Re: [SSSD] could SSSD provide better integration with backends that PAM?

2014-02-07 Thread Nikos Mavrogiannopoulos
On Thu, Feb 06, 2014 at 05:29:01PM +0100, Nikos Mavrogiannopoulos wrote: (The scenario that the vpn server would benefit, is the case where a user connects using TLS-client authentication, and the server -if it could obtain the client's public key from SSS- it would verify the client

Re: [SSSD] could SSSD provide better integration with backends that PAM?

2014-02-10 Thread Nikos Mavrogiannopoulos
On Fri, 2014-02-07 at 11:11 +0100, Jakub Hrozek wrote: On Fri, Feb 07, 2014 at 03:09:51AM -0500, Nikos Mavrogiannopoulos wrote: On Thu, Feb 06, 2014 at 05:29:01PM +0100, Nikos Mavrogiannopoulos wrote: (The scenario that the vpn server would benefit, is the case where a user connects

Re: [SSSD] could SSSD provide better integration with backends that PAM?

2014-02-10 Thread Nikos Mavrogiannopoulos
On Mon, 2014-02-10 at 13:11 +0100, Jakub Hrozek wrote: Hello, I see that the supported list of attributes isn't there. Is there going to be some standard list of attributes (and the attribute data formats) that will be available in multiple back-ends? Otherwise the caller should know

Re: [SSSD] could SSSD provide better integration with backends that PAM?

2014-02-11 Thread Nikos Mavrogiannopoulos
On Mon, 2014-02-10 at 14:22 -0500, Dmitri Pal wrote: So I'd still be interested whether the extra attributes will contain some consistent set of attributes across different SSSD installations, or they would be system-specific. The extra attributes are defined in sssd.conf, which is

[SSSD] sssd documentation issues

2015-10-12 Thread Nikos Mavrogiannopoulos
I tried to setup sssd on my fedora using the following instructions: https://fedorahosted.org/sssd/wiki/HOWTO_Configure_1_0_2 Didn't succeed yet, but some issues of the documentation are given below: * It says "I suggest that you start with the /etc/sssd/sssd.conf file that comes with the Fedora

Re: [SSSD] sssd documentation issues

2015-10-12 Thread Nikos Mavrogiannopoulos
On Mon, 2015-10-12 at 15:53 +0200, Jakub Hrozek wrote: > On Mon, Oct 12, 2015 at 03:45:44PM +0200, Nikos Mavrogiannopoulos > wrote: > > I tried to setup sssd on my fedora using the following > > instructions: > > https://fedorahosted.org/sssd/wiki/HOWTO_Configure_1_

Re: [SSSD] sssd + pkcs11

2015-09-15 Thread Nikos Mavrogiannopoulos
On Mon, 2015-09-14 at 18:40 +0200, Sumit Bose wrote: > On Mon, Sep 14, 2015 at 12:10:31PM +0200, Nikos Mavrogiannopoulos > wrote: > > On Mon, 2015-09-14 at 11:46 +0200, Sumit Bose wrote: > > > On Mon, Sep 14, 2015 at 11:25:39AM +0200, Nikos Mavrogiannopoulos >

[SSSD] sssd + pkcs11

2015-09-14 Thread Nikos Mavrogiannopoulos
Hello, I've been writing some text to integrate freeipa/sssd with openconnect server [0], and for single password or OTP that seems to integrate seamlessly. However, when PAM-SSSD is configured to use smart cards, that only works with locally inserted cards. That is even if one uses the smart

Re: [SSSD] sssd + pkcs11

2015-09-14 Thread Nikos Mavrogiannopoulos
On Mon, 2015-09-14 at 11:46 +0200, Sumit Bose wrote: > On Mon, Sep 14, 2015 at 11:25:39AM +0200, Nikos Mavrogiannopoulos > wrote: > > Hello, > > I've been writing some text to integrate freeipa/sssd with > > openconnect > > server [0], and for single password