Pluggable authentication modules (PAM)

Tell us your most wanted features from QNAP products.

Pluggable authentication modules (PAM)

Postby pwilson » Wed Jul 18, 2012 4:49 am

Please join the '90's and actually implement PAM as quickly as possible.

It is already part of both MacOS and Linux, and has been around for more than 15 years. PAM is currently supported in the AIX operating system, DragonFly BSD, FreeBSD, HP-UX, Linux, Mac OS X, NetBSD and Solaris. Using PAM would make it far easier to implement SSO (Single Sign-On) in all kinds of interesting ways. Including using Samba credentials to login to the NAS via SSH etc, which would make NAS shell access far more transparent for Windows users to access the NAS.

You have recently added support for "home" folders in your Windows networking, so home folders with "user login" to the NAS, rather than "admin-only" login via SSH would be far easier to implement from various platforms, if PAM was implemented.

Microsoft is unlikely to ever play nice with the Linux world, (note especially their refusal to offer a built-in "SSH" client in Windows, despite SSH existing for over 30 years now), and the changes in default network security settings introduced in Windows 7, which effectively "broke" Windows access to non-Microsoft SMB Servers, with no added benefit to the End-User). With the direction Microsoft seems determined to take Windows in, I'm assuming the number of Linux and Mac users can only continue to grow in the near future.

Patrick.

Patrick M. Wilson
Victoria, BC Canada
QNAP TS-419P+ w/ 4 * Seagate Barracuda 2TB 5900rpm (RAID5) - FW: 3.8.1 Build 20121205
Forums: View My Profile - Search My Posts - Send Private Message - View My Photo - Top Community Forum Posters
QNAP: Turbo NAS User Manual - QNAP Wiki - QNAP Tutorials - QNAP FAQs - HowTos - QNAP Video Library
User avatar
pwilson
Moderator
 
Posts: 3793
Joined: Fri Mar 06, 2009 11:20 am
Location: Victoria, BC, Canada
NAS Model: TS-419P+

Re: Pluggable authentication modules (PAM)

Postby dchang0 » Thu Dec 13, 2012 6:21 pm

I second this motion.

Here's the deal--we're trying to use QNAP NASes as "intermediaries" between Windows and LINUX. The Windows boxes can get to the NAS shares via CIFS. The LINUX boxes need SFTP/SSH AND want to be able to use Active Directory user accounts.

That means that we need OpenSSH installed on the QNAP (which can be done, but by hand), and we need PAM support for OpenSSH to use LDAP to get to Active Directory (easier than going Kerberos 5 + GSSAPI, which would also get us the same result).

QNAP, please, please incorporate PAM into your standard firmware!
dchang0
New here
 
Posts: 4
Joined: Thu Dec 13, 2012 6:17 pm
NAS Model: TS-x19P II

Re: Pluggable authentication modules (PAM)

Postby doktornotor » Thu Dec 13, 2012 7:41 pm

Long overdue indeed.
QNAP, why is your homework still not done?
3.8.2 Build0301 - Codename "Titanic" - Dear customer, GTFO! NOT acceptable once again!
QTS 4.0 - Codename "Leaky Snail" - Slower than ever. Yes, we can!
QNAP's new logo competition
User avatar
doktornotor
Experience counts
 
Posts: 2650
Joined: Tue Apr 24, 2012 5:44 am
NAS Model: Not Selected

Re: Pluggable authentication modules (PAM)

Postby geva » Fri Dec 14, 2012 3:54 am

+1

I'm slowly moving away from Windows, but the Linux NAS is currently the centerpiece which I've frequently been using to bridge things together.

That said, if QNAP doesn't step up to the plate on many of these basic Linux staples, I'll just be building my own Linux systems and get away from their NASes entirely (or go to Synology).
geva
Know my way around
 
Posts: 233
Joined: Wed Aug 31, 2011 4:21 pm
Location: Lyon, France
NAS Model: TS-219P+


Return to Features Wanted

Who is online

Users browsing this forum: No registered users and 3 guests