Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 9 Apr 2002 07:52:38 -0700 (PDT)
From:      Roger Marquis <marquis@roble.com>
To:        security@FreeBSD.ORG
Subject:   Re: Centralized authentication
Message-ID:  <20020409073815.Q26460-100000@roble.com>
In-Reply-To: <bulk.67777.20020408212519@hub.freebsd.org>

next in thread | previous in thread | raw e-mail | index | archive | help
Samuel Chow wrote:
> 	How about NIS?  I use it at home with a total
> 	of two machines and one users.

I've used NIS with over 30,000 users, and adminitered 2 domains
with over 2,500 users and experienced near zero problems.  NIS+
may be a bit more difficult given it's Kerberos roots but it is
being used successfully in shops with hundreds of NIS+ accounts
and hosts.  Adminning Sun NIS servers and clients is neither
difficult nor complicated even with NFS and automount.  Not sure
if the same is true for FreeBSD servers however.

The drawback to NIS is that it is not secure enough for many
environments and does not support password aging.

The best tool for this job (directory services) IMO is LDAP.  Over
the past couple of years it has matched NIS for reliability and
clearly is the future direction of the industry.

-- 
Roger Marquis
Roble Systems Consulting
http://www.roble.com/


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20020409073815.Q26460-100000>