Re: [389-users] Certificate based authentication

2011-10-13 Thread Gerhardus Geldenhuis
> > > If I can have ssh/pam authentication and have ssh retrieve public key > from LDAP that might be a consolatory price. > > That is possible, but I don't think that's really what you are trying to > do. It really sounds like what you want to do is: > 1) generate an ssh compatible cert (or pub/

Re: [389-users] Certificate based authentication

2011-10-13 Thread Rich Megginson
On 10/13/2011 04:05 AM, Gerhardus Geldenhuis wrote: On Wed, Oct 12, 2011 at 8:53 PM, Rich Megginson > wrote: The second part of the question is how would this work with regards to ssh authentication. Somehow via pam and ssh the certificate must be pass

Re: [389-users] Certificate based authentication

2011-10-12 Thread Rich Megginson
On 10/11/2011 09:53 AM, Gerhardus Geldenhuis wrote: Hi I am looking at doing certifcate based authentication using 389. The company where I am working currently issues a certificate for every new starter and these certs are well managed with regards to sensible expiry dates etc. This cert is

[389-users] Certificate based authentication

2011-10-11 Thread Gerhardus Geldenhuis
Hi I am looking at doing certifcate based authentication using 389. The company where I am working currently issues a certificate for every new starter and these certs are well managed with regards to sensible expiry dates etc. This cert is your key to the whole environment and a lot of the applic

[389-users] Certificate based Authentication

2011-09-15 Thread David Partridge
Attempting to configure Certificate based authentication with SASL External such that if TLS successfully completed the user is authenticated by certificate DN as an authenticated user without the requirement for the corresponding DN to be present in the Directory Server. nsslapd-sasl-force-extern

[389-users] Certificate based Authentication

2011-09-15 Thread David Partridge
Attempting to configure Certificate based authentication with SASL External such that if TLS successfully completed the user is authenticated by certificate DN as an authenticated user without the requirement for the corresponding DN to be present in the Directory Server. nsslapd-sasl-force-extern