3 ms·
LDAP as a public key service and servers configured via PAM to use that as source for pub keys. Nothing to distribute. Delete key from LDAP and second later use
by sp0ck 9y ago
LDAP as a public key service and servers configured via PAM to use that as source for pub keys. Nothing to distribute. Delete key from LDAP and second later user can't log on any machine. We are analysing teleport ssh suite for possible migration direction.
SSL is different story :)
- Pyxl101 9y agoCan anyone log into hosts if LDAP is down? Is that a concern? Is there an easy way to mitigate the concern if you wanted to? Interested in exploring this solution, but worried about the availability risk.
- voltagex_ 9y agoIn a Windows environment you mitigate this with multiple Directory servers. Users can log onto machines if the credentials are cached, I think. Unsure how PAM handles this on Linux.
- subway 9y agoVarious PAM module handle it differently. The hotness these days is `sssd`, which transparently tries multiple directory servers (be they AD, IPA, or straight LDAP).
- travisby 9y agotl;dr: Yes! There's some caching mechanism, _providing_ the user has already logged into the host. Also there seems to be some replication that could help. in my homelab I'm running RedHat IdM (which is their downstream version of _freeipa_). It's some value-add on top of LDAP on the server side, and sssd on the client side. My IdM runs in a VM on a server that isn't always powered on, and I'm still able to login thanks to sssd being configured to cache.. something. Clearly I haven't played with it as much as I should :).
- stephenr 9y agoApart from the caching stuff mentioned in other replies, this is why you have multiple ldap servers in a HA replication setup.
- scurvy 9y agoYeah running multiple servers is easy and the daemons are very mature at this point. LDAP daemons aren't crash prone. I haven't had an LDAP outage in over 10 years.