On Mon, 19 Jul 1999 15:47:33 -0400 
 "David E. Cross" <cro...@cs.rpi.edu> wrote:

 > PAM isn't going to cut it.  This is outside of its realm.  Things like ps,
 > top, ls, chown, chmod, lpr, rcmd, who, w, (the list goes on) need to be able
 > to pull 'passwd' entries from the LDAP server, and unless we PAM all of those
 > (I think that is a very bad idea), then a person will be able to login but
 > will be dead in the water without a UID <->Username mapping.

What you want is nsswitch, a'la Solaris.

nsswitch tells you what the user's name is, PAM tells you how that user is
to authenticate himself.  The two things are orthogonal, and nsswitch and
PAM together can work quite well.  Solaris, for example, has both.

        -- Jason R. Thorpe <thor...@nas.nasa.gov>



To Unsubscribe: send mail to majord...@freebsd.org
with "unsubscribe freebsd-hackers" in the body of the message

Reply via email to