flagflag  

SSSD anchor.png

  • System Security Services Daemon
  • LDAP を使用した認証が可能.キャッシュサーバ一体型.
 
Page Top

Getting Start anchor.png

  • getent shadow が使えなくても,認証可能!
     
Page Top
設定ファイル anchor.png
  • authconfig, authconfig-uti コマンドでデフォルトの設定ファイルを用意してくくれる
    • CentOS8 では authselect になった. authconfig-uti は削除.
    • # authselect select sssd
  • /etc/sssd/sssd.conf   (-rw------- 1 root root)
  • /etc/nsswitch.conf
    • sss を追加
  • ​/etc​/pam.d/*
  • /etc/sysconfig/authconfig 
    • 手動:SSSD関連を yes, LDAP関連を no (手動は意味ないかも知れない.ない気がする.参考程度に記す)
       
Page Top
起動 anchor.png
  • # systemctl start sssd
     
Page Top
全キャッシュのクリア anchor.png
  • # systemctl stop sssd
  • # \rm /var/lib/sss/db/*
  • # systemctl start sssd
     
Page Top
検証 anchor.png
  • 要 sssd-tools
# sssctl domain-status default
 
Page Top

PAM anchor.png

Page Top
system-auth anchor.png
auth        required      pam_env.so
auth        required      pam_faildelay.so delay=2000000
auth        [default=1 ignore=ignore success=ok] pam_succeed_if.so uid >= 1000 quiet
auth        [default=1 ignore=ignore success=ok] pam_localuser.so
auth        sufficient    pam_unix.so nullok try_first_pass
auth        requisite     pam_succeed_if.so uid >= 1000 quiet_success
auth        sufficient    pam_sss.so forward_pass
auth        required      pam_deny.so

account     required      pam_unix.so broken_shadow
account     sufficient    pam_localuser.so
account     sufficient    pam_succeed_if.so uid < 1000 quiet
account     [default=bad success=ok user_unknown=ignore] pam_sss.so
account     required      pam_permit.so

password    requisite     pam_pwquality.so try_first_pass local_users_only retry=3 authtok_type=
password    sufficient    pam_unix.so shadow nullok try_first_pass use_authtok
password    sufficient    pam_sss.so use_authtok
password    required      pam_deny.so

session     optional      pam_keyinit.so revoke
session     required      pam_limits.so
-session     optional      pam_systemd.so
session     optional      pam_oddjob_mkhomedir.so umask=0077
session     [success=1 default=ignore] pam_succeed_if.so service in crond quiet use_uid
session     required      pam_unix.so
session     optional      pam_sss.so
Page Top
password-auth anchor.png
auth        required      pam_env.so
auth        required      pam_faildelay.so delay=2000000
auth        [default=1 ignore=ignore success=ok] pam_succeed_if.so uid >= 1000 quiet
auth        [default=1 ignore=ignore success=ok] pam_localuser.so
auth        sufficient    pam_unix.so nullok try_first_pass
auth        requisite     pam_succeed_if.so uid >= 1000 quiet_success
auth        sufficient    pam_sss.so forward_pass
auth        required      pam_deny.so

account     required      pam_unix.so broken_shadow
account     sufficient    pam_localuser.so
account     sufficient    pam_succeed_if.so uid < 1000 quiet
account     [default=bad success=ok user_unknown=ignore] pam_sss.so
account     required      pam_permit.so

password    requisite     pam_pwquality.so try_first_pass local_users_only retry=3 authtok_type=
password    sufficient    pam_unix.so shadow nullok try_first_pass use_authtok
password    sufficient    pam_sss.so use_authtok
password    required      pam_deny.so

session     optional      pam_keyinit.so revoke
session     required      pam_limits.so
-session     optional      pam_systemd.so
session     optional      pam_oddjob_mkhomedir.so umask=0077
session     [success=1 default=ignore] pam_succeed_if.so service in crond quiet use_uid
session     required      pam_unix.so
session     optional      pam_sss.so

Front page   Freeze Diff Backup Copy Rename Reload   New List of Pages Search Recent changes   Help   RSS of recent changes (RSS 1.0) RSS of recent changes (RSS 2.0) RSS of recent changes (RSS Atom)
Counter: 842, today: 1, yesterday: 1
Last-modified: 2021-07-05 (Mon) 10:55:33 (JST) (1457d) by iseki

Site Search

Login

Username:

Password:


Lost Password?
Register now!!

Sub Menu

mini Calendar

Last MonthJul 2025Next Month
Su Mo Tu We Th Fr Sa
1 2 3 4 5
6 7 8 9 10 11 12
13 14 15 16 17 18 19
20 21 22 23 24 25 26
27 28 29 30 31
Today

Who's Online

123 user(s) are online (7 user(s) are browsing xpwiki)

Members: 0
Guests: 123

more...

Access Counter

Today : 1448414484144841448414484
Yesterday : 2172621726217262172621726
Total : 2734466227344662273446622734466227344662273446622734466227344662
Powered by XOOPS Cube 2.1© 2001-2006 XOOPS Cube Project
Design by XoopsDesign.com