Using winbind to filter ssh or su logins?

Gerald (Jerry) Carter jerry at samba.org
Fri Jan 30 15:48:31 GMT 2009


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Gerald (Jerry) Carter wrote:
> Diego Zuccato wrote:
>> Hello all.
> 
>> Given up hope to have login by upn, I'm now facing another 
>> problem: is it possible to have an AD group that
>> "filters" users that can use su (like pam_wheel) ?
> 
> What the pam module that supports options like
> "useringroup=DOMAIN\DOmain admins"?  Can' rmember the name but
> I used to use it a lot....
> 
> 
> It's pam_succeed_if.  I remember now.

You could also use the require-membership-of if using
pam_winbind for auth.


-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFJgyFPIR7qMdg1EfYRAlnNAKDtLVQPbEqLtpz6bt50d9pm1lATfgCeKnCq
DZquB1bgTJBUkPosK03pdP4=
=RjwU
-----END PGP SIGNATURE-----


More information about the samba-technical mailing list