linux nslcd服务,redhat – sssd vs nslcd for RHEL-5/6

sssd可能是更具“前瞻性”的选择.在这种程度上,其他答案是正确的.也就是说,与流行的观点相反,sssd并没有完全取代nslcd的功能.

nslcd优于sssd的主要(情境)优势是您可以编写带参数替换的自定义authz查询:

pam_authz_search FILTER

This option allows flexible fine tuning of the authorisation check that should be performed. The search filter specified is executed and if any entries

match, access is granted, otherwise access is denied.

The search filter can contain the following variable references: $username, $service, $ruser, $rhost, $tty, $hostname, $dn, and $uid. These references

are substituted in the search filter using the same syntax as described in the section on attribute mapping expressions below.

For example, to check that the user has a proper authorizedService value if the attribute is present: (&(objectClass=posixAccount)(uid=$username)

(|(authorizedService=$service)(!(authorizedService=*))))

The default behaviour is not to do this extra search and always grant access.

我最后一次检查sssd文档(在过去六个月内),仍然没有替换此功能.所以这真的取决于这个功能是否足够重要,以撇开sssd整合解决方案的好处.

  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值