
<?xml version="1.0" encoding="utf-8"?>
<?xml-stylesheet type="text/css" href="http://selinuxproject.org/w/skins/common/feed.css?63"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
	<channel>
		<title>Labeled NFS/Demo/UserMapping - Revision history</title>
		<link>http://selinuxproject.org/w/?title=Labeled_NFS/Demo/UserMapping&amp;action=history</link>
		<description>Revision history for this page on the wiki</description>
		<language>en</language>
		<generator>MediaWiki 1.10.4</generator>
		<lastBuildDate>Tue, 21 May 2013 07:35:33 GMT</lastBuildDate>
		<item>
			<title>CraigGrube: /* Host Machine Identity Mapping */</title>
			<link>http://selinuxproject.org/w/?title=Labeled_NFS/Demo/UserMapping&amp;diff=373&amp;oldid=prev</link>
			<description>&lt;p&gt;&lt;span class=&quot;autocomment&quot;&gt;Host Machine Identity Mapping&lt;/span&gt;&lt;/p&gt;

			&lt;table border='0' width='98%' cellpadding='0' cellspacing='4' style=&quot;background-color: white;&quot;&gt;
			&lt;tr&gt;
				&lt;td colspan='2' width='50%' align='center' style=&quot;background-color: white;&quot;&gt;←Older revision&lt;/td&gt;
				&lt;td colspan='2' width='50%' align='center' style=&quot;background-color: white;&quot;&gt;Revision as of 18:24, 11 December 2008&lt;/td&gt;
			&lt;/tr&gt;
		&lt;tr&gt;&lt;td colspan=&quot;2&quot; align=&quot;left&quot;&gt;&lt;strong&gt;Line 113:&lt;/strong&gt;&lt;/td&gt;
&lt;td colspan=&quot;2&quot; align=&quot;left&quot;&gt;&lt;strong&gt;Line 113:&lt;/strong&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;The client configuration for this file was shown in one of the NFS&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;The client configuration for this file was shown in one of the NFS&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;install instruction sections, &lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;install instruction sections, &lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; font-size: smaller;&quot;&gt;but since 'nsswitch' is the current default for &lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;F9&lt;/del&gt;, it probably did&lt;/td&gt;&lt;td&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; font-size: smaller;&quot;&gt;but since 'nsswitch' is the current default for &lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;Fedora Core 9&lt;/ins&gt;, it probably did&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;not need to be changed.&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;not need to be changed.&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</description>
			<pubDate>Thu, 11 Dec 2008 18:24:19 GMT</pubDate>			<dc:creator>CraigGrube</dc:creator>			<comments>http://selinuxproject.org/page/Talk:Labeled_NFS/Demo/UserMapping</comments>		</item>
		<item>
			<title>CraigGrube: /* Authentication Service, Client Side */</title>
			<link>http://selinuxproject.org/w/?title=Labeled_NFS/Demo/UserMapping&amp;diff=372&amp;oldid=prev</link>
			<description>&lt;p&gt;&lt;span class=&quot;autocomment&quot;&gt;Authentication Service, Client Side&lt;/span&gt;&lt;/p&gt;

			&lt;table border='0' width='98%' cellpadding='0' cellspacing='4' style=&quot;background-color: white;&quot;&gt;
			&lt;tr&gt;
				&lt;td colspan='2' width='50%' align='center' style=&quot;background-color: white;&quot;&gt;←Older revision&lt;/td&gt;
				&lt;td colspan='2' width='50%' align='center' style=&quot;background-color: white;&quot;&gt;Revision as of 18:23, 11 December 2008&lt;/td&gt;
			&lt;/tr&gt;
		&lt;tr&gt;&lt;td colspan=&quot;2&quot; align=&quot;left&quot;&gt;&lt;strong&gt;Line 59:&lt;/strong&gt;&lt;/td&gt;
&lt;td colspan=&quot;2&quot; align=&quot;left&quot;&gt;&lt;strong&gt;Line 59:&lt;/strong&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;== Authentication Service, Client Side ==&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;== Authentication Service, Client Side ==&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; font-size: smaller;&quot;&gt;&lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;Host &lt;/del&gt;can be configured using&lt;/td&gt;&lt;td&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; font-size: smaller;&quot;&gt;&lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;Hosts &lt;/ins&gt;can be configured using&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;authentication-tui and checking a box&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;authentication-tui and checking a box&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; font-size: smaller;&quot;&gt;to turn on Kerberos authentication.  &lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;But below &lt;/del&gt;that, what was&lt;/td&gt;&lt;td&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; font-size: smaller;&quot;&gt;to turn on Kerberos authentication.  &lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; font-size: smaller;&quot;&gt;&amp;#160;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; font-size: smaller;&quot;&gt;&lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;Below &lt;/ins&gt;that, what was&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;actually happening was changes within the /etc/pam.d/system-auth&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;actually happening was changes within the /etc/pam.d/system-auth&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;file.  This is part of the authentication system on the machines,&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;file.  This is part of the authentication system on the machines,&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;the Plug-able Authentication Module (PAM).  This file was changed so&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;the Plug-able Authentication Module (PAM).  This file was changed so&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;that system authentication would additionally use the pam_krb5.so&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;that system authentication would additionally use the pam_krb5.so&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; font-size: smaller;&quot;&gt;library which authenticates a user-name using the Kerberos &lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;services&lt;/del&gt;.&lt;/td&gt;&lt;td&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; font-size: smaller;&quot;&gt;library which authenticates a user-name using the Kerberos &lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;service&lt;/ins&gt;.&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;= Identity Mapping Services =&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;= Identity Mapping Services =&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</description>
			<pubDate>Thu, 11 Dec 2008 18:23:30 GMT</pubDate>			<dc:creator>CraigGrube</dc:creator>			<comments>http://selinuxproject.org/page/Talk:Labeled_NFS/Demo/UserMapping</comments>		</item>
		<item>
			<title>CraigGrube: /* on the Client */</title>
			<link>http://selinuxproject.org/w/?title=Labeled_NFS/Demo/UserMapping&amp;diff=371&amp;oldid=prev</link>
			<description>&lt;p&gt;&lt;span class=&quot;autocomment&quot;&gt;on the Client&lt;/span&gt;&lt;/p&gt;

			&lt;table border='0' width='98%' cellpadding='0' cellspacing='4' style=&quot;background-color: white;&quot;&gt;
			&lt;tr&gt;
				&lt;td colspan='2' width='50%' align='center' style=&quot;background-color: white;&quot;&gt;←Older revision&lt;/td&gt;
				&lt;td colspan='2' width='50%' align='center' style=&quot;background-color: white;&quot;&gt;Revision as of 18:22, 11 December 2008&lt;/td&gt;
			&lt;/tr&gt;
		&lt;tr&gt;&lt;td colspan=&quot;2&quot; align=&quot;left&quot;&gt;&lt;strong&gt;Line 35:&lt;/strong&gt;&lt;/td&gt;
&lt;td colspan=&quot;2&quot; align=&quot;left&quot;&gt;&lt;strong&gt;Line 35:&lt;/strong&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;** returns UID, GID, shell, home directory path&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;** returns UID, GID, shell, home directory path&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;* Mount users NFS home directory using the LDAP values for path, UID, GID, etc...&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;* Mount users NFS home directory using the LDAP values for path, UID, GID, etc...&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; font-size: smaller;&quot;&gt;* &lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;Login &lt;/del&gt;user&lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;.&lt;/del&gt;&lt;/td&gt;&lt;td&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; font-size: smaller;&quot;&gt;* &lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;Complete &lt;/ins&gt;user &lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;login&lt;/ins&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;== on the NFS Server ==&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;== on the NFS Server ==&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</description>
			<pubDate>Thu, 11 Dec 2008 18:22:15 GMT</pubDate>			<dc:creator>CraigGrube</dc:creator>			<comments>http://selinuxproject.org/page/Talk:Labeled_NFS/Demo/UserMapping</comments>		</item>
		<item>
			<title>CraigGrube: /* on the Client */</title>
			<link>http://selinuxproject.org/w/?title=Labeled_NFS/Demo/UserMapping&amp;diff=370&amp;oldid=prev</link>
			<description>&lt;p&gt;&lt;span class=&quot;autocomment&quot;&gt;on the Client&lt;/span&gt;&lt;/p&gt;

			&lt;table border='0' width='98%' cellpadding='0' cellspacing='4' style=&quot;background-color: white;&quot;&gt;
			&lt;tr&gt;
				&lt;td colspan='2' width='50%' align='center' style=&quot;background-color: white;&quot;&gt;←Older revision&lt;/td&gt;
				&lt;td colspan='2' width='50%' align='center' style=&quot;background-color: white;&quot;&gt;Revision as of 18:21, 11 December 2008&lt;/td&gt;
			&lt;/tr&gt;
		&lt;tr&gt;&lt;td colspan=&quot;2&quot; align=&quot;left&quot;&gt;&lt;strong&gt;Line 29:&lt;/strong&gt;&lt;/td&gt;
&lt;td colspan=&quot;2&quot; align=&quot;left&quot;&gt;&lt;strong&gt;Line 29:&lt;/strong&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;* Examine /etc/idmapd.conf to find how where to do user translations&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;* Examine /etc/idmapd.conf to find how where to do user translations&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; font-size: smaller;&quot;&gt;** indicates nsswitch&lt;/td&gt;&lt;td&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; font-size: smaller;&quot;&gt;** &lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;Default configuration &lt;/ins&gt;indicates nsswitch&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;* Examine /etc/nsswitch.conf to find out what to use for translations&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;* Examine /etc/nsswitch.conf to find out what to use for translations&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; font-size: smaller;&quot;&gt;** indicates LDAP for user info and auto-mounting&lt;/td&gt;&lt;td&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; font-size: smaller;&quot;&gt;** &lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;Default configuration &lt;/ins&gt;indicates LDAP for user info and auto-mounting&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;* User enters user-name, look up user-name on LDAP server&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;* User enters user-name, look up user-name on LDAP server&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;** returns UID, GID, shell, home directory path&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;** returns UID, GID, shell, home directory path&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</description>
			<pubDate>Thu, 11 Dec 2008 18:21:23 GMT</pubDate>			<dc:creator>CraigGrube</dc:creator>			<comments>http://selinuxproject.org/page/Talk:Labeled_NFS/Demo/UserMapping</comments>		</item>
		<item>
			<title>CraigGrube: /* Host Machine Identity Mapping */</title>
			<link>http://selinuxproject.org/w/?title=Labeled_NFS/Demo/UserMapping&amp;diff=325&amp;oldid=prev</link>
			<description>&lt;p&gt;&lt;span class=&quot;autocomment&quot;&gt;Host Machine Identity Mapping&lt;/span&gt;&lt;/p&gt;

			&lt;table border='0' width='98%' cellpadding='0' cellspacing='4' style=&quot;background-color: white;&quot;&gt;
			&lt;tr&gt;
				&lt;td colspan='2' width='50%' align='center' style=&quot;background-color: white;&quot;&gt;←Older revision&lt;/td&gt;
				&lt;td colspan='2' width='50%' align='center' style=&quot;background-color: white;&quot;&gt;Revision as of 21:44, 10 December 2008&lt;/td&gt;
			&lt;/tr&gt;
		&lt;tr&gt;&lt;td colspan=&quot;2&quot; align=&quot;left&quot;&gt;&lt;strong&gt;Line 118:&lt;/strong&gt;&lt;/td&gt;
&lt;td colspan=&quot;2&quot; align=&quot;left&quot;&gt;&lt;strong&gt;Line 118:&lt;/strong&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;This configuration file sets the options available, and their order,&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;This configuration file sets the options available, and their order,&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;when using the GNU C library API's (e.g. libc.so.6) to lookup user&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;when using the GNU C library API's (e.g. libc.so.6) to lookup user&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; font-size: smaller;&quot;&gt;information. &lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt; In this example, the user did not have to touch this&lt;/del&gt;&lt;/td&gt;&lt;td&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; font-size: smaller;&quot;&gt;information. authconfig-tui &lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;can be &lt;/ins&gt;run &lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;to update &lt;/ins&gt;the nsswitch.conf file to&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; font-size: smaller;&quot;&gt;&lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;file by hand.  The GUI &lt;/del&gt;authconfig-tui &lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;was &lt;/del&gt;run &lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;and the LDAP user&lt;/del&gt;&lt;/td&gt;&lt;td&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; font-size: smaller;&quot;&gt;&lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;information was selected.  This updated &lt;/del&gt;the nsswitch.conf file to&lt;/td&gt;&lt;td&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;indicate that LDAP is to be used for user information on that host.&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;indicate that LDAP is to be used for user information on that host.&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;The pertinent changes to include LDAP were to the following nsswitch&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;The pertinent changes to include LDAP were to the following nsswitch&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</description>
			<pubDate>Wed, 10 Dec 2008 21:44:52 GMT</pubDate>			<dc:creator>CraigGrube</dc:creator>			<comments>http://selinuxproject.org/page/Talk:Labeled_NFS/Demo/UserMapping</comments>		</item>
		<item>
			<title>CraigGrube: /* Authentication Service, Client Side */</title>
			<link>http://selinuxproject.org/w/?title=Labeled_NFS/Demo/UserMapping&amp;diff=324&amp;oldid=prev</link>
			<description>&lt;p&gt;&lt;span class=&quot;autocomment&quot;&gt;Authentication Service, Client Side&lt;/span&gt;&lt;/p&gt;

			&lt;table border='0' width='98%' cellpadding='0' cellspacing='4' style=&quot;background-color: white;&quot;&gt;
			&lt;tr&gt;
				&lt;td colspan='2' width='50%' align='center' style=&quot;background-color: white;&quot;&gt;←Older revision&lt;/td&gt;
				&lt;td colspan='2' width='50%' align='center' style=&quot;background-color: white;&quot;&gt;Revision as of 21:40, 10 December 2008&lt;/td&gt;
			&lt;/tr&gt;
		&lt;tr&gt;&lt;td colspan=&quot;2&quot; align=&quot;left&quot;&gt;&lt;strong&gt;Line 59:&lt;/strong&gt;&lt;/td&gt;
&lt;td colspan=&quot;2&quot; align=&quot;left&quot;&gt;&lt;strong&gt;Line 59:&lt;/strong&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;== Authentication Service, Client Side ==&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;== Authentication Service, Client Side ==&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; font-size: smaller;&quot;&gt;&lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;The hosts were &lt;/del&gt;configured &lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;by running the&lt;/del&gt;&lt;/td&gt;&lt;td&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; font-size: smaller;&quot;&gt;&lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;Host can be &lt;/ins&gt;configured &lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;using&lt;/ins&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; font-size: smaller;&quot;&gt;authentication-tui &lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;GUI (Graphical User Interface) &lt;/del&gt;and checking a box&lt;/td&gt;&lt;td&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; font-size: smaller;&quot;&gt;authentication-tui and checking a box&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;to turn on Kerberos authentication.  But below that, what was&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;to turn on Kerberos authentication.  But below that, what was&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;actually happening was changes within the /etc/pam.d/system-auth&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;actually happening was changes within the /etc/pam.d/system-auth&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;file.  This is part of the authentication system on the machines,&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;file.  This is part of the authentication system on the machines,&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; font-size: smaller;&quot;&gt;the &lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;Pluggable &lt;/del&gt;Authentication Module (PAM).  This file was changed so&lt;/td&gt;&lt;td&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; font-size: smaller;&quot;&gt;the &lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;Plug-able &lt;/ins&gt;Authentication Module (PAM).  This file was changed so&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;that system authentication would additionally use the pam_krb5.so&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;that system authentication would additionally use the pam_krb5.so&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;library which authenticates a user-name using the Kerberos services.&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;library which authenticates a user-name using the Kerberos services.&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</description>
			<pubDate>Wed, 10 Dec 2008 21:40:21 GMT</pubDate>			<dc:creator>CraigGrube</dc:creator>			<comments>http://selinuxproject.org/page/Talk:Labeled_NFS/Demo/UserMapping</comments>		</item>
		<item>
			<title>CraigGrube: /* on the Client */</title>
			<link>http://selinuxproject.org/w/?title=Labeled_NFS/Demo/UserMapping&amp;diff=323&amp;oldid=prev</link>
			<description>&lt;p&gt;&lt;span class=&quot;autocomment&quot;&gt;on the Client&lt;/span&gt;&lt;/p&gt;

			&lt;table border='0' width='98%' cellpadding='0' cellspacing='4' style=&quot;background-color: white;&quot;&gt;
			&lt;tr&gt;
				&lt;td colspan='2' width='50%' align='center' style=&quot;background-color: white;&quot;&gt;←Older revision&lt;/td&gt;
				&lt;td colspan='2' width='50%' align='center' style=&quot;background-color: white;&quot;&gt;Revision as of 21:36, 10 December 2008&lt;/td&gt;
			&lt;/tr&gt;
		&lt;tr&gt;&lt;td colspan=&quot;2&quot; align=&quot;left&quot;&gt;&lt;strong&gt;Line 17:&lt;/strong&gt;&lt;/td&gt;
&lt;td colspan=&quot;2&quot; align=&quot;left&quot;&gt;&lt;strong&gt;Line 17:&lt;/strong&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;* PAM is used to authenticate users, which is configured to use Kerberos.&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;* PAM is used to authenticate users, which is configured to use Kerberos.&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; font-size: smaller;&quot;&gt;* &lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;Authenticate user-name using &lt;/del&gt;Kerberos &lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;and user entered &lt;/del&gt;password&lt;/td&gt;&lt;td&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; font-size: smaller;&quot;&gt;* Kerberos &lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;credentials are associated with a username, which require the correct &lt;/ins&gt;password &lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;to be accessed.&lt;/ins&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;== on the Server ==&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;== on the Server ==&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</description>
			<pubDate>Wed, 10 Dec 2008 21:36:39 GMT</pubDate>			<dc:creator>CraigGrube</dc:creator>			<comments>http://selinuxproject.org/page/Talk:Labeled_NFS/Demo/UserMapping</comments>		</item>
		<item>
			<title>CraigGrube: /* Identity Authentication Service */</title>
			<link>http://selinuxproject.org/w/?title=Labeled_NFS/Demo/UserMapping&amp;diff=322&amp;oldid=prev</link>
			<description>&lt;p&gt;&lt;span class=&quot;autocomment&quot;&gt;Identity Authentication Service&lt;/span&gt;&lt;/p&gt;

			&lt;table border='0' width='98%' cellpadding='0' cellspacing='4' style=&quot;background-color: white;&quot;&gt;
			&lt;tr&gt;
				&lt;td colspan='2' width='50%' align='center' style=&quot;background-color: white;&quot;&gt;←Older revision&lt;/td&gt;
				&lt;td colspan='2' width='50%' align='center' style=&quot;background-color: white;&quot;&gt;Revision as of 21:17, 10 December 2008&lt;/td&gt;
			&lt;/tr&gt;
		&lt;tr&gt;&lt;td colspan=&quot;2&quot; align=&quot;left&quot;&gt;&lt;strong&gt;Line 46:&lt;/strong&gt;&lt;/td&gt;
&lt;td colspan=&quot;2&quot; align=&quot;left&quot;&gt;&lt;strong&gt;Line 46:&lt;/strong&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;server.  The realm structure can be more complicated, but in this&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;server.  The realm structure can be more complicated, but in this&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;example, the network user-name matches the Kerberos principal of&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;example, the network user-name matches the Kerberos principal of&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; font-size: smaller;&quot;&gt;user-name@REALM (e.g. newuser@&lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;SETEST&lt;/del&gt;.COM).&lt;/td&gt;&lt;td&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; font-size: smaller;&quot;&gt;user-name@REALM (e.g. newuser@&lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;EXAMPLE&lt;/ins&gt;.COM).&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;== Authentication Service, Server Side ==&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;== Authentication Service, Server Side ==&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</description>
			<pubDate>Wed, 10 Dec 2008 21:17:37 GMT</pubDate>			<dc:creator>CraigGrube</dc:creator>			<comments>http://selinuxproject.org/page/Talk:Labeled_NFS/Demo/UserMapping</comments>		</item>
		<item>
			<title>CraigGrube: /* on the Client */</title>
			<link>http://selinuxproject.org/w/?title=Labeled_NFS/Demo/UserMapping&amp;diff=321&amp;oldid=prev</link>
			<description>&lt;p&gt;&lt;span class=&quot;autocomment&quot;&gt;on the Client&lt;/span&gt;&lt;/p&gt;

			&lt;table border='0' width='98%' cellpadding='0' cellspacing='4' style=&quot;background-color: white;&quot;&gt;
			&lt;tr&gt;
				&lt;td colspan='2' width='50%' align='center' style=&quot;background-color: white;&quot;&gt;←Older revision&lt;/td&gt;
				&lt;td colspan='2' width='50%' align='center' style=&quot;background-color: white;&quot;&gt;Revision as of 21:16, 10 December 2008&lt;/td&gt;
			&lt;/tr&gt;
		&lt;tr&gt;&lt;td colspan=&quot;2&quot; align=&quot;left&quot;&gt;&lt;strong&gt;Line 16:&lt;/strong&gt;&lt;/td&gt;
&lt;td colspan=&quot;2&quot; align=&quot;left&quot;&gt;&lt;strong&gt;Line 16:&lt;/strong&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;== on the Client ==&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;== on the Client ==&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; font-size: smaller;&quot;&gt;* &lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;Use &lt;/del&gt;PAM to authenticate &lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;user.&lt;/del&gt;&lt;/td&gt;&lt;td&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; font-size: smaller;&quot;&gt;* PAM &lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;is used &lt;/ins&gt;to authenticate &lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;users, which is configured to use &lt;/ins&gt;Kerberos&lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;.&lt;/ins&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; font-size: smaller;&quot;&gt;&lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;** indicates &lt;/del&gt;Kerberos&lt;/td&gt;&lt;td&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;* Authenticate user-name using Kerberos and user entered password&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;* Authenticate user-name using Kerberos and user entered password&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</description>
			<pubDate>Wed, 10 Dec 2008 21:16:28 GMT</pubDate>			<dc:creator>CraigGrube</dc:creator>			<comments>http://selinuxproject.org/page/Talk:Labeled_NFS/Demo/UserMapping</comments>		</item>
		<item>
			<title>CraigGrube: initial version</title>
			<link>http://selinuxproject.org/w/?title=Labeled_NFS/Demo/UserMapping&amp;diff=319&amp;oldid=prev</link>
			<description>&lt;p&gt;initial version&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;The network users are mapped between the Kerberos, NFS, and LDAP&lt;br /&gt;
server and the network hosts (i.e. Kerberos, NFS and LDAP clients)&lt;br /&gt;
using several different sub-systems.  The key to connecting them all&lt;br /&gt;
is the user-name, the string of text that uniquely identifies an&lt;br /&gt;
individual on the network.  This string is shared across the hosts&lt;br /&gt;
and between the three servers.  The use of user-name can further be&lt;br /&gt;
broken down between identity authentication and identity mapping&lt;br /&gt;
services.&lt;br /&gt;
&lt;br /&gt;
The two 'Basic Steps' sections below show the basic authentication&lt;br /&gt;
and identity mapping steps taken when a user logs on to a client&lt;br /&gt;
machine.  The sections following offer a more detailed explanation&lt;br /&gt;
of what is going on how the machines were configured to do it.&lt;br /&gt;
&lt;br /&gt;
= Simplified Authentication Steps for User Login =&lt;br /&gt;
== on the Client ==&lt;br /&gt;
&lt;br /&gt;
* Use PAM to authenticate user.&lt;br /&gt;
** indicates Kerberos&lt;br /&gt;
* Authenticate user-name using Kerberos and user entered password&lt;br /&gt;
&lt;br /&gt;
== on the Server ==&lt;br /&gt;
&lt;br /&gt;
* Kerberos server responds to client requests to check the user's password and return credentials.&lt;br /&gt;
'''Note''': The password is not sent across the network.  It is checked locally on the client using response from the Kerberos server.&lt;br /&gt;
&lt;br /&gt;
= Simplified User Mapping Steps =&lt;br /&gt;
&lt;br /&gt;
== on the Client ==&lt;br /&gt;
&lt;br /&gt;
* Examine /etc/idmapd.conf to find how where to do user translations&lt;br /&gt;
** indicates nsswitch&lt;br /&gt;
* Examine /etc/nsswitch.conf to find out what to use for translations&lt;br /&gt;
** indicates LDAP for user info and auto-mounting&lt;br /&gt;
* User enters user-name, look up user-name on LDAP server&lt;br /&gt;
** returns UID, GID, shell, home directory path&lt;br /&gt;
* Mount users NFS home directory using the LDAP values for path, UID, GID, etc...&lt;br /&gt;
* Login user.&lt;br /&gt;
&lt;br /&gt;
== on the NFS Server ==&lt;br /&gt;
&lt;br /&gt;
* NFS server maps user-name and group names to local UID and GID values (i.e. LDAP values are not used).&lt;br /&gt;
&lt;br /&gt;
= Identity Authentication Service =&lt;br /&gt;
&lt;br /&gt;
The authentication service is provided mainly by the Kerberos&lt;br /&gt;
server.  The realm structure can be more complicated, but in this&lt;br /&gt;
example, the network user-name matches the Kerberos principal of&lt;br /&gt;
user-name@REALM (e.g. newuser@SETEST.COM).&lt;br /&gt;
&lt;br /&gt;
== Authentication Service, Server Side ==&lt;br /&gt;
&lt;br /&gt;
The identity of the user-name is authenticated by the Kerberos&lt;br /&gt;
server interacting with the host machines and the NFS and LDAP&lt;br /&gt;
servers.  Principals are added and deleted on the Kerberos server&lt;br /&gt;
and it is responsible for checking that a user-name is in fact that&lt;br /&gt;
user.  It then hands out credentials for that user that can in turn&lt;br /&gt;
be checked by the host machines and the other servers.&lt;br /&gt;
&lt;br /&gt;
== Authentication Service, Client Side ==&lt;br /&gt;
&lt;br /&gt;
The hosts were configured by running the&lt;br /&gt;
authentication-tui GUI (Graphical User Interface) and checking a box&lt;br /&gt;
to turn on Kerberos authentication.  But below that, what was&lt;br /&gt;
actually happening was changes within the /etc/pam.d/system-auth&lt;br /&gt;
file.  This is part of the authentication system on the machines,&lt;br /&gt;
the Pluggable Authentication Module (PAM).  This file was changed so&lt;br /&gt;
that system authentication would additionally use the pam_krb5.so&lt;br /&gt;
library which authenticates a user-name using the Kerberos services.&lt;br /&gt;
&lt;br /&gt;
= Identity Mapping Services =&lt;br /&gt;
&lt;br /&gt;
The identity information is provided by the NFS and LDAP servers and&lt;br /&gt;
is mapped using a user-name.  LDAP provides the user information&lt;br /&gt;
necessary for the client hosts to instantiate a user.  NFS provides&lt;br /&gt;
the users' personal files.  It provides the files within their home&lt;br /&gt;
directories.&lt;br /&gt;
&lt;br /&gt;
== LDAP Identity ==&lt;br /&gt;
&lt;br /&gt;
The user-name is used to look up that user-name within the LDAP&lt;br /&gt;
directory.  The LDAP server maps that user-name to the information&lt;br /&gt;
needed by the host machines to instantiate that user locally.  In&lt;br /&gt;
this example the main information stored is:&lt;br /&gt;
* User ID (a unique number identifying the user)&lt;br /&gt;
* Groups to which the user-name is a member.&lt;br /&gt;
* User's shell&lt;br /&gt;
* Path to the user's home directory&lt;br /&gt;
* Group information&lt;br /&gt;
** Group-name to Group ID (unique group number)&lt;br /&gt;
&lt;br /&gt;
== NFS Server User Mapping ==&lt;br /&gt;
&lt;br /&gt;
The server in this example uses independent User IDs (UIDs) and&lt;br /&gt;
Group IDs (GIDs).  These are associated with user-names and group&lt;br /&gt;
names on its local system and do not use LDAP provided numerical&lt;br /&gt;
values for UID/GID.  When a client connects to the NFS server, the&lt;br /&gt;
user-name and group-name values are mapped to the local file&lt;br /&gt;
system's UID and GIDs.&lt;br /&gt;
&lt;br /&gt;
== Host Machine Identity Mapping ==&lt;br /&gt;
&lt;br /&gt;
The host machines are configured in several different ways in order&lt;br /&gt;
to map user Identity.  One of the first sources is the&lt;br /&gt;
/etc/idmapd.conf file's Translation section:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
[Translation]&lt;br /&gt;
Method = nsswitch&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The client configuration for this file was shown in one of the NFS&lt;br /&gt;
install instruction sections, &lt;br /&gt;
but since 'nsswitch' is the current default for F9, it probably did&lt;br /&gt;
not need to be changed.&lt;br /&gt;
&lt;br /&gt;
'''/etc/rc.d/nsswitch.conf''' is the file that configures nsswitch.&lt;br /&gt;
Nsswitch is the Name Service Switch configuration for the host.&lt;br /&gt;
This configuration file sets the options available, and their order,&lt;br /&gt;
when using the GNU C library API's (e.g. libc.so.6) to lookup user&lt;br /&gt;
information.  In this example, the user did not have to touch this&lt;br /&gt;
file by hand.  The GUI authconfig-tui was run and the LDAP user&lt;br /&gt;
information was selected.  This updated the nsswitch.conf file to&lt;br /&gt;
indicate that LDAP is to be used for user information on that host.&lt;br /&gt;
The pertinent changes to include LDAP were to the following nsswitch&lt;br /&gt;
subsystems:&lt;br /&gt;
* passwod (user,shell,UID,GIDs)&lt;br /&gt;
* shadow&lt;br /&gt;
* group (group-name&amp;lt;-&amp;gt;GID)&lt;br /&gt;
* automount&lt;/div&gt;</description>
			<pubDate>Wed, 10 Dec 2008 18:10:03 GMT</pubDate>			<dc:creator>CraigGrube</dc:creator>			<comments>http://selinuxproject.org/page/Talk:Labeled_NFS/Demo/UserMapping</comments>		</item>
	</channel>
</rss>