FAQ Search Today's Posts Mark Forums Read
» Video Reviews

» Linux Archive

Linux-archive is a website aiming to archive linux email lists and to make them easily accessible for linux users/developers.


» Sponsor

» Partners

» Sponsor

Go Back   Linux Archive > Ubuntu > Ubuntu Server Development

 
 
LinkBack Thread Tools
 
Old 02-01-2008, 09:16 AM
Timo Aaltonen
 
Default new features for libpam-ldap

Hi!

We have been using a patch for libpam-ldap for a couple of years (4+)
now, and it's about time to ask for merging it in Ubuntu and/or Debian
(but starting here . Here's a description by the author (ie. not me):


- Two new configuration options:
- pam_require_fqdn, allow matching host to either fully qualified
domain name or short hostname.
- pam_require_host_group, match against freely specified hostgroup
to gain access. Looked up from host attribute.
- Can work either way at the same time

- Introduces directly LDAP speaking variants of two internal
functions, _has_deny_value / _has_value. authorizedService
and host attributes are compared on the server side, thus
allowing to set somewhat more strict ACL's to those attributes
if wanted, and possibly saving some network bandwidth..
- Disable some old code replaced by use of _ldap_cmp_has_deny_value
and _ldap_cmp_has_value.

It was sent upstream but got no feedback (link to the patch is broken
now):


http://bugzilla.padl.com/show_bug.cgi?id=172


t--
ubuntu-server mailing list
ubuntu-server@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-server
More info: https://wiki.ubuntu.com/ServerTeam
 
Old 02-06-2008, 07:13 AM
Timo Aaltonen
 
Default new features for libpam-ldap

On Fri, 1 Feb 2008, Timo Aaltonen wrote:

>
> Hi!
>
> We have been using a patch for libpam-ldap for a couple of years (4+) now,
> and it's about time to ask for merging it in Ubuntu and/or Debian (but
> starting here . Here's a description by the author (ie. not me):
>
> - Two new configuration options:
> - pam_require_fqdn, allow matching host to either fully qualified
> domain name or short hostname.
> - pam_require_host_group, match against freely specified hostgroup
> to gain access. Looked up from host attribute.
> - Can work either way at the same time
>
> - Introduces directly LDAP speaking variants of two internal
> functions, _has_deny_value / _has_value. authorizedService
> and host attributes are compared on the server side, thus
> allowing to set somewhat more strict ACL's to those attributes
> if wanted, and possibly saving some network bandwidth..
> - Disable some old code replaced by use of _ldap_cmp_has_deny_value
> and _ldap_cmp_has_value.
>
> It was sent upstream but got no feedback (link to the patch is broken now):
>
> http://bugzilla.padl.com/show_bug.cgi?id=172

Still no comments.. Ok, lets put it this way; does anyone object if I were
to upload a new version with this patch?

t

--
ubuntu-server mailing list
ubuntu-server@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-server
More info: https://wiki.ubuntu.com/ServerTeam
 
Old 02-06-2008, 10:01 PM
Timo Aaltonen
 
Default new features for libpam-ldap

resending here to receive more feedback:

---------- Forwarded message ----------
Date: Fri, 01 Feb 2008 12:16:34 +0200 (EET)
From: Timo Aaltonen
To: ubuntu-server
Subject: [PATCH] new features for libpam-ldap


Hi!

We have been using a patch for libpam-ldap for a couple of years (4+) now,
and it's about time to ask for merging it in Ubuntu and/or Debian (but starting
here . Here's a description by the author (ie. not me):


- Two new configuration options:
- pam_require_fqdn, allow matching host to either fully qualified
domain name or short hostname.
- pam_require_host_group, match against freely specified hostgroup
to gain access. Looked up from host attribute.
- Can work either way at the same time

- Introduces directly LDAP speaking variants of two internal
functions, _has_deny_value / _has_value. authorizedService
and host attributes are compared on the server side, thus
allowing to set somewhat more strict ACL's to those attributes
if wanted, and possibly saving some network bandwidth..
- Disable some old code replaced by use of _ldap_cmp_has_deny_value
and _ldap_cmp_has_value.

It was sent upstream but got no feedback (link to the patch is broken now):

http://bugzilla.padl.com/show_bug.cgi?id=172


t--
ubuntu-server mailing list
ubuntu-server@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-server
More info: https://wiki.ubuntu.com/ServerTeam--
ubuntu-devel mailing list
ubuntu-devel@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-devel
 
Old 02-11-2008, 03:53 PM
Adam McGreggor
 
Default new features for libpam-ldap

On Wed, Feb 06, 2008 at 10:13:36AM +0200, Timo Aaltonen wrote:
> On Fri, 1 Feb 2008, Timo Aaltonen wrote:

[...]

> > http://bugzilla.padl.com/show_bug.cgi?id=172
>
> Still no comments.. Ok, lets put it this way; does anyone object if I were
> to upload a new version with this patch?

I work on the principle if anyone objects, they'll speak up...

--
ubuntu-server mailing list
ubuntu-server@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-server
More info: https://wiki.ubuntu.com/ServerTeam
 
Old 02-11-2008, 04:00 PM
Timo Aaltonen
 
Default new features for libpam-ldap

On Mon, 11 Feb 2008, Adam McGreggor wrote:

> On Wed, Feb 06, 2008 at 10:13:36AM +0200, Timo Aaltonen wrote:
>> On Fri, 1 Feb 2008, Timo Aaltonen wrote:
>
> [...]
>
>>> http://bugzilla.padl.com/show_bug.cgi?id=172
>>
>> Still no comments.. Ok, lets put it this way; does anyone object if I were
>> to upload a new version with this patch?
>
> I work on the principle if anyone objects, they'll speak up...

I had a chat with Rick about the patch, and there were some concerns which
are being addressed.


t

--
ubuntu-server mailing list
ubuntu-server@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-server
More info: https://wiki.ubuntu.com/ServerTeam
 

Thread Tools




All times are GMT. The time now is 08:55 AM.

VBulletin, Copyright ©2000 - 2014, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO ©2007, Crawlability, Inc.
Copyright 2007 - 2008, www.linux-archive.org