12.07.2015 Views

Red Hat Enterprise Linux 5 Administration Unleashed

Red Hat Enterprise Linux 5 Administration Unleashed

Red Hat Enterprise Linux 5 Administration Unleashed

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

262CHAPTER 12Identity ManagementChange the NIS server for the slave server to itself in the /etc/yp.conf file. If a differentNIS server is already configured, comment it out by added a # character in front of theline, or delete the line. The following line in /etc/yp.conf configures the slave server asits own NIS server:ypserver 127.0.0.1On the slave server, the ypserv service must be started before the ypbind service. As root,execute the following sequence of commands:service ypbind stop; service ypserv start; service ypbind startVerify that the slave server is now using itself as the NIS server by executing the ypwhichcommand. It should return the hostname of the slave server.Updating NIS Maps from MasterTo update the NIS maps on a slave server from the master server, the ypxfrd service mustbe running on the master server as previously mentioned. This daemon listens for clientrequests. On each slave server, the ypxfr command must be run as root for each map fileto be updated (on a 64-bit system, the lib directory will be lib64 instead):/usr/lib/yp/ypxfr To verify that the map was updated, execute the ypcat command and look forthe newly added data. As previously mentioned, a list of maps can be retrieved with theypwhich -m command.Instead of executing the ypxfr command manually every time a map file is changed, youcan configure a cron task to execute it periodically for each map file. The interval atwhich it is executed depends on how often you update the map files on the master server.Because the xpxfr command must be executed for each map file, all the map files do nothave to be updated at the same time. Refer to Chapter 11 for details on setting up a crontask.CAUTIONRemember, if shared data is modified on the server, the make command must be runin the /var/yp/ directory on the server to update the master NIS maps before theupdated map files can be transferred to the clients.Restricting Access to NIS ServerBy default, anyone with access to the network on which the NIS server is running canquery the server and query for data in the NIS maps. To restrict connections to specificclients, create a /var/yp/securenets file. Lines beginning with # are comments. The fileshould contain the following line to allow the local host to connect:host 127.0.0.1

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!