Bug 84376
| Summary: | glibc's nss_compat.so library fails to implement ldap functions | ||
|---|---|---|---|
| Product: | [Retired] Red Hat Linux | Reporter: | Andy Grimm <andy.grimm> |
| Component: | glibc | Assignee: | Jakub Jelinek <jakub> |
| Status: | CLOSED WONTFIX | QA Contact: | Brian Brock <bbrock> |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | 7.3 | CC: | fweimer |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | Bug Fix | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2003-04-22 05:41:44 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
Andy Grimm
2003-02-15 02:11:25 UTC
*** Bug 84378 has been marked as a duplicate of this bug. *** Can you please expand on why you need to use nss_compat for ldap? Why doesn't passwd: ldap work for you? passwd: ldap works fine, but doesn't allow me to restrict access in the way that I would like. For example, if my development domain has a webserver (or fileserver, nameserver, etc.) in it, and I only want administrators to have login access, my current way to do this is with compat mode, an admin netgroup, and a "+@admin" line at the bottom of the password file. I think this is pretty standard in the Solaris world. This works fine with Linux under NIS or NIS+, so I was surprised to find that it doesn't work for LDAP. It essentially means that I have to change to an "everybody or nobody" policy for LDAP-based user logins. Unless you know of another comparable way to control this, I'd consider it a security issue. This is no bug. nss_compat has one purpose only: to work with NIS and the old format used in the passwd file. There will never ever be a change as demanded here in nss_compat. But the nss module interface is documented. Feel free to write zour own nss module and use it. |