Integration with libpam-ldap and ncsd

Note that, with this setup, LDAP groups will automatically be assigned as Linux groups, same as using NIS (for instance)

Setup

1sudo apt-get install -y libpam-ldap nscd

Here are some answers to the prompts you will see during the setup process:

PromptAnswer
Should debconf…?Yes
LDAP URIYour GLAuth instance fqdn and port number
Distinguished Namedc=glauth,dc=com (replace with your org’s DN)
LDAP version3
Make local root database adminYes
Does the LDAP db require login?No
LDAP account for rootcn=serviceuser,ou=service,dc=glauth,dc=com
LDAP root password
Encryptioncrypt

You can reconfigure this later:

1sudo dpkg-reconfigure ldap-auth-config

In /etc/nsswitch.conf:

1passwd: ldap compat systemd
2group: ldap compat systemd
3shadow: ldap compat
4gshadow: files

In /etc/pam.d/common-session:

1session required pam_mkhomedir.so skel=/etc/b-skel umask=0077

Yes, this does create a home directory for each user being authenticated. We use a strong mask so that we can start storing sensitive info, if needed, in their home directory.

Note that we should also create our skeleton directory:

1sudo mkdir /etc/b-skel

In /etc/pam.d/common-password, remove use_authtok if present.

Allow password login. Make sure you have, in /etc/ssh/sshd_config:

1PasswordAuthentication yes

Security

Now, let’s say that you are connecting to GLAuth using LDAPS, but you are using a self-signed cert. Change /etc/ldap/ldap.conf accordingly:

1TLS_REQCERT never

You can also restrict access to certain groups.

In /etc/pam.d/common-auth:

1auth required pam_access.so

In /etc/security/access.conf:

1-:ALL EXCEPT root (admin):ALL EXCEPT LOCAL

Debugging

To debug authentication issues:

1sudo tail -f /var/log/auth.log

You can also check from the command line:

1sudo getent passwd
2sudo getent group
3finger {username} # if finger is installed
Copyright 2021