<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: UID and GID management across several servers in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/uid-and-gid-management-across-several-servers/m-p/3279798#M749591</link>
    <description>Thank you everyone for the help all of this has been so informative. I'm working with a 300+ Server count and 15,000+ user accounts. Based on the feedback I would like to use the /etc/passwd along with LDAP-UX. &lt;BR /&gt;&lt;BR /&gt;Next question I don't know LDAP-UX or where to begin.</description>
    <pubDate>Wed, 19 May 2004 12:26:44 GMT</pubDate>
    <dc:creator>Daniel Gutierrez</dc:creator>
    <dc:date>2004-05-19T12:26:44Z</dc:date>
    <item>
      <title>UID and GID management across several servers</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/uid-and-gid-management-across-several-servers/m-p/3279788#M749581</link>
      <description>Is there a product or way that will allow management of UID's and GID's across several hundred servers? I have run into a case were the same person can have a user ID across many servers and not have the same UID Number, and the User name is in different Groups. If HPUX has a way please pass that on. HPUX 10.20, 11.0 and 11i systems</description>
      <pubDate>Tue, 18 May 2004 11:59:58 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/uid-and-gid-management-across-several-servers/m-p/3279788#M749581</guid>
      <dc:creator>Daniel Gutierrez</dc:creator>
      <dc:date>2004-05-18T11:59:58Z</dc:date>
    </item>
    <item>
      <title>Re: UID and GID management across several servers</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/uid-and-gid-management-across-several-servers/m-p/3279789#M749582</link>
      <description>The standard way to handle this in the UNIX world is NIS and this will work across all these OS releases as well as essentially all flavors of UNIX. The downside is that NIS does not meet today's security needs so a better option is LDAP.&lt;BR /&gt;</description>
      <pubDate>Tue, 18 May 2004 12:04:02 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/uid-and-gid-management-across-several-servers/m-p/3279789#M749582</guid>
      <dc:creator>A. Clay Stephenson</dc:creator>
      <dc:date>2004-05-18T12:04:02Z</dc:date>
    </item>
    <item>
      <title>Re: UID and GID management across several servers</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/uid-and-gid-management-across-several-servers/m-p/3279790#M749583</link>
      <description>Hi Daniel,&lt;BR /&gt;&lt;BR /&gt;There are sure products that will do the user administration. NIS(insecure), NIS+ and LDAP are most commonly used. Control-SA by BMC is another product that costs $$.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.bmc.com/products/proddocview/0,2832,19052_19429_22855_1587,00.html" target="_blank"&gt;http://www.bmc.com/products/proddocview/0,2832,19052_19429_22855_1587,00.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;However, you will first need to clean up the mess before you can start using any product. You will need to come up with a standard set of uids/gids, sync them up on all the boxes and then use the product to maintain them. It can be quite a bit of work if the UIDs are in use (like generic logins to run the application processes).&lt;BR /&gt;&lt;BR /&gt;-Sri</description>
      <pubDate>Tue, 18 May 2004 12:11:44 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/uid-and-gid-management-across-several-servers/m-p/3279790#M749583</guid>
      <dc:creator>Sridhar Bhaskarla</dc:creator>
      <dc:date>2004-05-18T12:11:44Z</dc:date>
    </item>
    <item>
      <title>Re: UID and GID management across several servers</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/uid-and-gid-management-across-several-servers/m-p/3279791#M749584</link>
      <description>Daniel,&lt;BR /&gt;&lt;BR /&gt;We tried NIS and didn't really care for it.  We now simply use the same password file on all the different servers, copying it amongst them via NFS.  There are probably security concerns with this simplistic approach, but it works for us and didn't cost a dime.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Pete</description>
      <pubDate>Tue, 18 May 2004 12:16:12 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/uid-and-gid-management-across-several-servers/m-p/3279791#M749584</guid>
      <dc:creator>Pete Randall</dc:creator>
      <dc:date>2004-05-18T12:16:12Z</dc:date>
    </item>
    <item>
      <title>Re: UID and GID management across several servers</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/uid-and-gid-management-across-several-servers/m-p/3279792#M749585</link>
      <description>Suggest using NIS+&lt;BR /&gt;&lt;BR /&gt;However, if you are concerned about Security, there's a good read at:&lt;BR /&gt;&lt;A href="http://www.eng.auburn.edu/users/doug/nis.html" target="_blank"&gt;http://www.eng.auburn.edu/users/doug/nis.html&lt;/A&gt;</description>
      <pubDate>Tue, 18 May 2004 13:43:28 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/uid-and-gid-management-across-several-servers/m-p/3279792#M749585</guid>
      <dc:creator>Dani Seely</dc:creator>
      <dc:date>2004-05-18T13:43:28Z</dc:date>
    </item>
    <item>
      <title>Re: UID and GID management across several servers</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/uid-and-gid-management-across-several-servers/m-p/3279793#M749586</link>
      <description>NIS+ is not available for 10.20. It's more secure than NIS but it too is not long for this world. If you are serious about doing this, again the answer is LDAP, now what's your question?&lt;BR /&gt;</description>
      <pubDate>Tue, 18 May 2004 14:15:24 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/uid-and-gid-management-across-several-servers/m-p/3279793#M749586</guid>
      <dc:creator>A. Clay Stephenson</dc:creator>
      <dc:date>2004-05-18T14:15:24Z</dc:date>
    </item>
    <item>
      <title>Re: UID and GID management across several servers</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/uid-and-gid-management-across-several-servers/m-p/3279794#M749587</link>
      <description>I am part of a team that administers hundreds of servers. We also do NOT use NIS. It is too insecure. However, in our workstation environment they do use NIS. ALL users who get accounts on any of our systems, gets enetered into NIS. Then when we create a user on one of our servers we have a home grown app that pulls the UID from NIS and creates the account on the appropriate servers.&lt;BR /&gt;&lt;BR /&gt;However, due to Sarbanes Oxley requirements, we will be migrating to LDAP soon. &lt;BR /&gt;&lt;BR /&gt;Realize that you can't just chnage the UID's to be the same on all of the systems and think that everything is going to work. To change the UID of a user on a system, you will need to search the filesystems to find files owned by that UID and change the ownership to the new UID. This IS going to be a lot of work. But, the sooner you do it, the better. The problem will only get worse over time.</description>
      <pubDate>Tue, 18 May 2004 16:21:35 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/uid-and-gid-management-across-several-servers/m-p/3279794#M749587</guid>
      <dc:creator>Scott J. Showalter</dc:creator>
      <dc:date>2004-05-18T16:21:35Z</dc:date>
    </item>
    <item>
      <title>Re: UID and GID management across several servers</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/uid-and-gid-management-across-several-servers/m-p/3279795#M749588</link>
      <description>True.  I neglected to state that NIS+ won't be an answer for you on 10.20 systems, only on 11.00 for you.&lt;BR /&gt;&lt;BR /&gt;Scott brings up a good point too, that when a UID changes, the files are left and are identified as owned by the previous UID #.  When that UID # gets assigned, if those files aren't changed to the previous owners new UID then you will have a HUGH mess!&lt;BR /&gt;&lt;BR /&gt;Though Pete's suggestion of copying the same passwd file to all of your servers sounds simple, you'll run into this problem of file ownership.&lt;BR /&gt;&lt;BR /&gt;I'll keep looking into this, this is a VERY interesting concepct and concern.  By the way, how many servers are you talking about?  It would also help if you break it down to how many servers per platform.  Thanks!</description>
      <pubDate>Tue, 18 May 2004 16:36:22 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/uid-and-gid-management-across-several-servers/m-p/3279795#M749588</guid>
      <dc:creator>Dani Seely</dc:creator>
      <dc:date>2004-05-18T16:36:22Z</dc:date>
    </item>
    <item>
      <title>Re: UID and GID management across several servers</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/uid-and-gid-management-across-several-servers/m-p/3279796#M749589</link>
      <description>Hey Paul,&lt;BR /&gt;Thought I'd try to do a little explanation of file permissions.  Each digit corresponds&lt;BR /&gt;to the permissions for user, group, and other ... respectively.&lt;BR /&gt;&lt;BR /&gt;The umask is subtracted from 777 / 666 to give the permission set.&lt;BR /&gt;&lt;BR /&gt;So, since you have a umask 022, 666-022 leaves 644 (rw-r--r--).  As r=4, w=2, x=1,&lt;BR /&gt;644 is user rw- (4+2) group r-- (4) others r-- (4).&lt;BR /&gt;&lt;BR /&gt;Hope this adds some clarity.</description>
      <pubDate>Tue, 18 May 2004 18:43:19 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/uid-and-gid-management-across-several-servers/m-p/3279796#M749589</guid>
      <dc:creator>Dani Seely</dc:creator>
      <dc:date>2004-05-18T18:43:19Z</dc:date>
    </item>
    <item>
      <title>Re: UID and GID management across several servers</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/uid-and-gid-management-across-several-servers/m-p/3279797#M749590</link>
      <description>SORRY!&lt;BR /&gt;&lt;BR /&gt;While this is good information, I posted it to the wrong subject thread.  Oh well, enjoy.</description>
      <pubDate>Tue, 18 May 2004 18:46:37 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/uid-and-gid-management-across-several-servers/m-p/3279797#M749590</guid>
      <dc:creator>Dani Seely</dc:creator>
      <dc:date>2004-05-18T18:46:37Z</dc:date>
    </item>
    <item>
      <title>Re: UID and GID management across several servers</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/uid-and-gid-management-across-several-servers/m-p/3279798#M749591</link>
      <description>Thank you everyone for the help all of this has been so informative. I'm working with a 300+ Server count and 15,000+ user accounts. Based on the feedback I would like to use the /etc/passwd along with LDAP-UX. &lt;BR /&gt;&lt;BR /&gt;Next question I don't know LDAP-UX or where to begin.</description>
      <pubDate>Wed, 19 May 2004 12:26:44 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/uid-and-gid-management-across-several-servers/m-p/3279798#M749591</guid>
      <dc:creator>Daniel Gutierrez</dc:creator>
      <dc:date>2004-05-19T12:26:44Z</dc:date>
    </item>
    <item>
      <title>Re: UID and GID management across several servers</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/uid-and-gid-management-across-several-servers/m-p/3279799#M749592</link>
      <description>Hey Daniel,&lt;BR /&gt;I have not experimented with LDAP-UX, however, there's a REALLY good article that explains LDAP-UX, including topographical layouts at:&lt;BR /&gt;&lt;A href="http://docs.hp.com/cgi-bin/otsearch/getfile?id=/hpux/onlinedocs/internet/uxint.html&amp;amp;searchterms=LDAP&amp;amp;queryid=20011108-122355" target="_blank"&gt;http://docs.hp.com/cgi-bin/otsearch/getfile?id=/hpux/onlinedocs/internet/uxint.html&amp;amp;searchterms=LDAP&amp;amp;queryid=20011108-122355&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Also, the following link tells you how to purchase support for LDAP-UX (J4269AA LDAP-UX Integration), and a phone number for the HP Advantage Center you can call in lieu of talking with an HP sales representative (800-637-7740).&lt;BR /&gt;&lt;BR /&gt;Here you can obtain information about the product, including an overview, pricing, support level options, and other options.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.software.hp.com/cgi-bin/swdepot_parser.cgi/cgi/displayProductInfo.pl?productNumber=J4269AA" target="_blank"&gt;http://www.software.hp.com/cgi-bin/swdepot_parser.cgi/cgi/displayProductInfo.pl?productNumber=J4269AA&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Good luck!</description>
      <pubDate>Wed, 19 May 2004 13:09:27 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/uid-and-gid-management-across-several-servers/m-p/3279799#M749592</guid>
      <dc:creator>Dani Seely</dc:creator>
      <dc:date>2004-05-19T13:09:27Z</dc:date>
    </item>
  </channel>
</rss>

