Re: Account / user management

From: Jeremiah DeWitt Weiner (jdw_at_panix.com)
Date: 02/28/05


Date: Mon, 28 Feb 2005 21:47:38 +0000 (UTC)

Karosei <g.m.rijsdijk@gmail.com> wrote:
> I'm looking for some tips and hints regaring central user/account
> management software for multiple linux servers. I assume it should be
> based on the open-LDAP standard. I hear people talk about idirectory
> from novell ??

        I just recently set up an OpenLDAP system for a cluster of Linux
hosts, so I have some familiarity with this. OpenLDAP is free as in
speech and free as in beer. Unless there's some compelling reason to go
with something non-free, why do it?

        The May 2004 issue of Sys Admin magazine had some good articles on
LDAP, so you might want to get your hands on a copy if you can. One of
the articles is available online:
http://www.samag.com/documents/s=9142/sam0405a/0405a.htm
My high-level recommendations, just off the top of my head, are:
-Set up at least two servers with replication
-Make sure that every client is actually talking to every server
-Make sure you can get into every host even if LDAP is down
-Use local accounts for things like apache, oracle, etc. so they don't
break if LDAP falls down
-Agree on what UID and GID range that LDAP will use and what range local
accounts will use so you don't have conflicts
-Use autohome; otherwise, much of LDAP's benefits are wasted

JDW



Relevant Pages

  • Re: Antivirus in FC3?
    ... > export the home directories to all the servers and do network ... Most already have Windows boxes ... OK well - one size fits all LDAP just isn't gonna cover all this - nor ... but IDEALX scripts provide the absolute minimum necessary beyond what ...
    (Fedora)
  • Re: Dump of user accounts
    ... Both are LDAP servers and both support LDIFDE.exe, ... you can omit the attributes from the ... the command will run using the credentials of the ...
    (microsoft.public.win2000.active_directory)
  • Re: Anybody using a "real" Linux domain?
    ... >> servers and a coupla of windows 200x servers. ... >> claim that a windows license is only good for the machine that ... >> We have been gradually installing Linux in areas where a single ... I have been researching domains using SMB, LDAP, ...
    (comp.os.linux.misc)
  • Seeking KDC Priority/Weight Clarification/Recommendation
    ... We are using a SUN One Directory Server (LDAP) Authentication plugin as the backend authentication mechanism for users binding to our LDAP servers. ... Our kerberos environment consists of one MIT krb-1.5.x master KDC and three MIT krb-1.5.x slave KDCs. ...
    (comp.protocols.kerberos)
  • Re: Anybody using a "real" Linux domain?
    ... >> servers and a coupla of windows 200x servers. ... >> claim that a windows license is only good for the machine that ... >> We have been gradually installing Linux in areas where a single ... I have been researching domains using SMB, LDAP, ...
    (comp.os.linux.networking)