[SAC] [MOTION] refresh SAC LDAP group: vote to remain !

Sandro Santilli strk at kbt.io
Thu Sep 8 10:44:59 PDT 2022


On Wed, Sep 07, 2022 at 07:23:17PM -0400, Regina Obe wrote:

> > How are machines allowing shell access via LDAP configured ?
> 
> This is what I have as the setup for the instance images I've been using to
> build out the new instances. This is in the /etc/nslcd.conf, which I had
> originally copied I think from the old download server. 
> 
>       base passwd ou=People,dc=osgeo,dc=org
>       base shadow ou=People,dc=osgeo,dc=org
>       base group  ou=Group,dc=osgeo,dc=org
>       filter group (&(objectClass=posixGroup)(cn=sac,ou=Shell,dc=osgeo,dc=org))

Could you please write this info in this page ?
https://wiki.osgeo.org/wiki/SAC:Standard_System_Setup#Enable_LDAP

>From the look of it (cn=sac) none of the people in the
"cn=telascience" group would be allowed to login on those machines.
I verified even the "upload" machine has that entry, so maybe we can
drop the telascience group completely.

--strk;


More information about the Sac mailing list