14.02.2014 Views

ldapv3.pdf 7947KB Apr 17 2013 11:30:42 AM - mirror omadata

ldapv3.pdf 7947KB Apr 17 2013 11:30:42 AM - mirror omadata

ldapv3.pdf 7947KB Apr 17 2013 11:30:42 AM - mirror omadata

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Authentication via NSS LDAP<br />

/etc/security/user -<br />

default:<br />

admin = false<br />

login = true<br />

su = true<br />

daemon = true<br />

rlogin = true<br />

sugroups = ALL<br />

admgroups =<br />

ttys = ALL<br />

auth1 = SYSTEM<br />

auth2 = NONE<br />

tpath = nosak<br />

umask = 022<br />

expires = 0<br />

SYSTEM = "LDAP or compat"<br />

registry = LDAP<br />

logintimes =<br />

pwdwarntime = 0<br />

account_locked = false<br />

. . . .<br />

on AIX<br />

Change the default<br />

stanza modifying the<br />

SYSTEM value and<br />

adding the registry<br />

entry.<br />

root:<br />

admin = true<br />

SYSTEM = "compat"<br />

loginretries = 0<br />

account_locked = false<br />

registry = files<br />

The root stanza should<br />

look like the above, so<br />

you do not depend upon<br />

the LDAP service for<br />

authentication as root.<br />

drill:/ $ grep adam /etc/passwd<br />

drill:/ $ id adam<br />

uid=437(adam) gid=2<strong>30</strong>(cis)<br />

groups=2074(webdev),2098(cvsuser),2023(notesgroup),4<br />

(adm),7(security),14(uucp),19(floppy),21(shutdown),100(<br />

usr),200(informix),201(actng),203(cparts),207(class),209(<br />

gnv),234(mi),240(used),241(warranty),2<strong>42</strong>(wyc),253(mai<br />

lmgmt),259(console),260(partsqc),1077(intracal),1001(int<br />

ernet),1007(printadmin),1008(poweruser)

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!