13.07.2015 Views

Naming and Directory Services (DNS, NIS, and LDAP)

Naming and Directory Services (DNS, NIS, and LDAP)

Naming and Directory Services (DNS, NIS, and LDAP)

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

pam_ldap ChangesThe Solaris 10 OS release introduced several changes to pam_ldap, identified in thefollowing list. Also, see the pam_ldap(5) man page for more information.■■■The previously supported use_first_pass <strong>and</strong> try_first_pass options areobsolete as of the Solaris 10 software release. These options are no longer needed,may safely be removed from pam.conf, <strong>and</strong> are silently ignored. They may beremoved in a future release.Password prompting must be provided for by stacking pam_authtok_get beforepam_ldap in the authentication <strong>and</strong> password module stacks, <strong>and</strong> by includingpam_passwd_auth in the passwd service auth stack.The previously supported password update function is replaced in this release bythe previously recommended use of pam_authtok_store with theserver_policy option.An upgrade to this release will not automatically update the existing pam.conf file toreflect the above changes. If the existing pam.conf file contains a pam_ldapconfiguration, you will be notified after the upgrade via the CLEANUP file. You willneed to examine the pam.conf file <strong>and</strong> modify it, as needed.It is not possible to provide a clean automatic update for the changes listed above,primarily password prompting <strong>and</strong> password update, due to the relevance of othermodules used in the same stack <strong>and</strong> also due to the existence of third party modules.See pam_passwd_auth(5), pam_authtok_get(5), pam_authtok_store(5), <strong>and</strong>pam.conf(4) man pages for more information.<strong>LDAP</strong> Comm<strong>and</strong>sThere are two sets of <strong>LDAP</strong>-related comm<strong>and</strong>s in the Solaris system. One set is thegeneral <strong>LDAP</strong> tools, which do not require the client to be configured with <strong>LDAP</strong>naming services. The second set uses the common <strong>LDAP</strong> configuration on the client<strong>and</strong> therefore can only be used if the client is configured to use <strong>LDAP</strong> as its namingservice.198 System Administration Guide: <strong>Naming</strong> <strong>and</strong> <strong>Directory</strong> <strong>Services</strong> (<strong>DNS</strong>, <strong>NIS</strong>, <strong>and</strong> <strong>LDAP</strong>) • January 2005

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!