-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
When management vrf is enabled and vrf is present in the tacacs config, if we are unable to reach any configured tacacs server, try setting vrf context on the socket. Previously libnss-tacplus worked only with ssh@mgmt, now works with normal ssh in mgmt vrf Setting via the socket (rather than vrf context) is required so we don't set the VRF context for arbitrary processes that do uid or username lookups.
- Loading branch information
Dave Olson
committed
May 23, 2017
1 parent
490882d
commit 52aa2d4
Showing
3 changed files
with
12 additions
and
5 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -9,8 +9,9 @@ libnss-tacplus (1.0.2) unstable; urgency=low | |
libraries can connect to a TACACS+ server without being tacacs aware. | ||
* Improved debugging messages. | ||
* Minor corrections to Copyright and licensing | ||
* Added vrf config variable, so NSS lookups work correctly$ | ||
|
||
-- Dave Olson <[email protected]> Tue, 29 Nov 2016 16:55:16 -0800 | ||
-- Dave Olson <[email protected]> Tue, 07 Mar 2017 12:58:03 -0800 | ||
|
||
libnss-tacplus (1.0.2-1) unstable; urgency=low | ||
|
||
|
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,14 +1,17 @@ | ||
Source: libnss-tacplus | ||
Priority: optional | ||
Maintainer: Dave Olson <[email protected]> | ||
Build-Depends: debhelper (>= 9), autotools-dev, libtac-dev, libtacplus-map-dev, libaudit-dev, autoconf, libpam-tacplus-dev, dpkg-dev (>= 1.16.1) | ||
Build-Depends: debhelper (>= 9), autotools-dev, libtac-dev (>= 1.4.1~), | ||
libtacplus-map-dev, libaudit-dev, autoconf, libpam-tacplus-dev, | ||
dpkg-dev (>= 1.16.1), git | ||
Section: libs | ||
Standards-Version: 3.9.6 | ||
Homepage: http://www.cumulusnetworks.com | ||
|
||
Package: libnss-tacplus | ||
Architecture: any | ||
Depends: ${shlibs:Depends}, ${misc:Depends}, libtac2, libtacplus-map1, libaudit1 | ||
Depends: ${shlibs:Depends}, ${misc:Depends}, libtac2 (>= 1.4.1~), | ||
libtacplus-map1, libaudit1 | ||
Description: NSS module for TACACS+ authentication without local passwd entry | ||
Performs getpwname and getpwuid lookups via NSS for users logged in via | ||
tacacs authentication, and mapping done with libtacplus_map |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters