[tac_plus] linux pam and ldap - or just linux pam

Asif Iqbal vadud3 at gmail.com
Mon Aug 5 19:54:05 UTC 2013

This is how we setup our tac_plus with libpam_ldap on ubuntu

# sudo apt-get install build-essential libpam0g-dev gcc flex bison
 libwrap0-dev libpam-ldap
# (compile tac_plus and it should find pam libraries)

# cat /etc/pam.d/tac_plus
auth   sufficient        pam_ldap.so

# cat /etc/tacacs.conf
user = foo {
        login = PAM
        member = bar

# cat /etc/ldap.conf
base ou=People,dc=example,dc=com
uri  ldaps:// ldaps://
ldap_version 3
binddn uid=mybinduid,ou=people,dc=example,dc=com
bindpw secret
pam_password crypt

# cat /etc/ldap/ldap.conf
TLS_CACERT /etc/ssl/certs/company.cer

Hopefully I did not miss anything.

