LDAP - Can it Cut It?

From: cbaker@GOODYEAR.COM
Date: Thu Nov 07 2002 - 11:07:53 EST


(Ok, I am sure that this question has probably been asked. If so, just
please point me in the right direction.)

We have a large number of RS/6000 that are all tied together in a pretty
good NIS domain.

We are now asked to merge our domain with others... Not a real problem.
Basically, they just want the same login, same password, same data
automounted.... These things are being address.... More politics than
technical.

The real question is LDAP.

I have a number of users defined in my NIS domain that really do not need
full UNIX accounts with access to all my domain has. We just have them
there so they have some way of authorizing them in some intranet web sites.

I have begun setting up an iPlanet LDAP server for these folks. But, I see
the possibilities of this tool for doing much more. Alas, I am but a
novice (so far).

Can I use an LDAP server to perhaps do any of the following? :

- Authenticate ALL my RS/6k users? How? How would that mesh with NIS?

- Could I actually keep NIS password the same, but somehow use LDAP to
update the NIS master's passwords? Why?
    So I could synchronize my NIS passwords with the LDAP and in turn some
of these other NIS domains..... Single password!!??

- Can I use LDAP to not only authenticate passwords, but also group users
so they have specific areas, systems, programs they can and cannot enter?

I will stop there. I guess the first things I need are info from someone
who is now using LDAP to authenticate AIX users. And directions to where I
can quickly learn LDAP from the floor up.

Thanks,

Christopher M. Baker
Senior Technical Support Analyst
DSE/TCO
Goodyear Tire and Rubber Company
cbaker@goodyear.com

=================================================
Contains Confidential and/or Proprietary Information.
May not be copied or disseminated without the expressed
written consent of The Goodyear Tire & Rubber Company.
=================================================



This archive was generated by hypermail 2.1.7 : Wed Apr 09 2008 - 22:16:19 EDT