Details
-
Task
-
Status: Open (View Workflow)
-
Minor
-
Resolution: Unresolved
-
None
-
None
Description
COuld it be feasible to have anothe pam plugin that maps and automatically assign a given role to users depending on their group ?
for example Alice and Bob are both part of the dba group in ldap./unix/AD/whatever, so they are automatically assigned to the dba group upon succesfull login.
reasoning for this is the following :
since user who delegate authentication to third party ike ldap/AD/unix socket/whatever care about security, there is littel chance they accept to map admin user to a single one since it removes all ability to effectively have an account accountability process with the audit plugin for exempla, but not only.