On 11/16/2012 12:55 PM, Dmitri Pal wrote:
Would moving such accounts into local sssd provider help?
Hmm, that would be similar in concept to proxying nss_files, although certainly less kludgy on the sss side. However, we have existing procedures and scripts which currently assume local service accounts exist in the /etc/passwd file, I'd have to track all of those down and make sure they were updated. And there'd still be "local" accounts in /etc/passwd added by packages and whatnot, resulting in multiple locations for local users and possible uid allocation issues.
So, no, I don't think that's a workable option, at least not one whose effort is low enough to make it worth replacing pam_listfile though.
Thanks for the suggestion... _______________________________________________ sssd-devel mailing list [email protected] https://lists.fedorahosted.org/mailman/listinfo/sssd-devel
