published by whitemice on Wed, 01/14/2015 - 00:00    
  
  
    LINUX has long been plagued with a rather lousy identity management scheme.  Beyond the limitations of POSIX's getent and related calls [which can be very inefficient] the attempts to stub in network-aware identity services such as LDAP have only piled onto the rough edges.  NSCD attempted to work around performance problems via caching - and did not do very well.  Then was NSLCD the next evolution of NSCD which was better, but still inflexible.  Identity management in more complex networks is a tedious business and what administrators need more than anything else is flexibility.