09-19-2007
Password database
Quote:
Originally Posted by
cassj
What are you wanting to accomplish with this...
1. just store all kinds of passwords securely in a database for users to retrieve.
Basically yes.
This database is for use by a support group maintaining routers, switches, servers, etc. Of course all users should not have access to everything so I need to be able to limit their access to passwords based on the group they are in. From my limited database knowledge I believe this would be considered a view.
2. Or does the database need to feed to passwords to applications? That of course is more involved.
Nope, not needed.
2. Server as a central authentication point for infrastructure access? In that case, ONE option would be to look at LDAP, such as OpenLDAP
OpenLDAP
No, not trying to set up something like a PKI, that's too complicated for me.
Thanks
thumper
8 More Discussions You Might Find Interesting
1. Programming
HI i need to delete an entry in /etc/security/passwd.
can't find a way to do it with userpw.h api ( AIX ).
the passwd file i delete like this.
Write all entrys to passwd file except the one we are removing.
can't find any function that works like getspent / getpwent do
in AIX userpw api.... (4 Replies)
Discussion started by: nighter
4 Replies
2. Shell Programming and Scripting
Hi,
I need to connect to DB through my shell script. but I dont want to hardcode my db password in the script. Is there a way to do it?
Thanks
---------- Post updated at 07:42 PM ---------- Previous update was at 04:54 PM ----------
:(Guys..please help me with this:( (1 Reply)
Discussion started by: agrawal.prachi
1 Replies
3. Shell Programming and Scripting
Hi there,
This is my first post, so as you have probably guessed I am looking for some help.
Currently we have close to 1000 ksh scripts operating on HPUX servers that call either isql or bcp to connect to Sybase databases. Problem being that the db passwords are appearing in the job log... (3 Replies)
Discussion started by: kdk_irl
3 Replies
4. Solaris
I installed Oracle 10 software on Solaris 11 Express, everything was fine execpt I can't create database using dbca.rsp file. I populated file with following options.
OPERATION_TYPE = "createDatabase"
GDBNAME = "solaris_user.domain.com"
SID = "solaris_user"
TEMPLATENAME = "General... (0 Replies)
Discussion started by: solaris_user
0 Replies
5. Shell Programming and Scripting
Hi All,
I want to validate the Production Database password at the time of login through script. If incorrect password entererd by the user, the script will ask again for the password.
Below is the sample of my script...
#########################
# Unix Code Starts here #... (6 Replies)
Discussion started by: saps19
6 Replies
6. Shell Programming and Scripting
I have a reseller account with hostgator, which means i have WHM and Cpanel. I have set up a staging environment for one of my wordpress installations (client website), which is essentially sitting at staging.domain.com (live site is at domain.com). The staging website is a complete copy of the... (1 Reply)
Discussion started by: nzrobert
1 Replies
7. UNIX for Beginners Questions & Answers
Hello everybody,
I need to modify 200 files using a patern matching, I would like to do it with sed but it's not working with the following syntax:
sed -e 's/DATABASE_PASSWORD.*oldpass/DATABASE_PASSWORD__', 'newpass/g' config.php
need to find:
define("__DATABASE_PASSWORD__", ... (6 Replies)
Discussion started by: dco
6 Replies
8. Forum Support Area for Unregistered Users & Account Problems
I was unable to login and so used the "Forgotten Password' process. I was sent a NEWLY-PROVIDED password and a link through which my password could be changed. The NEWLY-PROVIDED password allowed me to login.
Following the provided link I attempted to update my password to one of my own... (1 Reply)
Discussion started by: Rich Marton
1 Replies
LEARN ABOUT MOJAVE
slapd-monitor
SLAPD-MONITOR(5) File Formats Manual SLAPD-MONITOR(5)
NAME
slapd-monitor - Monitor backend to slapd
SYNOPSIS
/etc/openldap/slapd.conf
DESCRIPTION
The monitor backend to slapd(8) is not an actual database; if enabled, it is automatically generated and dynamically maintained by slapd
with information about the running status of the daemon.
To inspect all monitor information, issue a subtree search with base cn=Monitor, requesting that attributes "+" and "*" are returned. The
monitor backend produces mostly operational attributes, and LDAP only returns operational attributes that are explicitly requested.
Requesting attribute "+" is an extension which requests all operational attributes.
CONFIGURATION
These slapd.conf options apply to the monitor backend database. That is, they must follow a "database monitor" line and come before any
subsequent "backend" or "database" lines.
As opposed to most databases, the monitor database can be instantiated only once, i.e. only one occurrence of "database monitor" can occur
in the slapd.conf(5) file. Moreover, the suffix of the database cannot be explicitly set by means of the suffix directive. The suffix is
automatically set to "cn=Monitor".
The monitor database honors the rootdn and the rootpw directives, and the usual ACL directives, e.g. the access directive.
Other database options are described in the slapd.conf(5) manual page.
USAGE
The usage is:
1) enable the monitor backend at configure:
configure --enable-monitor
2) activate the monitor database in the slapd.conf(5) file:
database monitor
3) add ACLs as detailed in slapd.access(5) to control access to the database, e.g.:
access to dn.subtree="cn=Monitor"
by dn.exact="uid=Admin,dc=my,dc=org" write
by users read
by * none
4) ensure that the core.schema file is loaded.
The monitor backend relies on some standard track attributeTypes that must be already defined when the backend is started.
ACCESS CONTROL
The monitor backend honors access control semantics as indicated in slapd.access(5), including the disclose access privilege, on all cur-
rently implemented operations.
KNOWN LIMITATIONS
The monitor backend does not honor size/time limits in search operations.
FILES
/etc/openldap/slapd.conf
default slapd configuration file
SEE ALSO
slapd.conf(5), slapd-config(5), slapd.access(5), slapd(8), ldap(3).
ACKNOWLEDGEMENTS
OpenLDAP Software is developed and maintained by The OpenLDAP Project <http://www.openldap.org/>. OpenLDAP Software is derived from Uni-
versity of Michigan LDAP 3.3 Release.
OpenLDAP 2.4.28 2011/11/24 SLAPD-MONITOR(5)