<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Authentication Servers</title>
	<atom:link href="http://blogs.cae.tntech.edu/mwr/2007/05/16/authentication-servers/feed/" rel="self" type="application/rss+xml" />
	<link>http://blogs.cae.tntech.edu/mwr/2007/05/16/authentication-servers/</link>
	<description>A partial repository of whatever comes to mind</description>
	<lastBuildDate>Sat, 21 Nov 2009 07:51:49 -0600</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Mike Renfro&#8217;s Blog : Authentication Servers, the Next Generation</title>
		<link>http://blogs.cae.tntech.edu/mwr/2007/05/16/authentication-servers/comment-page-1/#comment-95</link>
		<dc:creator>Mike Renfro&#8217;s Blog : Authentication Servers, the Next Generation</dc:creator>
		<pubDate>Thu, 02 Aug 2007 23:48:53 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.cae.tntech.edu/mwr/2007/05/16/authentication-servers/#comment-95</guid>
		<description>[...] mildly embarassed by my previous setup authentication servers, but this one should be a vast improvement. A reminder of the existing constraints and [...]</description>
		<content:encoded><![CDATA[<p>[...] mildly embarassed by my previous setup authentication servers, but this one should be a vast improvement. A reminder of the existing constraints and [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike Renfro&#8217;s Blog : The New File Server: Puppet and Modules</title>
		<link>http://blogs.cae.tntech.edu/mwr/2007/05/16/authentication-servers/comment-page-1/#comment-94</link>
		<dc:creator>Mike Renfro&#8217;s Blog : The New File Server: Puppet and Modules</dc:creator>
		<pubDate>Thu, 02 Aug 2007 21:24:12 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.cae.tntech.edu/mwr/2007/05/16/authentication-servers/#comment-94</guid>
		<description>[...] into an active-directory-member class, and that class warrants an entire followup artcle for my authentication notes, I&#8217;ll hold off on that part for now. But the Amanda configuration code, that&#8217;s worth [...]</description>
		<content:encoded><![CDATA[<p>[...] into an active-directory-member class, and that class warrants an entire followup artcle for my authentication notes, I&#8217;ll hold off on that part for now. But the Amanda configuration code, that&#8217;s worth [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike Renfro</title>
		<link>http://blogs.cae.tntech.edu/mwr/2007/05/16/authentication-servers/comment-page-1/#comment-42</link>
		<dc:creator>Mike Renfro</dc:creator>
		<pubDate>Mon, 04 Jun 2007 14:19:56 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.cae.tntech.edu/mwr/2007/05/16/authentication-servers/#comment-42</guid>
		<description>I fought a long way through option (a) there. ldapsearch worked fine, but nss just wouldn&#039;t cooperate. The errors I was running into were not unique, but I couldn&#039;t find anyone with working solutions, or else I just mis-implemented them.

Option (b) honestly never occurred to me, but it sounds promising. I may yet do that on my next round of work.</description>
		<content:encoded><![CDATA[<p>I fought a long way through option (a) there. ldapsearch worked fine, but nss just wouldn&#8217;t cooperate. The errors I was running into were not unique, but I couldn&#8217;t find anyone with working solutions, or else I just mis-implemented them.</p>
<p>Option (b) honestly never occurred to me, but it sounds promising. I may yet do that on my next round of work.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Peter Hoeg</title>
		<link>http://blogs.cae.tntech.edu/mwr/2007/05/16/authentication-servers/comment-page-1/#comment-41</link>
		<dc:creator>Peter Hoeg</dc:creator>
		<pubDate>Mon, 04 Jun 2007 12:39:20 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.cae.tntech.edu/mwr/2007/05/16/authentication-servers/#comment-41</guid>
		<description>Mike, it seems like an awful lot of local modifications taking place. I can off-hand think of two  solutions that would make things a lot easier for you:

a) Direct look-up in the AD using NSS, or

b) Set up a slave LDAP server that replicates from the AD and then NSS look-up against that using NSS.

/peter</description>
		<content:encoded><![CDATA[<p>Mike, it seems like an awful lot of local modifications taking place. I can off-hand think of two  solutions that would make things a lot easier for you:</p>
<p>a) Direct look-up in the AD using NSS, or</p>
<p>b) Set up a slave LDAP server that replicates from the AD and then NSS look-up against that using NSS.</p>
<p>/peter</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Marty Heyman</title>
		<link>http://blogs.cae.tntech.edu/mwr/2007/05/16/authentication-servers/comment-page-1/#comment-19</link>
		<dc:creator>Marty Heyman</dc:creator>
		<pubDate>Fri, 18 May 2007 00:09:24 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.cae.tntech.edu/mwr/2007/05/16/authentication-servers/#comment-19</guid>
		<description>You could probably accomplish this with fewer moving parts using an OpenLDAP Proxy (our CDS product) and name-service-switch (NSS) and pluggable-authentication-module (PAM) like our CNS product. Fewer moving parts, probably easier to set up.</description>
		<content:encoded><![CDATA[<p>You could probably accomplish this with fewer moving parts using an OpenLDAP Proxy (our CDS product) and name-service-switch (NSS) and pluggable-authentication-module (PAM) like our CNS product. Fewer moving parts, probably easier to set up.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike Renfro&#8217;s Blog &#8250; Directory Servers</title>
		<link>http://blogs.cae.tntech.edu/mwr/2007/05/16/authentication-servers/comment-page-1/#comment-17</link>
		<dc:creator>Mike Renfro&#8217;s Blog &#8250; Directory Servers</dc:creator>
		<pubDate>Thu, 17 May 2007 19:51:33 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.cae.tntech.edu/mwr/2007/05/16/authentication-servers/#comment-17</guid>
		<description>[...] I don&#8217;t use automount, and the vast majority of UID/GID mappings I already covered in the Authentication Servers post, though it may technically belong here. One other thing at the bottom of the [...]</description>
		<content:encoded><![CDATA[<p>[...] I don&#8217;t use automount, and the vast majority of UID/GID mappings I already covered in the Authentication Servers post, though it may technically belong here. One other thing at the bottom of the [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike Renfro&#8217;s Blog &#8250; The Beginnings of Infrastructure Management</title>
		<link>http://blogs.cae.tntech.edu/mwr/2007/05/16/authentication-servers/comment-page-1/#comment-15</link>
		<dc:creator>Mike Renfro&#8217;s Blog &#8250; The Beginnings of Infrastructure Management</dc:creator>
		<pubDate>Thu, 17 May 2007 01:06:33 +0000</pubDate>
		<guid isPermaLink="false">http://blogs.cae.tntech.edu/mwr/2007/05/16/authentication-servers/#comment-15</guid>
		<description>[...] Authentication servers [...]</description>
		<content:encoded><![CDATA[<p>[...] Authentication servers [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
