Re: Best practices for "pure" remote accounts

2023-10-20 Thread Philip Prindeville
Yes, this would be for multiple machines. Also, my understanding is that sssd works with LDAP/AD but not with Radius? I'd like to find something that works with both. Looking for a deployment guide that explains how PAM, NSS, and SSSD all fit together. > On Oct 19, 2023, at 6:03 AM, James

RE: Best practices for "pure" remote accounts

2023-10-20 Thread James Yu Wang
Where are the accounts stored? PAM allows you to stack modules. For example, you can use pam_krb5 to auth off AD and pam_radius to auth off radius. You stack them in the 'auth' section in pam.d config file. You use NSS to get users' uid, gid, homedir, etc information. Nslcd and sssd can do