UID & GID instead of user name and group name


 
Thread Tools Search this Thread
Operating Systems AIX UID & GID instead of user name and group name
# 8  
Old 04-13-2015
As I was trying to say, your local passwd is not longer being used to resolve uid and gid to names since you tried to implement kerberos authentication.

The /etc/security/user shows for root you have the entries:
Code:
root:
...
...
SYSTEM = "compat"
registry = files
...
...

For default, ie. all other users that are not listed in this file, it shows:
Code:
default:
...
SYSTEM = "compat"
...

You should check your /usr/lib/security/methods.cfg for the modules that are loaded. It should contain something like
Code:
KRB5A:
		program = /usr/lib/security/KRB5A
		options = authonly
KRB5Afiles:
		options = db=BUILTIN,auth=KRB5A

So your default: in /etc/security/user should have something like this:
Code:
default:
...
registry=KRB5Afiles
SYSTEM=KRB5Afiles 
...

That also stand all in the links I have already posted.
This User Gave Thanks to zaxxon For This Post:
# 9  
Old 04-13-2015
Hi Ron,

We have executed the steps mentioned but no luck yet.

please find the output when we do listing with non-root user

Code:
emamidev:edsadm 1> ls -ltr
total 328
-rwxr-xr-x    1 207      204              25 Oct 31 2003  rfcexec.sec

Thanks and Regards
Madhav

Last edited by zaxxon; 04-13-2015 at 10:37 AM..
# 10  
Old 04-13-2015
Sounds strange,

please also compare /usr/lib/security/methods.cfg.

Regards,
Ron

PS Zaxxon was faster than me Smilie
# 11  
Old 04-13-2015
Hi Zaxxon,

Yes you are right. We have followed the same links to configure Kerberos authentication and have added the following in the /usr/lib/security/methods.cfg file

Code:
KRB5A: 
        program = /usr/lib/security/KRB5A 
        options = authonly
 
KRB5Afiles: 
 
       options = db=BUILTIN,auth=KRB5A

Though we have deleted these lines from the /usr/lib/security/methods.cfg file, the issue is still not resolved.

Do you want us to add the following lines in /etc/security/user file

Code:
default:
...
registry=KRB5Afiles
SYSTEM=KRB5Afiles 
...

Thanks and Regards
Madhav

---------- Post updated at 07:44 PM ---------- Previous update was at 07:10 PM ----------

Hi Zaxxoon,

Is there a way to make local password file to be in use again ?

Thanks and Regards
Madhav

Last edited by zaxxon; 04-13-2015 at 12:48 PM.. Reason: change icode to code
# 12  
Old 04-13-2015
Quote:
Originally Posted by madhav.kunapa
Hi Zaxxoon,

Is there a way to make local password file to be in use again ?

Thanks and Regards
Madhav
If you change SYSTEM = "files" and registry = files for the user 'edsadm' the local password should be used.

Code:
chsec -f /etc/security/user -s edsadm -a "registry=files"
chsec -f /etc/security/user -s edsadm -a "SYSTEM=files"

Regards
# 13  
Old 04-13-2015
If you removed the lines from /usr/lib/security/methods.cfg, it makes no sense to have them still in /etc/security/user.

You can set it back to the default which should be something like
Code:
SYSTEM=files
registry=files

for your default: stanza.

I have no AIX box here to check, but this should work to have every information being looked up in files, as the values show.

Before you alter anything in the authentication mechanisms, make sure you read the already provided link to documentations and also have a read on this:

Security authentication mechanism in AIX

Please read some documentation - it can't harm! You need to understand what you do. Just trying by trial and error and asking here is maybe not a very good approach to such a sensible part of configuration.

Edit:
Mensch Ron!! Smilie Smilie This time I was too slow, but the half of my post still counts! Smilie
# 14  
Old 04-13-2015
Hi Ron,

We have executed the following

Code:
chsec -f /etc/security/user -s edsadm -a "registry=files"
chsec -f /etc/security/user -s edsadm -a "SYSTEM=files"

However the result is still the same

Code:
emamidev:edsadm 1> ls -ltr
total 328
-rwxr-xr-x    1 207      204              25 Oct 31 2003  rfcexec.sec

When we do chown -R edsadm:sapsys * it throws the following error:

Code:
chown: 3002-131 edsadm is an unknown username

Thanks and Regards
Madhav

Moderator's Comments:
Mod Comment Use CODE for code and ICODE for INLINE code. Don't just use ICODE on everything, thanks.

Last edited by zaxxon; 04-13-2015 at 02:50 PM..
Login or Register to Ask a Question

Previous Thread | Next Thread

10 More Discussions You Might Find Interesting

1. Shell Programming and Scripting

Tar extract: remap uid gid ?

OK, so simple question here: Is there anyway to REMAP, while extracting with tar, specific uid's and gid's on extracted files ? Background: The usual transfer between two servers with same literals username's names, but with different gid and uid. I would like, for example, files owned by... (6 Replies)
Discussion started by: fidodido
6 Replies

2. Homework & Coursework Questions

Display info about users (UID GID processes terminal)

I would like to get an opinion for my solution for this task and get feedback about better approach or mistakes I have made. 1. The problem statement, all variables and given/known data: The task is to create a script which prints information about users whose names are specified in the... (2 Replies)
Discussion started by: kornfan
2 Replies

3. UNIX for Dummies Questions & Answers

uid ,gid value change

Present /home/dsadm# id dsadm uid=0(root) gid=0(root) ---------------------------------- needs to be /home/dsadm> id dsadm uid=23186(dsadm) gid=16284(gdstage) Please provide the command/steps for the above uid, gid value change Thanks in advance for all your support . ... (3 Replies)
Discussion started by: sridhardwh
3 Replies

4. Shell Programming and Scripting

changing uid,gid

Hi, I am new to scrippting need little help, I would like to change uid, gid of exisisting user, example User A current uid=1,gid=2 would like to change uid=4,gid=5 I know the command to change uid,gid but after changing I have to change permissions on folders also which are belonging... (3 Replies)
Discussion started by: manoj.solaris
3 Replies

5. UNIX for Advanced & Expert Users

Numeric uid and gid in ls -l command

I´m listing the contents of a directory using the command ls -lI get numeric uid and gid for some lines. example: drwxr-xr-x root root 1970-01-01 01:00 sys -rw-r--r-- 501 20 0 2010-08-04 14:54 shutdown.bravo.rc drwxr-x--- 501 20 ... (5 Replies)
Discussion started by: flocki
5 Replies

6. UNIX for Advanced & Expert Users

GID & UID for HP-UX ?

Hi, can somebody tell me how to make directoriy in which all files will be generated as dir owner ? I'm able to add GID for directory group and files have group id like folder , but when i do same for user files still are created as user which creates them :( drwsrwsrwx 2 flexbul ... (2 Replies)
Discussion started by: pp56825
2 Replies

7. UNIX for Dummies Questions & Answers

UID & GID of the running process

Hi, out of curosity this question just popped in my mind. Is there any way to find out the uid and gid of the running process ? If i do a ls -l of a program then it shows the uid/gid bit (if its set). I want to see as which user/group the program is running ..... is there any way to know this... (2 Replies)
Discussion started by: ankurjain
2 Replies

8. Shell Programming and Scripting

Rsync - Preserve owner/group with different UID/GID

Dear Folks :-) I want to rsync some files between some servers and preserve files owner and group (not UID or GID), in some machines UID and GID are differents, for example: a) In the rsync server: # stat vbseo.php File: `vbseo.php' Size: 26758 Blocks: 56 IO... (1 Reply)
Discussion started by: Santi
1 Replies

9. Solaris

NFS Mount UID and GID

I have a truble with NFS mount. When i mount remote dir, then all permissions changes! For example: # mkdir /data # mount 10.1.1.100:/var/data /data # ls -l /data drwxr-xr-x 7 nobody nobody 5632 Oct 22 14:55 file1 drwxr-xr-x 4 nobody nobody 512 Oct 22 14:55... (4 Replies)
Discussion started by: jess_t03
4 Replies

10. UNIX for Dummies Questions & Answers

negative UID/GID?!! I can see 'em but what the hell do they mean?!

Just as the subject asks :) Thanks! hellz (2 Replies)
Discussion started by: hellz
2 Replies
Login or Register to Ask a Question