About nixCraft

Force OpenSSH (SSHD) to use authentication via LDAP server

Posted by Vivek Gite [Last updated: November 6, 2006]

Lightweight Directory Access Protocol, or LDAP , is a directory services running over TCP/IP. Most large business and organization use LDAP for centralized authentication.

You can read LDAP Linux HOWTO for setup and configuration. If your workstation or server setup to authenticate via LDAP, open ssh will not work when user try to connect from remote system. You need to make little modification to openssh, so that it can authenticate you via LDAP:

Open /etc/ssh/sshd_config file
# vi /etc/ssh/sshd_config file

Append or modify line as follows:
PAMAuthenticationViaKbdInt yes

Restart OpenSSH
# /etc/init.d/sshd restart

Now ssh server will accept login for remote users.

Want to stay up to date with the latest Linux tips, news and announcements? Subscribe to our free e-mail newsletter or RSS feed to get all updates. You can Email this page to a friend.

You may also be interested in other helpful articles:

Discussion on This Article:

  1. Aneesh Says:

    I think no additional configuration is needed because the file /etc/nsswitch.conf

  2. Aneesh Says:

    I think no additional configuration is needed because the file /etc/nsswitch.conf contains the entry
    passwd: files ldap

    This will do the trick.

  3. nixcraft Says:

    LDAP and authentication mechanism is already configured. But you need to tell this to OpenSSH.

Leave a Reply

We encourage your comments, and suggestions. But please stay on topic, be polite, and avoid spam. Thank you very much for stopping by our site!

XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

*
To prove you're a person (not a spam script), type the security word shown in the picture. Click on the picture to hear an audio file of the word.
Click to hear an audio file of the anti-spam word

Copyright © 2004-2008 nixCraft. All rights reserved - TOS/Disclaimer - Privacy policy - Sitemap - Powered by Open source software.