03-22-2013
Quote:
Originally Posted by
MichaelFelt
my pleasure.
p.s. I do not know the answer - exactly - but you should also look into a construction for not allowing "any" AD defined user to be able to login to "all" systems. Normally, there are only one or two systems where a login is appropriate.
I've found two ways to do this:
1. Is to define a group or OU in AD for each server, and tell the ldap client to look for user information only inside that group or OU.
2. Modify the /etc/security/user file, so the default stanza will use SYSTEM=compat (therefore no LDAP user will be able to log in), and add a stanza per LDAP user, where SYSTEM=LDAP and registry=LDAP. This way, only the users that have a custom stanza here will be able to use LDAP for login.
This User Gave Thanks to Janpol For This Post:
10 More Discussions You Might Find Interesting
1. UNIX for Advanced & Expert Users
All newly created Aix5 users are forced to change password first time when they log in. We know removing the ADMCHG flag in passwd file will not prompt the user for change password. But we are trying to figure out the similar solution if the user is created as a LDAP user ?. Any help?
Thanks... (0 Replies)
Discussion started by: vipas
0 Replies
2. UNIX for Advanced & Expert Users
hi,
is it possible to link users on a LDAP-Server from one container to another?
we have two trees, one for AIX and one for solaris-linux
but we have a few users in both trees, they should have the same password and a password change must affect both entries
we use IBM Directory Server... (3 Replies)
Discussion started by: funksen
3 Replies
3. Solaris
I am trying to let user asillitoe su to the godbrook role to execute commands. I have editted files as follows:
user_attr:
asillito::::type=normal;roles=godbrook
godbrook::::type=role;profiles=Gadbrook,All
prof_attr:
Gadbrook:::Allow root commands to be used by godbrook:
exec_attr:... (0 Replies)
Discussion started by: chrisdberry
0 Replies
4. Solaris
do i have to create a new account to add a role?
i want the sysadmin login
i have 3 users on my systems
sysadmin
secman
oc01
also 3 profiles
SA (goes t0 sysadmin account)
SSO (goes to secman account)
LMICS (goes to oc01 account)
the user accounts are located in /h/USERS/local
the... (4 Replies)
Discussion started by: deaconf19
4 Replies
5. UNIX for Dummies Questions & Answers
Can anyone help me on "How to change Unix to support RBAC policy"? (4 Replies)
Discussion started by: JPoroo
4 Replies
6. Solaris
Hi all!
On backup server with contab my script worked, but one command don't fine to be executed:
bash-3.00$ scp itadmin@172.17.0.44:/export/backups/* /bckp1/opencms/bcp_`date +%Y%m%d`/
www-zone.cfg 100%... (0 Replies)
Discussion started by: sotich82
0 Replies
7. Solaris
I have an issue with integration between Microsoft LDAP users and RBAC roles defined in a Solaris box.
to explain more , i managed to integrate Microsoft Active Directory user loggings to Solaris boxes. I've done it to centralize user repo. and instead of creating admin accounts on more than... (9 Replies)
Discussion started by: mduweik
9 Replies
8. Linux
Any way to find the ldap users currently logged into the clinets ? I am using Openldap with NFS for home directory mounts. (0 Replies)
Discussion started by: nitin09
0 Replies
9. Linux
Need to find the ldap id's of all the users in my organizations... is there any command??? (0 Replies)
Discussion started by: Syed Imran
0 Replies
10. Solaris
I have very limited knowledge on LDAP configuration and have been trying fix one issue, but unsuccessful.
The server, I am working on, is Solaris-10 zone. sudoers is configured on LDAP (its not on local server). I have access to login directly on server with root, but somehow sudo is not working... (9 Replies)
Discussion started by: solaris_1977
9 Replies
LEARN ABOUT CENTOS
lusermod
lusermod(1) General Commands Manual lusermod(1)
NAME
lusermod - Modify an user
SYNOPSIS
lusermod [OPTION]... user
DESCRIPTION
Modifies the user with name user.
OPTIONS
-c, --gecos=gecos
Set user's GECOS field to gecos. The GECOS field is traditionally used to store user's real name and other information.
-d, --directory=directory
Set user's home directory to directory.
-g, --gid=gid
Change user's primary group ID to gid. If group with ID gid does not exist, a warning is printed, but the operation is performed
anyway.
-i, --interactive
Ask all questions when connecting to the user database, even if default answers are set up in libuser configuration.
-L, --lock
Lock user's account. This prevents logging in using user's password.
-l, --login=name
Rename user to name.
-m, --movedirectory
After changing user's home directory (using the -d option), move the old home directory to the new location.
-P, --plainpassword=password
Set user's password to password. Note that the password can be viewed while running lusermod using tools such as ps(1).
-p, --password=encrypted
Set user's password to the password represented by the hash encrypted. Note that the hash can be viewed while running lusermod
using tools such as ps(1).
-s, --shell=shell
Set user's login shell to shell.
-U, --unlock
Unlock user's account.
-u, --uid=uid
Change user's user ID to uid.
--commonname=name
Set user's common name to name. This attribute is only supported in some backends (e.g.LDAP), and its support may have further lim-
itations (e.g. LDAP schema rules).
--givenname=name
Set user's given name to name. This attribute is only supported in some backends (e.g.LDAP), and its support may have further limi-
tations (e.g. LDAP schema rules).
--homephone=phone
Set user's home telephone number to phone. This attribute is only supported in some backends (e.g.LDAP), and its support may have
further limitations (e.g. LDAP schema rules).
--roomnumber=room
Set user's room number to room. This attribute is only supported in some backends (e.g.LDAP), and its support may have further lim-
itations (e.g. LDAP schema rules).
--surname=name
Set user's surname to name. This attribute is only supported in some backends (e.g.LDAP), and its support may have further limita-
tions (e.g. LDAP schema rules).
--telephonenumber=phone
Set user's telephone number to phone. This attribute is only supported in some backends (e.g.LDAP), and its support may have fur-
ther limitations (e.g. LDAP schema rules).
EXIT STATUS
The exit status is 0 on success, nonzero on error.
libuser 2009-12-11 lusermod(1)