13.07.2015 Views

Naming and Directory Services (DNS, NIS, and LDAP)

Naming and Directory Services (DNS, NIS, and LDAP)

Naming and Directory Services (DNS, NIS, and LDAP)

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Configuring the <strong>Directory</strong> Server toEnable Account ManagementIn order for pam_ldap to work properly, the password <strong>and</strong> account lockout policymust be properly configured on the server. You can use the <strong>Directory</strong> Server Consoleor ldapmodify to configure the account management policy for the <strong>LDAP</strong> directory.For procedures <strong>and</strong> more information, see the “User Account Management” chapter inthe Administration Guide for the version of Sun Java System <strong>Directory</strong> Server that youare using.Note – After you enable pam_ldap account management, all users must provide apassword any time they log in to the system. A login password is required forauthentication. Therefore, nonpassword-based logins using tools such as rsh,rlogin, orssh will fail.Passwords for proxy users should never be allowed to expire. If proxy passwordsexpire, clients using the proxy credential level cannot retrieve naming serviceinformation from the server. To ensure that proxy users have passwords that do notexpire, modify the proxy accounts with the following script.# ldapmodify -h ldapserver -D administrator DN \-w administrator password

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!