- 专利标题: ENFORCING JIT ACCESS CONTROL BY LEVERAGING PAM AND LDAP
-
申请号: US18159460申请日: 2023-01-25
-
公开(公告)号: US20240250948A1公开(公告)日: 2024-07-25
- 发明人: Yan Tesis , Kamran Khan
- 申请人: Salesforce, Inc.
- 申请人地址: US CA San Francisco
- 专利权人: Salesforce, Inc.
- 当前专利权人: Salesforce, Inc.
- 当前专利权人地址: US CA San Francisco
- 主分类号: H04L9/40
- IPC分类号: H04L9/40 ; H04L61/4523
摘要:
Usage of Pluggable Authentication Module (PAM) for time bound access control to any PAM enabled Linux application predicated by rules stored in an LDAP directory including a processor to execute computer-executable instructions for receiving a user information from a user interface indicative of a user, receiving an access request via PAM indicative of the user information, a time of invocation of the access request and the host server, querying a lightweight directory access protocol directory in response to the user information and the request, receiving a plurality of attribute values associated with the user information including a time bound access limit and a host access restriction information, and coupling an access success response to the pluggable access module in response to a host server access allowance indicated by the host access restriction information for the host service and the time of invocation being within the time bound access limit.
信息查询