Forums

Skip to content

Advanced search
  • Quick links
    • Unanswered topics
    • Active topics
    • Search
  • FAQ
  • Login
  • Register
  • Board index Assistance Networking & Security
  • Search

Do I need LDAP?

Having problems getting connected to the internet or running a server? Wondering about securing your box? Ask here.
Post Reply
Advanced search
4 posts • Page 1 of 1
Author
Message
mattjgalloway
l33t
l33t
Posts: 761
Joined: Tue Mar 16, 2004 10:07 am
Location: Coventry, UK
Contact:
Contact mattjgalloway
Website

Do I need LDAP?

  • Quote

Post by mattjgalloway » Mon Apr 10, 2006 11:17 pm

Hey people,

I have a server on my network which I admin and a few different computers access it. Basically I want to keep the passwd and group files updated on each machine without too much hassle. I thought about LDAP but do I really need to setup something like this and does it actually update the local files? So basically I need something which keeps the files up to date for the UID and GID and passwords... what should I use?
AMD64 3200+, 1024MB RAM, Gentoo Linux
MacBook Core Duo, 1024MB RAM, Leopard
Top
gfa
n00b
n00b
User avatar
Posts: 14
Joined: Tue May 20, 2003 10:09 pm

  • Quote

Post by gfa » Tue Apr 11, 2006 3:06 am

you should use ldap, but for keeping your sanity use it for uid > 1000 (users)
if you want HA read about sluprd/synrepl, if not, don't care about it.
if you use openldap, use bdb as backend
suerte
Top
bemis
Tux's lil' helper
Tux's lil' helper
Posts: 136
Joined: Tue Mar 30, 2004 5:27 pm
Location: USA
Contact:
Contact bemis
Website

  • Quote

Post by bemis » Tue Apr 11, 2006 3:09 am

LDAP is a good, mature solution for your problem - but it may be a bit overkill for your environment - if you have a realtively protected LAN environment, there is nothing wrong with a NIS solution - (http://gentoo-wiki.com/HOWTO_Setup_NIS) - there are some security implications - but in a LAN setup they're basically shadowed by the physical access people already have. Another option is cfengine (http://sial.org/howto/cfengine/) which gives you literally what you asked for, although I would advise taking the NIS path over cfengine, for the same reasons as LDAP - it's a bit overkill.
Y'know, somewhere along the line, my brain got wired directly to my fingers .. I'm not even consulted anymore in the decision making processes.
-bemis
Top
James Wells
n00b
n00b
User avatar
Posts: 57
Joined: Fri Sep 10, 2004 4:26 pm

Re: Do I need LDAP?

  • Quote

Post by James Wells » Fri Jul 21, 2006 2:23 am

Greetings,
mattjgalloway wrote:I have a server on my network which I admin and a few different computers access it. Basically I want to keep the passwd and group files updated on each machine without too much hassle.
Right off the bat, you are describing the ideal environment for cfengine. Cfengine is the Configuration Engine, it is designed to keep the configuration of many machines on a network syncrhonized. From what you describe, you won't need anywhere near the full power of cfengine, and could actually get away with something as simple of rsync, though I suspect if you start using cfengine, you will find many more uses for it.

Further, based on your description, LDAP is not a good solution for you. LDAP is meant to provide a centralized directory service, in your case passwd / shadow / group service. what this means in your case though is that each client machine on the network, would query your LDAP server for it's password / shadow / group service, instead of using it's own local files.

Please note that I use LDAP both on my home network, but also my network at work. At home I manage 3 to 30 systems and at work between 40 - 200 systems. Additionally, I use cfengine to keep my /etc/passwd, /etc/shadow, and /etc/group files synchronized, with minimal user information, on all of my systems just in case the LDAP servers go down.
Top
Post Reply

4 posts • Page 1 of 1

Return to “Networking & Security”

Jump to
  • Assistance
  • ↳   News & Announcements
  • ↳   Frequently Asked Questions
  • ↳   Installing Gentoo
  • ↳   Multimedia
  • ↳   Desktop Environments
  • ↳   Networking & Security
  • ↳   Kernel & Hardware
  • ↳   Portage & Programming
  • ↳   Gamers & Players
  • ↳   Other Things Gentoo
  • ↳   Unsupported Software
  • Discussion & Documentation
  • ↳   Documentation, Tips & Tricks
  • ↳   Gentoo Chat
  • ↳   Gentoo Forums Feedback
  • ↳   Duplicate Threads
  • International Gentoo Users
  • ↳   中文 (Chinese)
  • ↳   Dutch
  • ↳   Finnish
  • ↳   French
  • ↳   Deutsches Forum (German)
  • ↳   Diskussionsforum
  • ↳   Deutsche Dokumentation
  • ↳   Greek
  • ↳   Forum italiano (Italian)
  • ↳   Forum di discussione italiano
  • ↳   Risorse italiane (documentazione e tools)
  • ↳   Polskie forum (Polish)
  • ↳   Instalacja i sprzęt
  • ↳   Polish OTW
  • ↳   Portuguese
  • ↳   Documentação, Ferramentas e Dicas
  • ↳   Russian
  • ↳   Scandinavian
  • ↳   Spanish
  • ↳   Other Languages
  • Architectures & Platforms
  • ↳   Gentoo on ARM
  • ↳   Gentoo on PPC
  • ↳   Gentoo on Sparc
  • ↳   Gentoo on Alternative Architectures
  • ↳   Gentoo on AMD64
  • ↳   Gentoo for Mac OS X (Portage for Mac OS X)
  • Board index
  • All times are UTC
  • Delete cookies

© 2001–2026 Gentoo Foundation, Inc.

Powered by phpBB® Forum Software © phpBB Limited

Privacy Policy

 

 

magic