Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 27 May 2003 12:41:37 -0700 (PDT)
From:      Bigby Findrake <bigby@ephemeron.org>
To:        Eric Anderson <anderson@centtech.com>
Cc:        FreeBSD Security <FreeBSD-Security@freebsd.org>
Subject:   Re: multihost master.passwd sync
Message-ID:  <Pine.BSF.4.44.0305271240300.15643-100000@home.ephemeron.org>
In-Reply-To: <3ED3BE9E.60407@centtech.com>

next in thread | previous in thread | raw e-mail | index | archive | help

On Tue, 27 May 2003, Eric Anderson wrote:

> Andy Harrison wrote:
> >>>>The problem is that while it allows authentication, it doesn't integrate
> >>>>seamlessly allowing you to own files as a user that only exists in the
> >>>>ldap.
> >>>
> >>>Huh?  Explain more please..
> >>
> >
> > I was told that if the user isn't in the passwd file physically, they can't own
> > files on the local server.  I've run into this personally with radius, I can't
> > speak with authority on ldap and pam integration.
>
> Oh, ok.. Well, I *believe* that is incorrect.. Should work fine
> (specially with nss_ldap stuff in FreeBSD-5.1, etc)..

NIS is a perfect example of how users not in the password file can own
files on a machine.


/-------------------------------------------------------------------------/
"I've tried to install this linux crap about nearly five times, but everytime 
it stops with the error message: 'login:'
Fix that immediately or I'll go public with that." -- some random moron

		      http://ephemeron.org:81/~bigby/
		    finger bigby@ephemeron.org for info
/-------------------------------------------------------------------------/



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.BSF.4.44.0305271240300.15643-100000>