13.07.2015 Views

Naming and Directory Services (DNS, NIS, and LDAP)

Naming and Directory Services (DNS, NIS, and LDAP)

Naming and Directory Services (DNS, NIS, and LDAP)

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>LDAP</strong> <strong>Naming</strong> <strong>Services</strong> Security ModelIntroductionSolaris <strong>LDAP</strong> naming services use the <strong>LDAP</strong> repository as a source of both a namingservice <strong>and</strong> an authentication service. This section discusses the concepts of clientidentity, authentication methods, pam_ldap(5) <strong>and</strong> pam_unix modules, <strong>and</strong> accountmanagement.Note – After you enable pam_ldap account management, all users must provide apassword any time they log in to the system. A login password is required forauthentication. Therefore, nonpassword-based logins using tools such as rsh,rlogin, orssh will fail.To access the information in the <strong>LDAP</strong> repository, clients can first establish identitywith the directory server. This identity can be either anonymous or as an objectrecognized by the <strong>LDAP</strong> server. Based on the client’s identity <strong>and</strong> the server’s accesscontrol information (ACI), the <strong>LDAP</strong> server will allow the client to read or writedirectory information. For more information on ACIs, consult the Administration Guidefor the version of Sun Java System <strong>Directory</strong> Server that you are using.If the client is connecting as anything other than anonymous for any given request, theclient must prove its identity to the server using an authentication method supportedby both the client <strong>and</strong> the server. Once the client has established its identity, it can thenmake the various <strong>LDAP</strong> requests.There is a distinction between how the naming service <strong>and</strong> the authentication service(pam_ldap) access the directory. The naming service reads various entries <strong>and</strong> theirattributes from the directory based on predefined identity. The authentication serviceestablishes whether the user has entered the correct password by using that user’sname <strong>and</strong> password to authenticate to the <strong>LDAP</strong> server. See the pam_ldap(5) manpage for more information about the authentication service.Chapter 9 • <strong>LDAP</strong> Basic Components <strong>and</strong> Concepts (Overview) 141

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!