Re: libpam-sshauth and libnss-sshsock
Gideon Romm <[email protected]> Mon, 14 Nov 2011 13:11:04 -0500
| Newsgroups | gmane.linux.terminal-server.devel |
|---|---|
| Message-ID | <CAF=Y7_ehrkd9aMf5fMsuw9WwTQ+2Zx62GjARASR2zER9=NjG+A@mail.gmail.com> |
>> 2. We could use a different pam module, like pam_group that
>> automatically adds users as members to system groups, and simply
>> modify that module's configuration (even via lts.conf).
>
> This, to my mind, seems to be a cleaner solution. Since we're
> going to want to use the pam_exec module anyway, part of the
> scripting could be updating the /etc/security/group.conf file,
> before the pam_group module's loaded.
>
> We might not even need to do that... Couldn't we just have static
> entries adding everyone to the groups we need... sound, plugdev, fuse
> etc. ? Seems like we could just do that at chroot build time.
>
> I could be missing something...
Yeah, I was leaning more towards #2, myself. Although we *could* do it
statically, I would *prefer* to write it dynamically upon connecting
to the LDM_SERVER. If the distro way of locking down certain users'
perms to access certain system devices/daemons is to adjust the group
membership, I think it is important that that not have to be something
hard-coded into the chroot image at build time or something that
requires a reboot of the client to take effect.
There could be other reasons, such as if the chroot distro and
LDM_SERVER distro are not the same.
-Gadi
------------------------------------------------------------------------------
RSA(R) Conference 2012
Save $700 by Nov 18
Register now
http://p.sf.net/sfu/rsa-sfdev2dev1
_____________________________________________________________________
Ltsp-developer mailing list. To un-subscribe, or change prefs, goto:
https://lists.sourceforge.net/lists/listinfo/ltsp-developer
For additional LTSP help, try #ltsp channel on irc.freenode.net