZqt9xRFZwUCm0vFeQMRDeN9xzAKoRzrJifoDOacOjG1lhZTKYvVZGgUT89Ao3QeHh Q7gPzcAKNoueoR2y3FXStOYuRrbk5PlSjVAITjsotgc7PWE9mmVYpeu8a+byK/DBHKUyolOA 1UXYvDa7MbPhMtdNm8qnwtKs1Vsyk1VkErM+5cIe+zTT6WYQcmZMRjCtWGiFTzk9W6Mdlskk WRTKhKNgokTsgcy1ecaCBUZWxv/SyXgD81+rwRi9b8Px+1reg43ayxi8sV7jrI1feybbABEB AAG0J01pY2hhZWwgU3Ryw7ZkZXIgPG1pY2hhZWxAc3Ryb2VkZXIuY29tPokBNwQTAQgAIQUC Vt2dGgIbAwULCQgHAgYVCAkKCwIEFgIDAQIeAQIXgAAKCRAH3HrjaovJOFpTCACjO773gcmJ KvzjiNpUFl/gANyaJgIq4VbMQ7VthRb1F9X6YbdJ6Z99ntyESjGFCpjofcSomr2vJDpv6ht+ lY33yo20YwsMpqe2OeId0jPybG+FtabKjgBNoAk7iqnBGUvE4t0dz0n1LQVCQR2jxyTKmcNq OYpsRZ3H+6kWwJMuVgsNZglINVZ8JgV5QuLYN5jhYz+pOuFnU11bV6nWREvzZXzebe7g7Zus 6AsWjtJ0lDvgBNzLlF3/eFrVch6Bejs0SvuFseIdZQk+4YU6Rb8xul/jDFXIfo7eTmijO3dV T5AmC1cUi8czncwpgAJnEH8vYv23RoN/aw2gSMCS2huIuQENBFbdnRoBCAC7L1cTVBVZZuM/ yxSUM5CsgGBlTD1Cr7C2ngZFsHSYXVLq6NUB8GZA2iLK96CrwnFw4/Jjz4llOjc50iVRMQKL RyFWOJAMrpPq2ew5T+Uoo524D//dwVbqkFVVuvM8NPiKIDyPGCjP+acM1D8hXwhOXgQ8Iz8Q 3/GRSYjitn9JrkF0ia2nhariznBKVu0LDffxF/hOCx45+QRR2/rYYlshfZMB7nEJX9P+hVfM CSzltz9Z8CldeUbiJvnyrISReR2XBw9oh8JkIUP0BtpIaify9A7EfzOk+W9BUnWe+YwdSUsB fJxOhSv+umyW5GMqZGFu+4oYnkzbe+1LUs1JarCtABEBAAGJAR8EGAEIAAkFAlbdnRoCGwwA CgkQB9x642qLyTjEUgf+JX6Atatl/QKe37yCj1OZYNPd3B0rPLJRF5mEmrADRXLZC9+uFeDS Wxxln040gnR6rjBHrRcvVmlTDiZY26iuL16+V+0/aZ9uyXNQSzk2cwDSiI/8gvr72Y+FN5fh cGXpeNHxHilYc9onzDhxyE76cwzqTKm4q2ULIH2u9IHQ5O86Fv6nHPYhe2fy1bhQapNwi/Xl 3G3i2WNH/w7m+1zWU1IddZOjmXzoxLT1BATwXGa0Tt5RjVb2mM1Wg3Zj6kqFkF2vvKcvrwj0 q0Ap5uyfN5m0uWzQMCMoaV9HQf7f5MkS1lnwBqDgnojjVAieX5uk7olUiRuPKHMfhvXulYP8 AA==
- Cc: "openldap-technical@openldap.org" <openldap-technical@openldap.org>
- Content-language: en-US
- In-reply-to: <CA+nFYV-WT4_oHPAXZbOEshCJHTNwbez5-nPd7GDLrOYhTxok9w@mail.gmail.com>
- References: <AC174E14-271E-400D-BFA0-17B2B265F3F4@wildberries.ru> <d1db6cbf-4ee9-3372-1cb7-c96dd311aee1@stroeder.com> <CA+nFYV-WT4_oHPAXZbOEshCJHTNwbez5-nPd7GDLrOYhTxok9w@mail.gmail.com>
- User-agent: Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Thunderbird/68.5.0
On 2/19/20 7:05 PM, Dave Macias wrote:
> If trying to access via ssh you can add to sshd_config file
>
> # you gonna want root group....
> AllowGroups root blabla bla2 bla3
Yes, that's one of the client-side solutions for limiting SSH access.
But you have to configure all the clients. With a decent config
management that's not that hard anymore. Still you have to model the
access control scheme in your config management.
Still it's much nicer to just modify LDAP entries to make an access
control change without having to reconfigure the Linux client systems.
Ciao, Michael.
> On Wed, Feb 19, 2020 at 1:01 PM Michael Ströder <michael@stroeder.com
> <mailto:michael@stroeder.com>> wrote:
>
> On 2/19/20 9:55 AM, Клеусов Владимир Сергеевич wrote:
> > I connected ldap linux clients to the OpenLDAP server.
> > I need to make a certain group of users able to connect to certain
> > computers. How do I do this ?
> With most LDAP posix user management deployments you have to configure
> the Linux clients to query only certain user groups or configure other
> PAM access control or similar.
>
> My Æ-DIR (based on OpenLDAP) provides views to the Linux clients based
> on hosts' service group membership and the user groups referenced:
>
> https://www.ae-dir.com/docs.html#er-roles
>
> So no need to configure the clients (except bind-DN and host password).
>
> If you have many clients consider using aehostd for better search
> performance / less load (see https://ae-dir.com/aehostd.html).
>
> Ciao, Michael.