01-06-2008
Quote:
Originally Posted by
Katkota
I'm going to use LDAP on Solaris 10 to authenticate users
1. when users login for the first time, Is there a way to auto create a home directory like "/home/"user_name" so we don't have to a create a home directory for every single users (we will have about 300 users that going to need access to that Solaris box.
/home is a virtual filesystem linked to the automounter. If you want to use LDAP to authenticate, I'd suggest also using NFS for their home dirs to keep everything in sync - otheriwse you'll have the situation where a new user won't have a home dir on several servers and an old, deleted user will leave their homedir behind on several servers.
If you configure automount to go to a predefined NFS server, you won't need to create accounts on any of your LDAP client servers.
Quote:
Originally Posted by
Katkota
2. If question 1 can be done, is there a way to assign group to each user as well?
This comes over as part of the LDAP info - you should use LDAP for user and groups to avoid the problems described in (1).
Quote:
Originally Posted by
Katkota
3. If question 2 can be done, Is there a way to make the group assignment based on their own group in LDAP?
In other word, let's say i have 2 groups in LDAP called "new & old", then if a user from group "old" in ldap logs in to the Solaris box he should be assigned to group "staff" and if a user from group "new" in ldap logs in, the associated group on Solaris box would be "sysadm"
No idea sorry but I would imagine it would be easier to stick with LDAP groups for users and avoid using groups from /etc/group altogether for these (non-system) users.
9 More Discussions You Might Find Interesting
1. UNIX for Advanced & Expert Users
Hi all,
First of all, i am so sorry about my bad level in English writing.
I have some problem in linux and i hope the experts of this forum to help me if they have enough time to reply to me.
I have a scenario of configuring NIS and NFS in Redhat Linux environment such that user can login... (0 Replies)
Discussion started by: pioneer
0 Replies
2. UNIX for Dummies Questions & Answers
Is there a way to set the size of the home directory for every single user in a specific group, in more details:
I have a group & i will have to add about 20 users to it to be their home directories. i want each of the home directories for this group to be limited to 50 MB
Help? (11 Replies)
Discussion started by: Katkota
11 Replies
3. Filesystems, Disks and Memory
Hi
Im working in an environment where 2 production and 2 testing unix servers are used.. All these servers share the same home directory..
how is it done
where would the home directory be located (0 Replies)
Discussion started by: raghav288
0 Replies
4. UNIX for Dummies Questions & Answers
How to find the free space & usage of the particular directory in Hp-Unix?
I want to see the usage in % (2 Replies)
Discussion started by: bobprabhu
2 Replies
5. UNIX for Dummies Questions & Answers
Folks;
I'd like to create a group on my Linux box & add a few users to it.
Is there a way to do so and restrict this group/users to have access to only one or directory trees?
Let's say i need this group to only have a read write access to only these two directories /opt/Virtu & /fsn/comers
... (10 Replies)
Discussion started by: Katkota
10 Replies
6. UNIX for Dummies Questions & Answers
folks;
I created a new users on my SUSE box and i need to give this user/group a read write access to one specific folder. here's the details:
- I created new user "funny" under group "users".
- I need to give this user "funny" a read/write access to another directory that is owned by "root".... (3 Replies)
Discussion started by: Katkota
3 Replies
7. UNIX for Dummies Questions & Answers
Hi I've just made a directory, what command do I use to now make it the base directory?
Thanks!!!!!!!!!!!!!!! (1 Reply)
Discussion started by: beckywatson
1 Replies
8. Shell Programming and Scripting
I have many views in my Linux home dir under different folders mentioned below.
Home
1. CCVIEWS
2. views
3. Development
4. testproject
:
:
etc.
Now i want to list all the clearcase views in my linux dir in below format to work on other script.
1) user_test_Work1.vws
... (4 Replies)
Discussion started by: saku
4 Replies
9. Shell Programming and Scripting
Hi, I'm new to the world of UNIX and have been asked to create a complex script (at least complex to me:confused:) for AIX UNIX to create a report of all the users on the server including server, user, UID, groups, GID, etc.
Found a script using lsuser, but the output is still lacking. 2 things I... (2 Replies)
Discussion started by: panthur
2 Replies
group(4) File Formats group(4)
NAME
group - group file
DESCRIPTION
The group file is a local source of group information. The group file can be used in conjunction with other group sources, including the
NIS maps group.byname and group.bygid, the NIS+ table group, or group information stored on an LDAP server. Programs use the getgrnam(3C)
routines to access this information.
The group file contains a one-line entry for each group recognized by the system, of the form:
groupname:password: gid:user-list
where
groupname The name of the group.
gid The group's unique numerical ID (GID) within the system.
user-list A comma-separated list of users allowed in the group.
The maximum value of the gid field is 2147483647. To maximize interoperability and compatibility, administrators are recommended to assign
groups using the range of GIDs below 60000 where possible.
If the password field is empty, no password is demanded. During user identification and authentication, the supplementary group access list
is initialized sequentially from information in this file. If a user is in more groups than the system is configured for, {NGROUPS_MAX}, a
warning will be given and subsequent group specifications will be ignored.
Malformed entries cause routines that read this file to halt, in which case group assignments specified further along are never made. To
prevent this from happening, use grpck(1B) to check the /etc/group database from time to time.
Previous releases used a group entry beginning with a `+' (plus sign) or `-' (minus sign) to selectively incorporate entries from a naming
service source (for example, an NIS map or data from an LDAP server) for group. If still required, this is supported by specifying
group:compat in nsswitch.conf(4). The compat source may not be supported in future releases. Possible sources are files followed by ldap or
nisplus. This has the effect of incorporating information from an LDAP server or the entire contents of the NIS+ group table after the
group file.
EXAMPLES
Example 1: Sample of a group File.
Here is a sample group file:
root::0:root
stooges:q.mJzTnu8icF.:10:larry,moe,curly
and the sample group entry from nsswitch.conf:
group: files ldap
With these entries, the group stooges will have members larry, moe, and curly, and all groups listed on the LDAP server are effectively
incorporated after the entry for stooges.
If the group file was:
root::0:root
stooges:q.mJzTnu8icF.:10:larry,moe,curly
+:
and the group entry from nsswitch.conf:
group: compat
all the groups listed in the NIS group.bygid and group.byname maps would be effectively incorporated after the entry for stooges.
SEE ALSO
groups(1), grpck(1B), newgrp(1), getgrnam(3C), initgroups(3C), nsswitch.conf(4), unistd.h(3HEAD)
System Administration Guide: Basic Administration
SunOS 5.10 22 Jul 2004 group(4)