04.06.2013 Views

UCS 2.4 - Univention

UCS 2.4 - Univention

UCS 2.4 - Univention

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

10.12 SSH<br />

In the basic setting, a resolved group or host name is kept in cache for one hour, a user name for ten min-<br />

utes. With the <strong>Univention</strong> Configuration Registry variables nscd/group/positive_time_to_live,<br />

nscd/hosts/positive_time_to_live and nscd/passwd/positive_time_to_live these peri-<br />

ods can be extended or diminished (in seconds).<br />

As of <strong>UCS</strong> 2.3 a <strong>Univention</strong> Directory Listener module is also included, which empties the group cache<br />

when a change is made to group memberships. This listener module can be activated/deactivated<br />

via the <strong>Univention</strong> Configuration Registry variable nscd/group/invalidate_cache_on_changes<br />

(true/false).<br />

From time to time it might be necessary to manually invalidate the cache of the NSCD. This can be done<br />

individually for each cache table with the following commands:<br />

nscd -i passwd<br />

nscd -i group<br />

nscd -i hosts<br />

The verbosity of the log messages can be configured through the <strong>Univention</strong> Configuration Registry vari-<br />

able nscd/debug/level.<br />

10.11.4 Configuration of /etc/hosts in <strong>Univention</strong> Configuration Registry<br />

The configuration file /etc/hosts is managed through a <strong>Univention</strong> Configuration Registry template.<br />

Individual entries can be added through a <strong>Univention</strong> Configuration Registry variable in the format<br />

hosts/static/192.168.1.1="test.local test".<br />

10.12 SSH<br />

When installing a <strong>UCS</strong> system, an SSH server is also installed per preselection. SSH is used for realising<br />

encrypted connections to other hosts, wherein the identity of a host can be assured via a check sum.<br />

Essential aspects of the SSH server’s configuration can be adjusted in <strong>Univention</strong> Configuration Registry.<br />

By default the login of the privileged root user is permitted by SSH (e.g. for configuring a newly installed<br />

system where no users have been created yet, from a remote location). If the <strong>Univention</strong> Configuration<br />

Registry variable sshd/permitroot is set to without-password, then no interactive password request<br />

will be performed for the root user, but only a login based on a public key. By this means brute force<br />

attacks to passwords can be avoided. If the variable is set to no, then the root user cannot login via SSH.<br />

The <strong>Univention</strong> Configuration Registry variable sshd/xforwarding can be used to configure whether<br />

an X11 output should be passed on via SSH. This is necessary, for example, for allowing a user to start a<br />

program with graphic output on a remote computer by logging in with ssh -X TARGETHOST. Valid settings<br />

are yes and no.<br />

The standard port for SSH connections is port 22 via TCP. If a different port is to be used, this can be<br />

arranged via the <strong>Univention</strong> Configuration Registry variable sshd/port.<br />

235

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!