Hi , What I understand from below is .. AD users should directly use vsftp to ftp into the server , there wouldnt be any users on the ftp server. if we are using kerberose .. would it work with the existing users that are already created in the AD with out any change (or do we need to have an SFU in between)? the URL that you have sent talks about the openldap server .. do we need a openldap server or the ldap client should be sufficent that is there by default in the RHEL5 (/etc/ldap.conf) sorry to interrupt .. in between VSFTP server+pam+openldap on linux users on w2k3 to provide (authentication and authourization) Prasad
--- On Sat, 7/12/08, Ashok <[EMAIL PROTECTED]> wrote: From: Ashok <[EMAIL PROTECTED]> Subject: Re: [TwinCLinG] VSFTPD+Open LDAP To: [email protected] Date: Saturday, July 12, 2008, 4:15 AM Hi David, I want to know, if you want , How to configure Vsftpd to authenticate using AD users / Or OpenLDAP, Can you clarify more. Configuring vsftpd with OpenLDAP , is configuring the vsftpd system to authenticate to LDAP server, and nothing to do with vsftpd, as vsftp will call pam and appropriate LDAP libararies will be called. So configure an LDAP Server, using OpenLDAP, You will find a lot of howto's on that in google. Here is a few http://kbase. redhat.com/ faq/FAQ_91_ 11441.shtm So once system is configured to authenticate OpenLDAP, vsftpd can use PAM to get LDAP user. If you want Vsftpd to authenticate using AD user. For that, vsftpd server should authenticate to AD using LDAP and kerberos (is one option) or you use Winbind as another option. Using LDAP and kerberos to Authenticate to Windows AD is better option. Regards Niranjan --- On Fri, 7/11/08, G.David Manohar <david_manohar@ yahoo.com> wrote: From: G.David Manohar <david_manohar@ yahoo.com> Subject: [TwinCLinG] VSFTPD+Open LDAP To: [EMAIL PROTECTED] .com Date: Friday, July 11, 2008, 11:36 AM Hi, Can someone please help me configuring VSFTPD with OPEN-LDAP to access active directory. Thanks in advance... David [Non-text portions of this message have been removed] [Non-text portions of this message have been removed]
