12.07.2015 Views

Red Hat Enterprise Linux 5 Administration Unleashed

Red Hat Enterprise Linux 5 Administration Unleashed

Red Hat Enterprise Linux 5 Administration Unleashed

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Enabling NIS 257. optional: Results of the module is ignored.. include: Include lines from the given configuration file in the same /etc/pam.d/directory such as include system-auth.The can also be in the following form:[value1=action1 value2=action2 ... ]12The value should be the return code from the function called in the module. Refer to thepam.conf man page by executing the man pam.conf command for details.Enabling NISNIS, or Network Information Systems, is a network service that allows authentication andlogin information to be stored on a centrally located server. This includes the usernameand password database for login authentication, database of user groups, and the locationsof home directories.To allow users to log in to any system on the network seamlessly, NIS and NFS can beused together. The NIS server provides the network service for logging in to the system,and NFS can be used to export user home directories from a central server. If usedtogether, users can access any system with the same username and password, systemgroups remain the same across the network, and users’ home directories are exactly thesame regardless of which system they log in to. If using SE<strong>Linux</strong>, the use_nfs_home_dirsboolean SE<strong>Linux</strong> boolean must be set to 1 on each NFS client mounting the home directories.Refer to Chapter 13, “Network File Sharing” for details.NIS and SE<strong>Linux</strong>In <strong>Red</strong> <strong>Hat</strong> <strong>Enterprise</strong> <strong>Linux</strong> 5, NIS is protected by the default Security-Enhanced <strong>Linux</strong>(SE<strong>Linux</strong>) policy, known as the targeted policy. Refer to Chapter 23 for more informationon SE<strong>Linux</strong>.By default, this targeted policy does not allow NIS connections. To use NIS, you must setthe allow_ypbind SE<strong>Linux</strong> boolean to 1 with the following command:setsebool -P allow_ypbind 1To verify that the setting has been changed, execute the following:getsebool allow_ypbindIf enabled, the output should be the following:allow_ypbind --> onOther SE<strong>Linux</strong> booleans for NIS include the following (they are set to 0 by default) :. yppasswdd_disable_trans: Disable SE<strong>Linux</strong> protection for yppasswd if set to 1.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!