13.07.2015 Views

Naming and Directory Services (DNS, NIS, and LDAP)

Naming and Directory Services (DNS, NIS, and LDAP)

Naming and Directory Services (DNS, NIS, and LDAP)

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

In addition, if audit_user, auth_attr, exec_attr <strong>and</strong> prof_attr aretobetaken from a directory other than the default, you must amend the RBACDIR=/etc/security to RBACDIR=/your-choice.Passwd Files <strong>and</strong> Namespace SecurityThe passwd map is a special case. In addition to the old Solaris 1 passwd file format,this implementation of <strong>NIS</strong> accepts the /etc/passwd <strong>and</strong> /etc/shadow file formatsas input for building the <strong>NIS</strong> password maps.For security reasons, the files used to build the <strong>NIS</strong> password maps should not containan entry for root, to prevent unauthorized root access. Therefore, the password mapsshould not be built from the files located in the master server’s /etc directory. Thepassword files used to build the password maps should have the root entry removedfrom them <strong>and</strong> be located in a directory that can be protected from unauthorizedaccess.For example, the master server password input files should be stored in a directorysuch as /var/yp, or any directory of your choice, as long as the file itself is not a linkto another file <strong>and</strong> its location is specified in the Makefile. The correct directoryoption is set automatically according to the configuration specified in your Makefile.Caution – Be sure that the passwd file in the directory specified by PWDDIR does notcontain an entry for root.If your source files are in a directory other than /etc, you must alter the PWDIRpassword macro in the Makefile to refer to the directory where the passwd <strong>and</strong>shadow files reside, changing the line PWDIR=/etc to PWDIR/your-choice, whereyour-choice is the name of the directory you will be using to store the passwd mapsource files.Preparing Source Files for Conversion to <strong>NIS</strong> MapsPrepare the source files for conversion to <strong>NIS</strong> maps.▼How to Prepare Source Files for Conversion1. Become superuser or assume an equivalent role.Roles contain authorizations <strong>and</strong> privileged comm<strong>and</strong>s. For more informationabout roles, see “Using Role-Based Access Control (Tasks)” in System AdministrationGuide: Security <strong>Services</strong>.Chapter 5 • Setting Up <strong>and</strong> Configuring <strong>NIS</strong> Service 83

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!