Possible to run an IdP from /etc/passwd or NIS?

Cameron Kerr cameron.kerr at otago.ac.nz
Fri Mar 7 20:12:37 EST 2014


Would it be possible to create a local LDAP server that feeds off the 'local' user database? Never tried it, but worth a shot?

Sent from my iPhone

> On 8/03/2014, at 9:37 am, "Phil Gold" <phil at cs.jhu.edu> wrote:
> 
> I run a bunch of systems that use NIS for identity management (and which
> aren't going to use anything else in the near future, at least).  I've
> been asked to set up an IdP that uses these NIS accounts for
> authentication.  I don't seem to be having success with this so I'm hoping
> someone here can point me in the right direction.
> 
> I'm trying to use the UsernamePassword LoginHandler, but I haven't had
> much luck.  It seems that the JAAS UnixLoginModule doesn't actually do any
> authentication, so it lets literally anything in.  I've tried the
> JndiLoginModule with the following configuration:
> 
>    ShibUserPassAuth {
>      com.sun.security.auth.module.JndiLoginModule required
>        user.provider.url="nis://nis.example.com/example.com/user"
>        group.provider.url="nis://nis.example.com/example.com/system/group";
>    };
> 
> but a) it appears to fail every login attempt, and b) I don't see any
> network traffic between the IdP and the NIS server.
> 
> Am I using JndiLoginModule correctly?  Is there a different JAAS module
> that would work better?  Is there a different LoginHandler I should be
> using?
> 
> (While I'm at it, is there a way to get Unix account information into SAML
> attributes?  I'd really like to have group membership available and the
> GECOS information would be nice, too.)
> 
> In case it makes a difference, I'm running version 2.4.0 of the IdP on
> Tomcat 6.0.24 installed from RPM onto a RHEL 6.5 system.
> 
> -- 
> Phil Gold / JHU CS IT (Linux)
> phil at cs.jhu.edu
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


More information about the users mailing list