03-14-2016
I managed to get this going including HMC to AD (fully) without any local intervention required, however what remains now is how to get HBAC in. I have HBAC on users and SUDO in AD but that works allright in Linux, though it's far from production ready. I was looking for something specific for AIX to AD from IBM. No luck, even when asking our IBM representatives, they were not even aware that you can have HMC to AD fully integrated without having to create local accounts. So I think I scraped the barrel of that pot quite well.
I mean to get to this in time but Cloud stuff has my head spinning at the moment.
Cheers,
Tom
7 More Discussions You Might Find Interesting
1. HP-UX
I am getting the following error message when trying to login to the client:
while verifying tgt
If I move the /etc/krb5.keytab out of /etc, it works fine. This is HP-UX v23
Does anyone have any ideas? (1 Reply)
Discussion started by: dhernand
1 Replies
2. AIX
Good day
I am trying to configure Kerberos and LDAP authentication on AIX 5.3 with Windows 2003 R2 but something is not quite right.
When I ran kinit username I get a ticket and I can display it using klist.
When the user login I can see the ticket request on Windows 2003, but the user... (1 Reply)
Discussion started by: mariusb
1 Replies
3. UNIX for Advanced & Expert Users
Hello, I asked this question in the AIX subforum but never received an answer, probably because the AIX forum is not that heavily trafficked. Anyway, here it is..
I have never had any issues like this when compiling applications from source. When I try to compile samba-3.5.0pre2, configure runs... (9 Replies)
Discussion started by: raidzero
9 Replies
4. Solaris
hi,
how to assign group policy to user in solaris (1 Reply)
Discussion started by: meet2muneer
1 Replies
5. Windows & DOS: Issues & Discussions
hi,
did anyone know how to configure a priority of dns ports (and other ports) on QOS on windows 2003? hard to understand the group policy "explain" tab on 'qos packet scheduler', no elaboration on how to use it.
thanks for any comment you may add.
---------- Post updated at 05:03 PM... (0 Replies)
Discussion started by: itik
0 Replies
6. Solaris
Hi, FYI, I'm new in Solaris
I'm trying to use Kerberos on authenticating LDAP Client with the Active Directory on Windows Server 2003 on both Solaris 10 5/08 and Solaris 10 9/10 by referring to the pdf file kerberos_s10.pdf available at sun official site.
... (0 Replies)
Discussion started by: chongzh
0 Replies
7. AIX
The KRB5ALDAP compound load module is giving me fits. Everything looks like it should be working, but no.
Goal: Integrate AIX host with Active Directory using a KRB5ALDAP compound load module so that users can be created in AD and used in AIX, with unix attributes (registry values) being... (2 Replies)
Discussion started by: jgeiger
2 Replies
LEARN ABOUT X11R4
fs_getcellstatus
FS_GETCELLSTATUS(1) AFS Command Reference FS_GETCELLSTATUS(1)
NAME
fs_getcellstatus - Reports whether setuid programs are honored in a cell
SYNOPSIS
fs getcellstatus -cell <cell name>+ [-help]
fs getce -c <cell name>+ [-h]
DESCRIPTION
The fs getcellstatus command reports whether the Cache Manager allows programs fetched from each specified cell to run with setuid
permission. To set a cell's setuid status, use the fs setcell command; fs_setcell(1) fully describes how AFS treats setuid programs.
OPTIONS
-cell <cell name>+
Names each cell for which to report setuid status. Provide the fully qualified domain name, or a shortened form that disambiguates it
from the other cells listed in the local /etc/openafs/CellServDB file.
-help
Prints the online help for this command. All other valid options are ignored.
OUTPUT
The output reports one of the following two values as appropriate:
Cell <cell> status: setuid allowed
Cell <cell> status: no setuid allowed
EXAMPLES
The following example indicates that programs from the cell "abc.com" are not allowed to run with setuid permission.
% fs getcellstatus abc.com
Cell abc.com status: no setuid allowed
PRIVILEGE REQUIRED
None
SEE ALSO
CellServDB(5), fs_setcell(1)
COPYRIGHT
IBM Corporation 2000. <http://www.ibm.com/> All Rights Reserved.
This documentation is covered by the IBM Public License Version 1.0. It was converted from HTML to POD by software written by Chas
Williams and Russ Allbery, based on work by Alf Wachsmann and Elizabeth Cassell.
OpenAFS 2012-03-26 FS_GETCELLSTATUS(1)