13.07.2015 Views

Naming and Directory Services (DNS, NIS, and LDAP)

Naming and Directory Services (DNS, NIS, and LDAP)

Naming and Directory Services (DNS, NIS, and LDAP)

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Pluggable Authentication MethodsBy using the PAM framework, you can choose among several authentication services.You can use either pam_unix or pam_ldap in conjunction with <strong>LDAP</strong>.Because of its increased flexibility, support of stronger authentication methods, <strong>and</strong>ability to use account management, the use of pam_ldap is recommended.pam_unixIf you have not changed the pam.conf(4) file, pam_unix functionality is enabled bydefault.Note – The pam_unix module has been removed <strong>and</strong> is no longer supported withSolaris. A set of other service modules provides equivalent or greater functionality.Therefore, in this guide, pam_unix refers to the equivalent functionality, not to thepam_unix module itself.Following is a list of the modules that provide the equivalent pam_unix functionality.pam_authtok_check(5)pam_authtok_get(5)pam_authtok_store(5)pam_dhkeys(5)pam_passwd_auth(5)pam_unix_account(5)pam_unix_auth(5)pam_unix_cred(5)pam_unix_session(5)pam_unix follows the traditional model of UNIX authentication, as described in thefollowing list.1. The client retrieves the user’s encrypted password from the name service.2. The user is prompted for his password.3. The user’s password is encrypted.4. The client compares the two encrypted passwords to determine whether the usershould be authenticated.Additionally, there are two restrictions when using pam_unix.■■The password must be stored in UNIX crypt format <strong>and</strong> not in any otherencryption methods, including clear.The userPassword attribute must be readable by the name service.Chapter 9 • <strong>LDAP</strong> Basic Components <strong>and</strong> Concepts (Overview) 147

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!