[OpenAFS] AFS+KRB5+LDAP users management

Charles Clancy security@xauth.net
Tue, 3 Jun 2003 06:48:41 -0500 (CDT)


On Mon, 2 Jun 2003, Lukas Kubin wrote:

> Is there a solution to help administrators do the users/groups management
> on site running $SUBJ?
> Now, when I do changes to any users' account, I have to do them on many
> places. Ie. in AFS protection server and others., Kerberos principals and
> LDAP user records.
> Do I really do it this way? Is there any tool simplifying this task? Or
> everybody running such site writes his own sync tools?
> Thank you.

There is no magic tool.  Everyone has their own custom scripts for user
management.  Others have created web interfaces for account management.

You could always use a Microsoft's Active Directory Server for your krb5
and LDAP server, and then you'd have a nice GUI for most of the user
administration.

[ t. charles clancy ]--[ tclancy@uiuc.edu ]--[ www.uiuc.edu/~tclancy ]