Re: Multiple servers, restricting user commands and LDAP

This is a discussion on Re: Multiple servers, restricting user commands and LDAP within the OpenSSH Development forums, part of the Networking and Network Related category; Finlay Dobbie wrote: > > On 21 Feb 2005, at 20:42, Damien Miller wrote: >> If you are ...


Go Back   Usenet Forums > Networking and Network Related > OpenSSH Development

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 02-21-2005
Damien Miller
 
Posts: n/a
Default Re: Multiple servers, restricting user commands and LDAP

Finlay Dobbie wrote:
>
> On 21 Feb 2005, at 20:42, Damien Miller wrote:
>> If you are using LDAP, then set posixAccount/loginShell appropriately.

>
> I know how to set a user's shell using the NIS schema. I don't see how
> that helps me, since I need to have different restricted commands for
> different hosts. If I could restrict commands by group then that'd be
> dandy.


You could have the same shell name map to different restrictions on each
host. Trivially, by symlinking the shell to the binary you want to tun
(e.g. /usr/bin/cvs) or, if you wanted to be fancy, you could make that
restricted shell look up the actual commands it is supposed to execute
in LDAP too. That way they user would get a consistent response
regardless of the method by which they logged in.

-d

_______________________________________________
openssh-unix-dev mailing list
openssh-unix-dev@mindrot.org
http://www.mindrot.org/mailman/listi...enssh-unix-dev
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 04:10 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0