10 More Discussions You Might Find Interesting
1. Shell Programming and Scripting
I have this situation
/u03/app/banjobs> ls -ltr icg*
82 Jun 12 10:37 iicgorldi_2419186.log
56810484 Jun 17 10:35 icgorldi_2421592.xml
2859 Jun 17 10:35 icgorldi_2421592.lis
- 125 Jun 17 10:35 icgorldi_2421592.log
82 Jun 12 10:37 iicgorldi_2419187.log
... (8 Replies)
Discussion started by: Bernardo Jarami
8 Replies
2. Shell Programming and Scripting
Hi All,
I'm trying to find a file which is created on current day.... I searched in unix.com and i found, below command.
find /land/ -mtime -1 -type f -print | grep "FF_Member_STG.dat"
The command checks if the file with name "FF_Member_STG.dat" is created today then exit else proceed.
... (3 Replies)
Discussion started by: ace_friends22
3 Replies
3. HP-UX
Hi All
Any one please suggest me...
I have one directory every monday one file will be created in that directory. so if the file is created on monday or not i need check first.
How can write a script??? if the file is not created i want to quit from script.
Thanks
K.Srinivas (5 Replies)
Discussion started by: k_s_rao7
5 Replies
4. Shell Programming and Scripting
Hi,
I have used expdp for datapump. The .dmp file is created by the "oracle" user.
my requirement is to make a zipped file of this .dmp file.
What i am trying to do is change the permissions of this .dmp file from 0640 to 0644 and then do a gzip and zip it. Is there any way i can change... (3 Replies)
Discussion started by: qwertyu
3 Replies
5. UNIX for Dummies Questions & Answers
Hi All
I use solaris 9 and just realised my opt volume has grown to 99%. How can I find out which file was created on the opt volume for it to have grown to 99%? Which command should I use since I can't go through each individual file to look at the date the files were created.
Regard (3 Replies)
Discussion started by: rahmantanko
3 Replies
6. Shell Programming and Scripting
Hi All,
We are copying all the files into ARCHIVE directory after we process them. We are doing this process from last 2 years, now we have a lot of files in ARCHIVE directory.
Now I need to find when the first file is copied into this directory?
If I Issue,
ls -l /ARCHIVE/*.* | tail -1... (3 Replies)
Discussion started by: Raamc
3 Replies
7. Shell Programming and Scripting
When I try to remove the file which was created by another user through super user, I am getting the "override protection 644 " meesage.
Could you please anyone help me how will I delete the file without prmpting the override protection.
I have also given the permission (rwx) to the group as... (3 Replies)
Discussion started by: kandi.reddy
3 Replies
8. UNIX for Dummies Questions & Answers
Is there a command or shell script which can be used for Finding all files created by a specified userid in a directory and its subdirectories.
Say, I want to find all such files in directory /abc as well as in all the subdirectories such as /abc/xyz or /abc/xyz/pqr aqnd so on which was created... (5 Replies)
Discussion started by: abhilashnair
5 Replies
9. Shell Programming and Scripting
I need to write a script which has to list all the files which are created before six months from now.
kindly help on this ... (7 Replies)
Discussion started by: amirthraj_12
7 Replies
10. Shell Programming and Scripting
I want to get the file which created the error when the find command was run ?
I am wrote a script to mail a list of files whose file size is ge than 0 and returns 0
but wen it finds a folder with only empty files it exits as 1. i need to modify it so that the return for this is also 0 (but it... (1 Reply)
Discussion started by: guhas
1 Replies
SSSD-SUDO(5) File Formats and Conventions SSSD-SUDO(5)
NAME
sssd-sudo - Configuring sudo with the SSSD back end
DESCRIPTION
This manual page describes how to configure sudo(8) to work with sssd(8) and how SSSD caches sudo rules.
CONFIGURING SUDO TO COOPERATE WITH SSSD
To enable SSSD as a source for sudo rules, add sss to the sudoers entry in nsswitch.conf(5).
For example, to configure sudo to first lookup rules in the standard sudoers(5) file (which should contain rules that apply to local users)
and then in SSSD, the nsswitch.conf file should contain the following line:
sudoers: files sss
More information about configuring the sudoers search order from the nsswitch.conf file as well as information about the LDAP schema that
is used to store sudo rules in the directory can be found in sudoers.ldap(5).
Note: in order to use netgroups or IPA hostgroups in sudo rules, you also need to correctly set nisdomainname(1) to your NIS domain name
(which equals to IPA domain name when using hostgroups).
CONFIGURING SSSD TO FETCH SUDO RULES
All configuration that is needed on SSSD side is to extend the list of services with "sudo" in [sssd] section of sssd.conf(5). To speed up
the LDAP lookups, you can also set search base for sudo rules using ldap_sudo_search_base option.
The following example shows how to configure SSSD to download sudo rules from an LDAP server.
[sssd]
config_file_version = 2
services = nss, pam, sudo
domains = EXAMPLE
[domain/EXAMPLE]
id_provider = ldap
sudo_provider = ldap
ldap_uri = ldap://example.com
ldap_sudo_search_base = ou=sudoers,dc=example,dc=com
When the SSSD is configured to use IPA as the ID provider, the sudo provider is automatically enabled. The sudo search base is configured
to use the compat tree (ou=sudoers,$DC).
THE SUDO RULE CACHING MECHANISM
The biggest challenge, when developing sudo support in SSSD, was to ensure that running sudo with SSSD as the data source provides the same
user experience and is as fast as sudo but keeps providing the most current set of rules as possible. To satisfy these requirements, SSSD
uses three kinds of updates. They are referred to as full refresh, smart refresh and rules refresh.
The smart refresh periodically downloads rules that are new or were modified after the last update. Its primary goal is to keep the
database growing by fetching only small increments that do not generate large amounts of network traffic.
The full refresh simply deletes all sudo rules stored in the cache and replaces them with all rules that are stored on the server. This is
used to keep the cache consistent by removing every rule which was deleted from the server. However, full refresh may produce a lot of
traffic and thus it should be run only occasionally depending on the size and stability of the sudo rules.
The rules refresh ensures that we do not grant the user more permission than defined. It is triggered each time the user runs sudo. Rules
refresh will find all rules that apply to this user, check their expiration time and redownload them if expired. In the case that any of
these rules are missing on the server, the SSSD will do an out of band full refresh because more rules (that apply to other users) may have
been deleted.
If enabled, SSSD will store only rules that can be applied to this machine. This means rules that contain one of the following values in
sudoHost attribute:
o keyword ALL
o wildcard
o netgroup (in the form "+netgroup")
o hostname or fully qualified domain name of this machine
o one of the IP addresses of this machine
o one of the IP addresses of the network (in the form "address/mask")
There are many configuration options that can be used to adjust the behavior. Please refer to "ldap_sudo_*" in sssd-ldap(5) and "sudo_*" in
sssd.conf(5).
SEE ALSO
sssd(8), sssd.conf(5), sssd-ldap(5), sssd-krb5(5), sssd-simple(5), sssd-ipa(5), sssd-ad(5), sssd-sudo(5),sss_cache(8), sss_debuglevel(8),
sss_groupadd(8), sss_groupdel(8), sss_groupshow(8), sss_groupmod(8), sss_useradd(8), sss_userdel(8), sss_usermod(8), sss_obfuscate(8),
sss_seed(8), sssd_krb5_locator_plugin(8), sss_ssh_authorizedkeys(8), sss_ssh_knownhostsproxy(8),pam_sss(8).
AUTHORS
The SSSD upstream - http://fedorahosted.org/sssd
SSSD
06/17/2014 SSSD-SUDO(5)