12.07.2015 Views

Red Hat Enterprise Linux 5 Administration Unleashed

Red Hat Enterprise Linux 5 Administration Unleashed

Red Hat Enterprise Linux 5 Administration Unleashed

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Enabling with Authentication Tool 289Lastly, the Options tab allows an administrator to customize identity management for thesystem. The following options are available:. Cache User Information: Enable the name caching daemon (nscd) and configure itto start at boot time. When enabled, this daemon can be configured to cache informationabout /etc/passwd, /etc/group, and hostname resolution. If this option isselected, all three are cached. The /etc/nscd.conf file can be modified by root tocustomize the caching such as the time-to-live values and which of the three tocache.12CAUTIONThe Winbind authentication method and nscd will not work together properly. If theyare both running at the same time, the system will not be able to resolve domainusers and groups.. Use Shadow Passwords: Enabled by default during installation using the shadowutilspackage. If enabled, instead of encrypted passwords being stored in the/etc/passwd file, which is readable by everyone, they are located in the /etc/shadow file, which is readable by the root user only.. Use MD5 Passwords: Enabled by default. If enabled, passwords can be 256 charactersinstead of just 8 characters. This enhances security on the system because it isharder to guess longer passwords.. Local authorization is sufficient for local users: Allow local users to be authenticatedwith local files instead of with the network authentication service.. Authenticate system accounts by network services: Authenticate system accounts(user accounts under UID 500) with the enabled network authentication serviceinstead of local files.Using the Command-Line VersionAs previously mentioned, the command-line version of the Authentication Configurationtool allows you to configure the same settings as the graphical interface. Command-lineoptions are used so that the commands are non-interactive, making it possible to use inan automated script or a kickstart file.Table 12.3 contains the available command-line options. These options can also be foundin the authconfig man page or by executing the authconfig --help command. They areinvoked by executing the authconfig command as root followed by one or more options:authconfig --updateIf the --update option is not listed, the settings are not updated. If --test is used instead,the settings are not updated, but the listed changes are displayed in a summary report.The --test option can also be used without any other options to display the current

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!