Latest LQ Deal: Linux Power User Bundle
Go Back > Forums > Linux Forums > Linux - Security
User Name
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.


Closed Thread
  Search this Thread
Old 04-10-2004, 01:02 PM   #1
LQ Newbie
Registered: Apr 2004
Posts: 5

Rep: Reputation: 0
Access Control database using pam-pgsql?

I am running Debian woody and am trying to setup an access control database using the pam module and PostgreSQL. I am testing the system using Apache 1.3. Basic functionality is working:

Apache PAM DSO loaded and configured
pam-pgsql working and configured
pam-pgsql called by /etc/pam.d/httpd
PostgreSQL simple user database working, configured, filled w/ test users
Apache authenticating correctly using pam-pgsql --> PostgreSQL database

My aim is:
I want to have a single user database that I can edit to give different users access to different services. I want to put a web front-end to this database where I can add/remove/edit users and grant/revoke access to different services w/ simple check boxes.

The trouble is:
Right now pam_pgsql does not support authentication by group (as far as I know) so I can't just make users in the database members of groups samba, apache or what have you. In order to have per service authentication, I would have to maintain a separate table for each service. This is clunky, and the point of this project is to consolidate everything so I don't have 20 password databases in different places with different formats that all need to be synced w/ shadow. Solliciting solutions!

Much obliged,

Old 04-11-2004, 08:34 PM   #2
LQ Newbie
Registered: Apr 2004
Posts: 5

Original Poster
Rep: Reputation: 0
LDAP PostgreSQL Backend

I had started another thread relating to pam_pgsql access control to specific services. I mentioned that it does not support groups (although looking at the code I think any reasonable UNIX hacker could add it [i'm just a hack, not a hacker]). pam_ldap DOES support groups, however (er, I think it does anyway). The thing I don't like about LDAP is that I don't know much about how easy it is to administer an LDAP tree through a web interface. I also don't like having 5 different database systems on my machine if I can help it. I've heard it's possible to setup LDAP to use Postgres in the backend but that it could be difficult at times. Soliciting comments or ideally an offer for someone to add groups support to pam_pgsql...

Old 04-18-2004, 07:20 AM   #3
Registered: May 2001
Posts: 29,358
Blog Entries: 55

Rep: Reputation: 3545Reputation: 3545Reputation: 3545Reputation: 3545Reputation: 3545Reputation: 3545Reputation: 3545Reputation: 3545Reputation: 3545Reputation: 3545Reputation: 3545
//Moderator note: invoked merge(threads)
//Moderator note: you have crossposted a message, which is against the LQ Rules. Cross-posting is considered bad netiquette on your part, a waste of resources on LQ's part and a waste of time for LQ members who take the time your question. Please do not do that again.

FUP to:

Closed Thread

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
LDAP: Can't contact master ldap server rulirahm Linux - Networking 2 07-14-2014 02:02 AM
LDAP server not starting as user LDAP klnasveschuk Fedora 1 02-15-2007 04:49 AM
ldap-abook unable to get street name in ldap-entry Jingle Linux - Software 1 06-06-2004 07:13 PM
LDAP, PostgreSQL Access Control Database PrimusXPrimus Linux - Networking 0 04-12-2004 05:48 PM
postgresql -odbc & postgresql-jdbc installation kjsubbu Linux - Software 0 06-19-2003 02:50 AM > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 08:20 PM.

Main Menu
Write for LQ is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration