Sponsored Content
Full Discussion: RBAC and LDAP users (AD)
Operating Systems AIX RBAC and LDAP users (AD) Post 302784483 by MichaelFelt on Friday 22nd of March 2013 10:54:48 AM
Old 03-22-2013
my pleasure.

If you have a chance to attend the TechU in Amsterdam or Athens this year I'll be doing a presentation/labs on RBAC and LDAP (installing ITDS from try and buy images). As I have time I am looking at compiling openldap for AIX and doing the same.

p.s. I expected that AD admins would not be "excited" about a schema change. "All" customers I have worked with have said no - in the end. AD support seems to end once a none-AD schema is installed. No support == No install.

Sorry I cannot provide an easier answer.

p.s. I do not know the answer - exactly - but you should also look into a construction for not allowing "any" AD defined user to be able to login to "all" systems. Normally, there are only one or two systems where a login is appropriate.
 

10 More Discussions You Might Find Interesting

1. UNIX for Advanced & Expert Users

Equivalent of ADMCHG for LDAP Users

All newly created Aix5 users are forced to change password first time when they log in. We know removing the ADMCHG flag in passwd file will not prompt the user for change password. But we are trying to figure out the similar solution if the user is created as a LDAP user ?. Any help? Thanks... (0 Replies)
Discussion started by: vipas
0 Replies

2. UNIX for Advanced & Expert Users

link LDAP-Users

hi, is it possible to link users on a LDAP-Server from one container to another? we have two trees, one for AIX and one for solaris-linux but we have a few users in both trees, they should have the same password and a password change must affect both entries we use IBM Directory Server... (3 Replies)
Discussion started by: funksen
3 Replies

3. Solaris

Rbac

I am trying to let user asillitoe su to the godbrook role to execute commands. I have editted files as follows: user_attr: asillito::::type=normal;roles=godbrook godbrook::::type=role;profiles=Gadbrook,All prof_attr: Gadbrook:::Allow root commands to be used by godbrook: exec_attr:... (0 Replies)
Discussion started by: chrisdberry
0 Replies

4. Solaris

RBAC Help

do i have to create a new account to add a role? i want the sysadmin login i have 3 users on my systems sysadmin secman oc01 also 3 profiles SA (goes t0 sysadmin account) SSO (goes to secman account) LMICS (goes to oc01 account) the user accounts are located in /h/USERS/local the... (4 Replies)
Discussion started by: deaconf19
4 Replies

5. UNIX for Dummies Questions & Answers

Unix Rbac

Can anyone help me on "How to change Unix to support RBAC policy"? (4 Replies)
Discussion started by: JPoroo
4 Replies

6. Solaris

rbac problem.

Hi all! On backup server with contab my script worked, but one command don't fine to be executed: bash-3.00$ scp itadmin@172.17.0.44:/export/backups/* /bckp1/opencms/bcp_`date +%Y%m%d`/ www-zone.cfg 100%... (0 Replies)
Discussion started by: sotich82
0 Replies

7. Solaris

LDAP users with RBAC Roles

I have an issue with integration between Microsoft LDAP users and RBAC roles defined in a Solaris box. to explain more , i managed to integrate Microsoft Active Directory user loggings to Solaris boxes. I've done it to centralize user repo. and instead of creating admin accounts on more than... (9 Replies)
Discussion started by: mduweik
9 Replies

8. Linux

Monitor ldap users

Any way to find the ldap users currently logged into the clinets ? I am using Openldap with NFS for home directory mounts. (0 Replies)
Discussion started by: nitin09
0 Replies

9. Linux

Help me with all users ldap

Need to find the ldap id's of all the users in my organizations... is there any command??? (0 Replies)
Discussion started by: Syed Imran
0 Replies

10. Solaris

LDAP Client not connecting to LDAP server

I have very limited knowledge on LDAP configuration and have been trying fix one issue, but unsuccessful. The server, I am working on, is Solaris-10 zone. sudoers is configured on LDAP (its not on local server). I have access to login directly on server with root, but somehow sudo is not working... (9 Replies)
Discussion started by: solaris_1977
9 Replies
claccess(1CL)						 Sun Cluster Maintenance Commands					     claccess(1CL)

NAME
claccess - manage Sun Cluster access policies for nodes SYNOPSIS
/usr/cluster/bin/claccess -V /usr/cluster/bin/claccess [subcommand] -? /usr/cluster/bin/claccess subcommand [options] -v [hostname[,...]] /usr/cluster/bin/claccess allow -h hostname[,...] /usr/cluster/bin/claccess allow-all /usr/cluster/bin/claccess deny -h hostname[,...] /usr/cluster/bin/claccess deny-all /usr/cluster/bin/claccess list /usr/cluster/bin/claccess set -p protocol=authprotocol /usr/cluster/bin/claccess show DESCRIPTION
The claccess command controls the network access policies for machines that attempt to access the cluster configuration. The claccess com- mand has no short form. The cluster maintains a list of machines that can access the cluster configuration. The cluster also stores the name of the authentication protocol that is used for these nodes to access the cluster configuration. When a machine attempts to access the cluster configuration, for example when it asks to be added to the cluster configuration (see cln- ode(1CL)), the cluster checks this list to determine whether the node has access permission. If the node has permission, the node is authenticated and allowed access to the cluster configuration. You can use the claccess command for the following tasks: o To allow any new machines to add themselves to the cluster configuration and remove themselves from the cluster configuration o To prevent any nodes from adding themselves to the cluster configuration and removing themselves from the cluster configuration o To control the authentication type to check You can use this command only in the global zone. The general form of the claccess command is as follows: claccess [subcommand] [options] You can omit subcommand only if options specifies the -? option or the -V option. Each option of this command has a long form and a short form. Both forms of each option are provided with the description of the option in the "OPTIONS" section of this man page. SUBCOMMANDS
The following subcommands are supported: allow Allows the specified machine or machines to access the cluster configuration. Users other than superuser require solaris.cluster.modify role-based access control (RBAC) authorization to use this subcommand. See rbac(5). See also the description of the deny and the allow-all subcommands. allow-all Allows all machines to add themselves to access the cluster configuration. Users other than superuser require solaris.cluster.modify RBAC authorization to use this subcommand. See rbac(5). See also the description of the deny-all and the allow subcommands. deny Prevents the specified machine or machines from accessing the cluster configuration. Users other than superuser require solaris.cluster.modify RBAC authorization to use this subcommand. See rbac(5). See also the description of the allow and the deny-all subcommands. deny-all Prevents all machines from accessing the cluster configuration. No access for any node is the default setting after the cluster is configured the first time. Users other than superuser require solaris.cluster.modify RBAC authorization to use this subcommand. See rbac(5). See also the description of the allow-all and the deny subcommands. list Displays the names of the machines that have authorization to access the cluster configuration. To see the authentication protocol as well, use the show subcommand. Users other than superuser require solaris.cluster.read RBAC authorization to use this subcommand. See rbac(5). set Sets the authentication protocol to the value that you specify with the -p option. By default, the system uses sys as the authentica- tion protocol. See the -p option in "OPTIONS". Users other than superuser require solaris.cluster.modify RBAC authorization to use this subcommand. See rbac(5). show Displays the names of the machines that have permission to access the cluster configuration. Also displays the authentication protocol. Users other than superuser require solaris.cluster.read RBAC authorization to use this subcommand. See rbac(5). OPTIONS
The following options are supported: -? --help Displays help information. When you use this option, no other processing is performed. You can specify this option without a subcommand or with a subcommand. If you specify this option without a subcommand, the list of subcommands of this command is displayed. If you specify this option with a subcommand, the usage options for the subcommand are dis- played. -h hostname --host=hostname --host hostname Specifies the name of the node being granted or denied access. -p protocol=authprotocol --authprotocol=authentication_protocol --authprotocol authentication_protocol Specifies the authentication protocol that is used to check whether a machine has access to the cluster configuration. Supported protocols are des and sys (or unix). The default authentication type is sys, which provides the least amount of secure authentication. For more information on adding and removing nodes, see Adding a Cluster Node in Sun Cluster System Administration Guide for Solaris OS. For more information on these authentication types, see Chapter 16, Using Authentication Services (Tasks), in System Administration Guide: Security Services. -V --version Displays the version of the command. Do not specify this option with subcommands, operands, or other options. The subcommands, operands, or other options are ignored. The -V option displays only the version of the command. No other processing is performed. -v --verbose Displays verbose information to standard output (stdout). EXIT STATUS
If the command is successful for all specified operands, it returns zero (CL_NOERR). If an error occurs for an operand, the command pro- cesses the next operand in the operand list. The returned exit code always reflects the error that occurred first. The following exit codes can be returned: 0 CL_NOERR No error The command that you issued completed successfully. 1 CL_ENOMEM Not enough swap space A cluster node ran out of swap memory or ran out of other operating system resources. 3 CL_EINVAL Invalid argument You typed the command incorrectly, or the syntax of the cluster configuration information that you supplied with the -i option was incorrect. 6 CL_EACCESS Permission denied The object that you specified is inaccessible. You might need superuser or RBAC access to issue the command. See the su(1M) and rbac(5) man pages for more information. 18 CL_EINTERNAL Internal error was encountered An internal error indicates a software defect or other defect. 39 CL_EEXIST Object exists The device, device group, cluster interconnect component, node, cluster, resource, resource type, or resource group that you specified already exists. EXAMPLES
Example 1 Allow a New Host Access The following claccess command allows a new host to access the cluster configuration. # claccess allow -h phys-schost-1 Example 2 Set the Authentication Type The following claccess command sets the current authentication type to des. # claccess set -p protocol=des Example 3 Deny Access to All Hosts The following claccess command denies all hosts access to the cluster configuration. # claccess deny-all ATTRIBUTES
See attributes(5) for descriptions of the following attributes: +-----------------------------+-----------------------------+ | ATTRIBUTE TYPE | ATTRIBUTE VALUE | +-----------------------------+-----------------------------+ |Availability |SUNWsczu | +-----------------------------+-----------------------------+ |Interface Stability |Evolving | +-----------------------------+-----------------------------+ SEE ALSO
Intro(1CL), clnode(1CL), cluster(1CL) NOTES
The superuser user can run all forms of this command. Any user can run this command with the following subcommands and options: o -? option o -V option To run this command with other subcommands, users other than superuser require RBAC authorizations. See the following table. +-----------+---------------------------------------------------------+ |Subcommand | RBAC Authorization | +-----------+---------------------------------------------------------+ |allow | solaris.cluster.modify | +-----------+---------------------------------------------------------+ |allow-all | solaris.cluster.modify | +-----------+---------------------------------------------------------+ |deny | solaris.cluster.modify | +-----------+---------------------------------------------------------+ |deny-all | solaris.cluster.modify | +-----------+---------------------------------------------------------+ |list | solaris.cluster.read | +-----------+---------------------------------------------------------+ |set | solaris.cluster.modify | +-----------+---------------------------------------------------------+ |show | solaris.cluster.read | +-----------+---------------------------------------------------------+ Sun Cluster 3.2 22 Jul 2005 claccess(1CL)
All times are GMT -4. The time now is 08:31 AM.
Unix & Linux Forums Content Copyright 1993-2022. All Rights Reserved.
Privacy Policy