13.07.2015 Views

Naming and Directory Services (DNS, NIS, and LDAP)

Naming and Directory Services (DNS, NIS, and LDAP)

Naming and Directory Services (DNS, NIS, and LDAP)

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

■The files used to build the <strong>NIS</strong> password maps should not contain an entry forroot to protect against unauthorized access. To accomplish this, the password filesused to build the password maps should have the root entry removed from them<strong>and</strong> be located in a directory other than the master server’s /etc directory. Thisdirectory should be secured against unauthorized access.For example, the master server password input files could be stored in a directorysuch as /var/yp, or any directory of your choice, as long as the file itself is not a linkto another file <strong>and</strong> is specified in the Makefile. When you use either the ServiceManagement Facility or the ypstart script to start the <strong>NIS</strong> service, the correctdirectory option is set according to the configuration specified in your Makefile.Note – In addition to the older Solaris 1 version passwd file format, thisimplementation of <strong>NIS</strong> accepts the Solaris 2 passwd <strong>and</strong> shadow file formats as inputfor building the <strong>NIS</strong> password maps.Administering <strong>NIS</strong> UsersThis section includes information about setting user passwords, adding new users toan <strong>NIS</strong> domain, <strong>and</strong> assigning users to netgroups.▼How to Add a New <strong>NIS</strong> User to an <strong>NIS</strong> Domain1. On the master <strong>NIS</strong> server, become superuser or assume an equivalent role.Roles contain authorizations <strong>and</strong> privileged comm<strong>and</strong>s. For more informationabout roles, see “Using Role-Based Access Control (Tasks)” in System AdministrationGuide: Security <strong>Services</strong>.2. Create the new user’s login ID with the useradd comm<strong>and</strong>.# useradd userIDuserID is the login ID of the new user. This comm<strong>and</strong> creates entries in the/etc/passwd <strong>and</strong> /etc/shadow files on the master <strong>NIS</strong> server.3. Create the new user’s initial password.To create an initial password that the new user can use to log in, run the passwdcomm<strong>and</strong>.# passwd userIDWhere userID is the login ID of the new user. You will be prompted for thepassword to assign to this user.94 System Administration Guide: <strong>Naming</strong> <strong>and</strong> <strong>Directory</strong> <strong>Services</strong> (<strong>DNS</strong>, <strong>NIS</strong>, <strong>and</strong> <strong>LDAP</strong>) • January 2005

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!