Home
News
Forum
Wiki
Blog
Contents
Gallery
Movies
Downloads
About NSL
[
List of Titles
|
List of Pages
|
New
|
Search
|
Recent changes
|
Help
]
sssd
[
Front page
]
[ ]
Start:
** SSSD
- System Security Services Daemon
- [[LDAP]] を使用した認証が可能.キャッシュサーバ一体型.
#br
*** Getting Start
- getent shadow が使えなくても,認証可能!
#br
****設定ファイル
- [[authconfig>authselect]], authconfig-uti コマンドでデ...
-- CentOS8 では [[authselect]] になった. authconfig-uti ...
-- # authselect select sssd
- /etc/sssd/[[sssd.conf>./sssd.conf]] (''-rw---...
- /etc/nsswitch.conf
-- sss を追加
- [[/etc/pam.d>PAM]]/*
- /etc/sysconfig/authconfig
-- 手動:SSSD関連を yes, LDAP関連を no (手動は意味ない...
#br
**** 起動
- # systemctl start sssd
#br
**** 全キャッシュのクリア
- # systemctl stop sssd
- # \rm /var/lib/sss/db/*
- # systemctl start sssd
#br
**** 検証
- 要 sssd-tools
# sssctl domain-status default
#br
*** [[PAM]]
**** system-auth
auth required pam_env.so
auth required pam_faildelay.so delay=2000000
auth [default=1 ignore=ignore success=ok] pam_suc...
auth [default=1 ignore=ignore success=ok] pam_loc...
auth sufficient pam_unix.so nullok try_first_p...
auth requisite pam_succeed_if.so uid >= 1000 ...
auth sufficient pam_sss.so forward_pass
auth required pam_deny.so
account required pam_unix.so broken_shadow
account sufficient pam_localuser.so
account sufficient pam_succeed_if.so uid < 1000 q...
account [default=bad success=ok user_unknown=ignore]...
account required pam_permit.so
password requisite pam_pwquality.so try_first_pas...
password sufficient pam_unix.so shadow nullok try_...
password sufficient pam_sss.so use_authtok
password required pam_deny.so
session optional pam_keyinit.so revoke
session required pam_limits.so
-session optional pam_systemd.so
session optional pam_oddjob_mkhomedir.so umask=...
session [success=1 default=ignore] pam_succeed_if.so...
session required pam_unix.so
session optional pam_sss.so
**** password-auth
auth required pam_env.so
auth required pam_faildelay.so delay=2000000
auth [default=1 ignore=ignore success=ok] pam_suc...
auth [default=1 ignore=ignore success=ok] pam_loc...
auth sufficient pam_unix.so nullok try_first_p...
auth requisite pam_succeed_if.so uid >= 1000 ...
auth sufficient pam_sss.so forward_pass
auth required pam_deny.so
account required pam_unix.so broken_shadow
account sufficient pam_localuser.so
account sufficient pam_succeed_if.so uid < 1000 q...
account [default=bad success=ok user_unknown=ignore]...
account required pam_permit.so
password requisite pam_pwquality.so try_first_pas...
password sufficient pam_unix.so shadow nullok try_...
password sufficient pam_sss.so use_authtok
password required pam_deny.so
session optional pam_keyinit.so revoke
session required pam_limits.so
-session optional pam_systemd.so
session optional pam_oddjob_mkhomedir.so umask=...
session [success=1 default=ignore] pam_succeed_if.so...
session required pam_unix.so
session optional pam_sss.so
End:
** SSSD
- System Security Services Daemon
- [[LDAP]] を使用した認証が可能.キャッシュサーバ一体型.
#br
*** Getting Start
- getent shadow が使えなくても,認証可能!
#br
****設定ファイル
- [[authconfig>authselect]], authconfig-uti コマンドでデ...
-- CentOS8 では [[authselect]] になった. authconfig-uti ...
-- # authselect select sssd
- /etc/sssd/[[sssd.conf>./sssd.conf]] (''-rw---...
- /etc/nsswitch.conf
-- sss を追加
- [[/etc/pam.d>PAM]]/*
- /etc/sysconfig/authconfig
-- 手動:SSSD関連を yes, LDAP関連を no (手動は意味ない...
#br
**** 起動
- # systemctl start sssd
#br
**** 全キャッシュのクリア
- # systemctl stop sssd
- # \rm /var/lib/sss/db/*
- # systemctl start sssd
#br
**** 検証
- 要 sssd-tools
# sssctl domain-status default
#br
*** [[PAM]]
**** system-auth
auth required pam_env.so
auth required pam_faildelay.so delay=2000000
auth [default=1 ignore=ignore success=ok] pam_suc...
auth [default=1 ignore=ignore success=ok] pam_loc...
auth sufficient pam_unix.so nullok try_first_p...
auth requisite pam_succeed_if.so uid >= 1000 ...
auth sufficient pam_sss.so forward_pass
auth required pam_deny.so
account required pam_unix.so broken_shadow
account sufficient pam_localuser.so
account sufficient pam_succeed_if.so uid < 1000 q...
account [default=bad success=ok user_unknown=ignore]...
account required pam_permit.so
password requisite pam_pwquality.so try_first_pas...
password sufficient pam_unix.so shadow nullok try_...
password sufficient pam_sss.so use_authtok
password required pam_deny.so
session optional pam_keyinit.so revoke
session required pam_limits.so
-session optional pam_systemd.so
session optional pam_oddjob_mkhomedir.so umask=...
session [success=1 default=ignore] pam_succeed_if.so...
session required pam_unix.so
session optional pam_sss.so
**** password-auth
auth required pam_env.so
auth required pam_faildelay.so delay=2000000
auth [default=1 ignore=ignore success=ok] pam_suc...
auth [default=1 ignore=ignore success=ok] pam_loc...
auth sufficient pam_unix.so nullok try_first_p...
auth requisite pam_succeed_if.so uid >= 1000 ...
auth sufficient pam_sss.so forward_pass
auth required pam_deny.so
account required pam_unix.so broken_shadow
account sufficient pam_localuser.so
account sufficient pam_succeed_if.so uid < 1000 q...
account [default=bad success=ok user_unknown=ignore]...
account required pam_permit.so
password requisite pam_pwquality.so try_first_pas...
password sufficient pam_unix.so shadow nullok try_...
password sufficient pam_sss.so use_authtok
password required pam_deny.so
session optional pam_keyinit.so revoke
session required pam_limits.so
-session optional pam_systemd.so
session optional pam_oddjob_mkhomedir.so umask=...
session [success=1 default=ignore] pam_succeed_if.so...
session required pam_unix.so
session optional pam_sss.so
Page:
Site Search
Advanced Search
Login
Username:
Password:
Lost Password?
Register now!!
Sub Menu
New Arrivals
Books
Web Links
Site Map
e-Learning
TUIS Certificate
mini Calendar
May 2025
Su
Mo
Tu
We
Th
Fr
Sa
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
Today
Who's Online
47 user(s) are online (16 user(s) are browsing xpwiki)
Members: 0
Guests: 47
more...
Access Counter
Today :
Yesterday :
Total :
Powered by XOOPS Cube 2.1© 2001-2006
XOOPS Cube Project
Design by
XoopsDesign.com