Access Filter Setup with SSSD   ldap_access_filter  (string)   If using access_provider = ldap , this option is mandatory. It specifies an LDAP search filter criteria that must be met for the user to be granted access on this host. If access_provider = ldap  and this option is not set, it will result in all users being denied access. Use access_provider = allow  to change this default behaviour.   Example:  access_provider = ldap  ldap_access_filter = memberOf=cn=allowed_user_groups,ou=Groups,dc=example,dc=com    Prerequisites  yum install sssd   Single LDAP Group   Under domain/default in /etc/sssd/sssd.conf  add:  access_provider = ldap ldap_access_filter = memberOf=cn=Group Name,ou=Groups,dc=example,dc=com   Multiple LDAP Groups   Under domain/default in /etc/sssd/sssd.conf  add:  access_provider = ldap ldap_access_filter = (|(memberOf=cn=System Adminstrators,ou=Groups,dc=example,dc=com)(memberOf=cn=Database Users,ou=Groups,dc=example,dc=com))   ldap_access_filter  accepts standa...
 
 
Comments
Post a Comment