4 069
contributi
Riga 1 309: | Riga 1 309: | ||
nss_base_group ou=Groups,dc=dominio,dc=local?one | nss_base_group ou=Groups,dc=dominio,dc=local?one | ||
</pre> | </pre> | ||
=== Sicurezza del server: configurazione di Pam === | |||
Il metodo migliore per evitare che gli utenti indiscriminatamente si logghino sul server è configurare correttamente ''PAM''. Andiamo quindi a modificare i quattro files che gestiscono la configurazione di ''pam'' per LDAP in modo che il loro contenuto sia:<br/><br/> | |||
'''/etc/pam.d/common-account'''<br/> | '''/etc/pam.d/common-account'''<br/> | ||
<pre> | <pre> | ||
#/etc/pam.d/common-account - authorization settings common to all services | #/etc/pam.d/common-account - authorization settings common to all services | ||
account sufficient pam_ldap.so | account sufficient pam_ldap.so | ||
account required pam_unix.so | account required pam_unix.so | ||
</pre> | </pre> | ||
<br/> | <br/> | ||
'''/etc/pam.d/common-auth'''<br/> | '''/etc/pam.d/common-auth'''<br/> | ||
<pre> | <pre> | ||
# /etc/pam.d/common-auth - authentication settings common to all services | # /etc/pam.d/common-auth - authentication settings common to all services | ||
auth sufficient pam_ldap.so | auth sufficient pam_ldap.so | ||
auth required pam_unix.so nullok_secure use_first_pass | auth required pam_unix.so nullok_secure use_first_pass | ||
Riga 1 346: | Riga 1 328: | ||
<pre> | <pre> | ||
# /etc/pam.d/common-password - password-related modules common to all services | # /etc/pam.d/common-password - password-related modules common to all services | ||
password sufficient pam_ldap.so md5 | |||
password required pam_unix.so nullok obscure md5 | |||
password sufficient pam_ldap.so | |||
password required pam_unix.so nullok obscure md5 | |||
</pre> | </pre> | ||
<br/> | <br/> | ||
'''/etc/pam.d/common-session'''<br/> | '''/etc/pam.d/common-session'''<br/> | ||
<pre> | <pre> | ||
session required pam_mkhomedir.so skel=/etc/skel | |||
session sufficient pam_ldap.so | session sufficient pam_ldap.so | ||
session required pam_unix.so | session required pam_unix.so |