Details
-
Task
-
Status: Closed (View Workflow)
-
Major
-
Resolution: Fixed
-
2.3.2
-
None
-
MXS-SPRINT-74
Description
MaxScale's PAM authenticators support user and group mapping, but this is completely undocumented:
https://mariadb.com/kb/en/mariadb-maxscale-23-pam-authenticator/
The relevant information and limitations should probably be documented. Feel free to refer to the MariaDB Server documentation that describes the pam_user_map PAM module, where it is relevant:
https://mariadb.com/kb/en/library/user-and-group-mapping-with-pam/
One very important thing to document is that based on the commit associated with MXS-1758, it looks like group mapping only works with MaxScale if the proxy user is the ''@'%' anonymous user.
Attachments
Issue Links
- relates to
-
MXS-2292 Allow PAM user and group mapping to work with more specific host than '%'
- Closed
-
MXS-2294 Document how to configure user and group mapping for PAM authenticators
- Closed
-
MXS-334 Enable Pam.d Support
- Closed
-
MXS-1758 Support PAM group mapping, like MariaDB Server does
- Closed
-
MXS-2267 Document which accounts PAM authenticators will actually use
- Closed