Can anyone log into hosts if LDAP is down? Is that a concern? Is there an easy way to mitigate the concern if you wanted to? Interested in exploring this solution, but worried about the availability risk.
in my homelab I'm running RedHat IdM (which is their downstream version of _freeipa_). It's some value-add on top of LDAP on the server side, and sssd on the client side. My IdM runs in a VM on a server that isn't always powered on, and I'm still able to login thanks to sssd being configured to cache.. something. Clearly I haven't played with it as much as I should :).
Users can log onto machines if the credentials are cached, I think. Unsure how PAM handles this on Linux.
The hotness these days is `sssd`, which transparently tries multiple directory servers (be they AD, IPA, or straight LDAP).