Tuesday, March 26, 2013

Re: [389-users] SSH public keys and 389?

Hello

On Mon, Mar 25, 2013 at 7:06 PM, Vesa Alho <listat@alho.fi> wrote:
> Thanks! It seems to require patching on Debian based distros.

I dont use ubuntu extensively, but a quick google says this might help
https://marc.wäckerlin.ch/computer/blog/ssh_and_ldap

>
> BTW, did you add some schema on 389 side?

You need to add schema on 389-ds server

>
> -Vesa
>
>
> On 03/25/2013 03:26 PM, s.oreilly wrote:
>>
>> On redhat/centos like systems you can install the openssh-ldap package so
>> no
>> patching involved.
>>
>> Regards
>>
>> Sean O'Reilly
>>
>> On Mon 25/03/13 1:20 PM , Vesa Alho listat@alho.fi sent:
>>>
>>> I think 389 side is "easy", but how about openssh-server and/or
>>> clients? Wondering do I need to patch openssh-server to get it working or
>>> is
>>> there an easier way.
>>>
>>> PS. thanks for responding!
>>>
>>> -Vesa
>>>
>>>
>>> On 03/25/2013 03:09 PM, s.oreilly wrote:
>>>>
>>>> I have just done this. I will see if I can find
>>>
>>> the docs.>
>>>>
>>>> You need to add an objectclass (ldappublickey)
>>>
>>> and an attribute (sshpublickey) to> the schema.
>>>>
>>>>
>>>> Regards
>>>>
>>>>
>>>> Sean O'Reilly
>>>>
>>>> On Mon 25/03/13 1:02 PM , Vesa Alho listat@alho.fi
>>>
>>> sent:>> Hi,
>>>>>
>>>>>
>>>>> What would it take to store SSH public keys
>>>
>>> in 389?>>
>>>>>
>>>>> I found this old thread in archives, but
>>>
>>> mentioned link doesn't work:>>
>>
>>
>> http://www.mail-archive.com/389-users@lists.fedoraproject.org/msg02389.html>>

I shared this, but looks like this blog is not accessible anymore, I
will write up in my blog & share soon.

>> Other googling revealed guides which seem to
>>>
>>> require patched version of>> openssh-server and openldap
>>> guides.>>
>>>>>
>>>>> I guess freeipa would support this, but any
>>>
>>> chance with only 389?>>
>>>>>
>>>>> -Mr. Vesa Alho
>>>>> --
>>>>> 389 users mailing list
>>>>>
>>>>
>>
>> 389-users@lists.fedoraproject.orghttps://admin.fedoraproject.org/mailman/listinfo/389-users>>
>>>>
>>>>
>>>> --
>>>> 389 users mailing list
>>>> 389-users@lists.fedoraproject.org>
>>
>> https://admin.fedoraproject.org/mailman/listinfo/389-users>
>>>
>>>
>>> --
>>> 389 users mailing list
>>>
>>
>> 389-users@lists.fedoraproject.orghttps://admin.fedoraproject.org/mailman/listinfo/389-users
>>>
>>>
>>
>> --
>> 389 users mailing list
>> 389-users@lists.fedoraproject.org
>> https://admin.fedoraproject.org/mailman/listinfo/389-users
>>
>
> --
> 389 users mailing list
> 389-users@lists.fedoraproject.org
> https://admin.fedoraproject.org/mailman/listinfo/389-users


--
Thanks & Regards
Arpit Tolani
--
389 users mailing list
389-users@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/389-users

No comments:

Post a Comment