Showing posts with label users. Show all posts
Showing posts with label users. Show all posts

Saturday, August 13, 2011

DIY: LDAP user management with LAM

We've tried a lot of LDAP administration tools, and they all pale in comparison to LDAP Account Manager. Here are some details about this powerful tool.

Ah, Lightweight Directory Access Protocol (LDAP), that feisty, pain in the keister system that can be a real joy to set up and administer. Seriously, someone needs to create a distribution based solely on LDAP such that you put the disk in the machine, boot up, install, and enjoy it without having to go through a boat trip on the River Styx to get it up and running.

Until then, there are a handful of tools designed to make life more tolerable for the LDAP admin. One of those tools is LDAP Account Manager (LAM).

Features

  • Management of various account types
  • Profiles for account creation
  • Account creation via file upload
  • Automatic creation/deletion of home directories
  • Setting file system quotas
  • PDF output for all accounts
  • Editor for organizational units
  • Schema browser
  • LDAP browser
  • Multiple configuration files
  • Multi-language support
  • Support for LDAP+SSL/TLS

Two versions: LAM and LAM Pro

LAM comes with the tool’s standard features. LAM Pro comes with the standard LAM features, plus User Self Service, Additional Account modules, Run Custom Scripts, Access Levels, Password Reset Page.

Look at the full feature matrix for the differences in features. The costs for LAM Pro are:
  • Single computer: New license $240 USD / Upgrade $180 USD
  • Company license: New license $800 USD / Upgrade $600 USD

Installing LAM

Beyond having LDAP installed, the requirements for a LAM installation are:
  • Apache webserver (SSL recommended) with PHP module (PHP 5 >= 5.2.4). Other modules for Apache include: ldap, gettext, xml, and optional mcrypt.
  • Some LAM plugins may require additional PHP extensions.
  • Perl (optional, needed only for lamdaemon).
  • OpenLDAP >2.0.
  • A web browser that supports CSS2 and JavaScript (The Chrome browser has a problem displaying some of the pages correctly.)
Installation is quite simple and well documented (on a per-operating system case). After the installation is complete, point your browser to http://ADDRESS_TO_LAM_SERVER/lam and you should see the LAM login page. By default, the user credentials are:
  • user: admin
  • password: lam
Be sure to change the master password immediately upon login.

Using LAM

After you log in to LAM, you’ll see the main window, which is where you’ll do all aspects of LDAP account management (Figure A).
Figure A

You can even add Samba domains from within LAM. (Click the image to enlarge.)
To see how simple LAM is to use, click the Add User button. From the Add User window (Figure B), various user types can be added. You’ll notice that regardless of type the minimum that can be entered for a user is the lastname field. This is standard operating procedure for LDAP.
Figure B

A sample of the Add User window for the UNIX type. (Click the image to enlarge.)

Various features or warnings

  • If you need to edit OU entries, browse the schema, edit the profile, run the test, etc. and click the Tools link. Use caution when editing any of the profiles or OU entries.
  • The Tree View (Figure C) might appeal to many old-school LDAP users because of its more familiar layout.
Figure C

You can see everything laid out in reference to its standard LDAP organization. (Click the image to enlarge.)
  • You should utilize the PDF feature. It allows you to download PDF documents of users, groups, hosts, etc.
  • The server information will give you: Managed Suffixes, LDAP Version, Config suffix, Schema suffix, and SASL mechanisms.

Bottom line

All of the tools I have used that promised to make LDAP easier have paled in comparison to LAM. This web-based system can have any LDAP admin, regardless of experience, working serious magic with their LDAP accounts.

Plus, when you’re on a tight budget, deploying and managing LDAP (over Active Directory) will save some serious cash. And anyone with a DIY mindset will appreciate the flexibility of LDAP, but not every DIYer wants to have to take the time to learn to manage LDAP accounts from the command line.

Get more IT Tips, news, and reviews delivered directly to your inbox by subscribing to TechRepublic’s free newsletters.

Thursday, September 23, 2010

Google Warning Gmail users on China Spying Attempts

Google is using automated warnings to alert users of its GMAIL messaging service about wide spread attempts to access personal mail accounts that may indicate wholesale spying by the Chinese government. The victims include one leading privacy activist.

Warnings began appearing when users logged onto GMAIL on Thursday, according to Twitter posts from scores of GMAIL users. Upon accessing their accounts, users encountered a red banner reading "Your account was recently accessed from China," and providing a list of IP addresses used to access the account.

Users were then encouraged to change their password immediately. Based on Twitter posts, there doesn't seem to be any pattern to the accounts that were accessed, though one target is a prominent privacy rights activist in the UK who has spoken out against the Chinese government's censorship of its citizens.

Alexander Hanff of Privacy International in the UK said he saw the warning when he accessed a GMAIL account this morning. Hanff set up the personal account, which Hanff created in 2005 when he operated the Torrent Web site DVDR-Core, an early target of the Motion Picture Association of America in its battle to stop copyright piracy.

Hanff said he immediately changed the password, at Google's suggestion, and said the attempts to access his account from China were recent - occurring within the past couple months.

He only rarely accesses the account and does not use it for e-mail related to his work for Privacy International. Still, he said the account is easily discoverable online for those looking to contact him via e-mail, which might have made it a target.

However, a survey of other GMAIL users who were warned suggests that the China-based attacks were widespread and lacked a clear pattern. Andrew Turnbull, editor of The Extraordinary Marketing Blog and a recent business school graduate from Alberta, Canada was one.

Others included media consultants, doctors and gamers from the U.S., Canada, Columbia and countries in Europe - most without any clear personal or professional connection to China. Google did not immediately respond to a request for comment.

Hanff, of Privacy International, said he believed the attack on his account was random, not targeted at him as a privacy rights advocate. Those who accessed his account wouldn't have had access to any sensitive information related to his work for Privacy International, but would have found "a hell of a lot of spam," Hanff said.

However, he acknowledges that he may have come to the attention of the Chinese Government after a speech he gave at a EU-China Human Rights Network seminar that was attended by high level Chinese government officials. Hanff said he spoke about issues such as freedom of speech, differences between Europe and China and China's record of suppressing free speech.

Google and its GMAIL messaging system, along with the networks of other high profile U.S. and European firms, were known to have been compromised by attackers believed to be affiliated with the Chinese Military.

Those attacks, code named "Aurora" temporarily caused a rift in relations between the search giant and the Chinese government, with Google suspending all filtering of its search results in China. Recently, experts have warned that a new round of attacks similar to the original Aurora attacks had been detected, though its unclear if the e-mail hacking is related to that wave of activity.

Wednesday, March 24, 2010

New App for LinkedIn: Claims to Match Users to Job Openings

LinkedIn announced a new beta feature this week, Real-Time Profile Matches, intended to help make it easier for users to find the right jobs, and for hiring companies to find the right talent.

When a LinkedIn user posts a job opening on the site, LinkedIn's new proprietary technology searches its database of more than 60 million professionals for profiles that best match the job description.

It then returns a list to the job poster of up to 24 matches, displaying candidates in a business-card-style format and rating them on a scale of 1through 10.

Because the search technology is proprietary, Parker Barrile, director of product management at LinkedIn, could not say what the technology looks for in a profile to deem it an appropriate job match but Barrile does say that it "goes a level deeper than just keyword matching."

If you're looking for a new job, Barrile suggests two things to ensure that your profile is appearing as an appropriate job match. First, be sure that your profile is up to date and complete.

That means filling out the experience, summary and professional headline sections, and including comprehensive details about your past and present work positions. Second, utilise the Status Update feature, which can alert your network that you're job searching and inform a job poster that you're an available candidate.

Currently, Real-Time Profile Matches is a free feature, but Barrile couldn't say for how long.

Wednesday, December 2, 2009

The Economist Debate: 90% of Users Do Not Trust Cloud Computing - Amazon CTO Video



Click here to enter the Economists Debate on the Cloud and how much we trust it.

At the Supernova Conference in San Francisco, Amazon Chief Technology Officer Werner Vogels (@Werner) broadly outlines the benefits of a cloud-based infrastructure. He says Web services offer businesses four distinct advantages:

1.Lower costs (both capital and operational)
2.Reducing time to market (as the provisioning of IT resources cease to be a barrier)
3.Increased security (using cloud services that are more secure than those you could build on your own)
4.Better scalability

Wednesday, September 30, 2009

New Google Wave Beta Testing - Released to 100,000 Users



Here are some of the Google Wave features and add-ons that could drive real benefits for organizations:

Ribbit (currently in beta) brings in audio with its conference call gadget and message gadget, incorporating real-time audio streaming and recorded messages (including a transcript) in the associated wave. No means of communication left behind!

Salesforce.com is working on a prototype extension to Google Wave that could help its customers provide customized, documented support in their own businesses — leveraging the cloud-based platforms and interactive capabilities. Support cases are maintained and updated, from initial point of contact to resolution within the wave. Google Wave, with the ability to interact with other cloud platforms, could change the way customer support is handled.

SAP is working on a prototype for business process modeling called Gravity. Using the communication integration capabilities of Wave, users collaborate on business process modeling activities in near real time — working together to approve models, find windows of opportunity for business process automation and help build a strategy for execution and refinement of the processes.

It’s still early days for the Wave technology (some bugs and kinks need to be worked out) but it all looks promising and a tool for CIOs to embrace

Tuesday, April 28, 2009

Bluetooth is now as fast as Wi-Fi

Let's talk about how Bluetooth got as fast as Wi-Fi.


Bluetooth 3.0
High Speed Bluetooth has stopped being chained to the low-power, low-throughput radio that has been both its strength and its weakness. Newly developed code lets Bluetooth applications now run over 802.11g wireless connections in the 2.4GHz, with a throughput jump to 20M to 24Mbps, from 1M to 3Mbps.

One of the key creators of this bit of wizardy is Kevin Hayes, a technical fellow with Atheros Communications, who has worked in more than a dozen task groups around the IEEE 802.11 wireless LAN standard, and in Wi-Fi Alliance projects such as Wi-Fi Protected Access.

Hayes was the technical editor for the 802.11 Protocol Adaption Layer (PAL), one of the big changes in the just-announced Bluetooth 3.0 specification, a two-year project. PAL, together with the 802.11 media access control (MAC) and 802.11 physical (PHY) layers constitute the Alternate MAC/PHY or AMP, enabling a Bluetooth profile (such as file transfer) to run over a Wi-Fi link.


It may be the beginning of "Bluetooth everywhere," according to Network World blogger Craig Mathias but make sure you look for the full formal designation: Bluetooth 3.0 + High Speed (or HS). (For some uses, vendors can deploy 3.0 without the ability to use a Wi-Fi connection but they can't use "high speed" in labeling it).


Is this such a big change?
It's a generational change. The Bluetooth SIG wanted something a) that would deliver five to ten times the performance of current Bluetooth b) that would be available to customers in a short timeframe and that was proven technology.

Gartner analysts picked Bluetooth 3.0 as one of eight hot mobile technologies to watch.
With 3.0, the Bluetooth stack exploits whichever radio link is best. Firstly, it would only be used if both sides support it, in silicon and software. Some of the classic Bluetooth profiles, such as the headset profile or the hands-free profile for a car kit, will never use high-speed [Wi-Fi] silicon.

There are many object and file transfer protocols and profiles that would happily use it. Things like file transfer, object push, printing, imaging: all these would involve taking some object or file from one device and moving it to another. The new standard is appropriate for almost all of these.

What happens when the new Bluetooth code is deployed on gadgets with a Wi-Fi radio?
There's a generic Bluetooth framework, that rides over the classic Bluetooth radio. There are a set of protocols for doing things like discover and negotiation and so on. Some configuration variables are currently handed over to the new software module, called the 802.11 PAL, which translates those variables from the Bluetooth domain to the .11 domain. It translates the sent data packets from the Bluetooth stack, and broadcasts these over 802.11.

How does it do that?
It removes part of the Bluetooth stack header and replaces it with the 802.11 header, and sends this to the 802.11 MAC for transmission. And it reverses this process when you're receiving a Bluetooth 802.11 packet.

How complicated was this?
What was the most challenging or puzzling thing about creating this translation layer? Bluetooth, as a stack, does have a different set of expectations in its parlance, compared to IP. For example, the idea of "best effort" in transmission. In IP, best effort means "this channel gets no advanced quality of service." Bluetooth is not quite like that. In Bluetooth, best effort means it doesn't get any advanced priority service, but it is a reliable channel anyway.

Another example, is the way Bluetooth defines certain channels, for example, for audio streaming: Bluetooth will send packets and retry if they get dropped, but after a certain amount of time has passed, it will stop retrying. While 802.11 also does retries, it doesn't use time measurements, but a configurable number of retry attempts.

The PAL layer adapts the intentions of the Bluetooth layer to the capabilities of the features in the 802.11 MAC and PHY physical layers.

How does this mess up existing Bluetooth applications or usage?
This process is very clean: the Bluetooth stack itself is unchanged. That was very important. The "profiles" in the Bluetooth stack are really the applications. That was a very clear mandate from the Bluetooth SIG that none of these would change in order to support this alternate MAC/PHY. They didn't want to have to test all their profiles all over again.

How does adding this new translation step affect performance?
There's no performance loss, because there's no need for any queuing in the adaptation layer and this is normally where you lose performance in a network stack. The 802.11 stack can accept packets at 20Mbps to 25 Mbps: that's more than 10 times as fast as the classic vanilla flavoured Bluetooth.

What about the reverse? How does the Bluetooth stack receive packets at 20Mbps to 25 Mpbs from the 802.11 stack?
That part of the Bluetooth stack is not standardised. So if a mobile phone manufacturer did nothing in their 3.0 implementation to address this, you might have performance issues. You must make changes to this layer to perform at high speeds with 3.0, by adding resources for queuing.

How big a problem is that technically?
It's well within the developers capabilities to address these issues.


What parts of the stack do I have to look at to optimize performance?
This is simply the same exercise you would go through for Bluetooth as you would for adapting your network stack for gigabit Ethernet. You are on familiar ground here.

What will users see?
Clearly, to benefit from the high speed connection, you'll need two devices with the new 3.0 silicon, e.g. a smartphone trying to send five to ten jobs to a PC. Users will be be shown a simple menu option on their smartphone, saying "send to Bluetooth" or a simple Bluetooth menu. They would go through the same motions as they do now, in transferring data but it would just happen faster.


When will they see it?
Nine to 12 months is the time frame, according to the Bluetooth SIG. If you are wanting a smartphone with Bluetooth and 802.11, you'll have to wait for the next version of the phone to come out. I am sure the manufacturers and providers will rush to get these on the shelves as quickly as they can when the technology is available.