13.07.2015 Views

Naming and Directory Services (DNS, NIS, and LDAP)

Naming and Directory Services (DNS, NIS, and LDAP)

Naming and Directory Services (DNS, NIS, and LDAP)

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Note – The preceding account management features only work with the Sun JavaSystem <strong>Directory</strong> Server. For information about configuring the password <strong>and</strong> accountlockout policy on the server, see the “User Account Management” chapter in theAdministration Guide for the version of Sun Java System <strong>Directory</strong> Server that you areusing. Also see “Example pam_conf file for pam_ldap Configured for AccountManagement” on page 201. Do not enable account management for proxy accounts.Before configuring the password <strong>and</strong> account lockout policy on Sun Java System<strong>Directory</strong> Server, make sure all hosts use the “newest” <strong>LDAP</strong> client with pam_ldapaccount management.In addition, make sure the clients have a properly configured pam.conf(4) file.Otherwise, <strong>LDAP</strong> naming services will not work when proxy or user passwordsexpire.Note – After you enable pam_ldap account management, all users must provide apassword any time they log in to the system. A login password is required forauthentication. Therefore, nonpassword-based logins using tools such as rsh,rlogin, orssh will fail.Chapter 9 • <strong>LDAP</strong> Basic Components <strong>and</strong> Concepts (Overview) 151

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!