Multiple servers, restricting user commands and LDAP

This is a discussion on Multiple servers, restricting user commands and LDAP within the OpenSSH Development forums, part of the Networking and Network Related category; I have a set-up of 3 servers at disparate geographical locations. Server 1 provides web services, and users should ...


Go Back   Usenet Forums > Networking and Network Related > OpenSSH Development

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 02-21-2005
Finlay Dobbie
 
Posts: n/a
Default Multiple servers, restricting user commands and LDAP

I have a set-up of 3 servers at disparate geographical locations.

Server 1 provides web services, and users should be able to use sftp
only. Admins should be able to get shells.
Server 2 provides CVS services, and users sh ould be able to use cvs
only. Admins should be able to get shells.
Server 3 provides shell services for all users.

There appears to be no easy way of implementing this within the
current OpenSSH system. At this point in time, for various reasons,
each server maintains its own authentication database, which are
periodically regenerated from a master SQL database of users and
groups (and other stuff). Another set of scripts generate
..ssh/authorized_keys files and rsync them about, creating the correct
command= and so on for each user based on their relative privileges
and the host in question.

For obvious reasons, this is nasty. I am pushing towards moving
everything over to LDAP for authentication and user information. This
includes the public keys, and in fact we have taken over the hosting
of the OpenSSH-LPK project[1] and I plan on contributing resources
towards that end (we've started using our own schema, I'm writing up
an Internet-Draft on it, etc).

Basically, I was wondering if anybody had any input on this situation,
what they'd like to see from any OpenSSH/LDAP integration, and that
kind of thing. It seems that the command= shouldn't necessarily only
be coupled to keys, no?

Has anybody dealt with a similar situation?

[1] http://www.opendarwin.org/projects/openssh-lpk/

-- Finlay

_______________________________________________
openssh-unix-dev mailing list
openssh-unix-dev@mindrot.org
http://www.mindrot.org/mailman/listi...enssh-unix-dev
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 12:54 AM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0