- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- partial smb authentication? Can this be done?
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Forums
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО06-25-2004 02:21 AM
тАО06-25-2004 02:21 AM
partial smb authentication? Can this be done?
On most of my systems, there are a few user accounts that I would prefer to offer the benefits of a single sign-on.
However, for most of the accounts on any given system (root, www, nobody, oracle, etc) I want to preclude any possiblity that they can be accessed by authenticating against the single sign-on directory.
I suppose what I'm thinking of might be implemented as an smbauth pam module that was smart enough to check a local list of usernames allowed to be authenticated via smb. Does such a module exist?
Other suggestions are very welcome.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО06-25-2004 02:37 AM
тАО06-25-2004 02:37 AM
Re: partial smb authentication? Can this be done?
So simply add your single signons to LDAP, and your unique signons to local passwd database.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО06-25-2004 03:05 AM
тАО06-25-2004 03:05 AM
Re: partial smb authentication? Can this be done?
(Unless I'm misunderstanding you...)
I do not want the presence of a 'root' account in the SSO directory to cause the unix root account to be authenticated against the directory.
Ie I want complete control over which accounts use sso and which accounts don't use sso to remain *only* with the Unix admin, not the SSO admin.
Did I misunderstand? If so, correct me and win more points. :-)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО06-25-2004 06:25 AM
тАО06-25-2004 06:25 AM
Re: partial smb authentication? Can this be done?
This may or may not help.
Look for /etc/pam_user.conf. In this file you can specify the authentication policy on an user basis.
-- Sundar
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО06-25-2004 06:47 AM
тАО06-25-2004 06:47 AM
Re: partial smb authentication? Can this be done?
Active Directory with LDAP installed will absolutely allow you to have single sign on for Unix servers.
The exception is account such as root and other admin accounts which can not and should not be authenticated this way.
Here are some docs that tell you how to do it:
http://docs.hp.com/cgi-bin/fsearch/framedisplay?top=/hpux/onlinedocs/J4269-90031/J4269-90031_top.html&con=/hpux/onlinedocs/J4269-90031/00/00/13-con.html&toc=/hpux/onlinedocs/J4269-90031/00/00/13-toc.html&searchterms=Directory%7cLDAP%7cintegration%7cActive&queryid=20040625-124636
http://docs.hp.com/cgi-bin/fsearch/framedisplay?top=/hpux/onlinedocs/J4269-90031/J4269-90031_top.html&con=/hpux/onlinedocs/J4269-90031/00/00/13-con.html&toc=/hpux/onlinedocs/J4269-90031/00/00/13-toc.html&searchterms=Directory%7cLDAP%7cintegration%7cActive&queryid=20040625-124537
http://docs.hp.com/cgi-bin/fsearch/framedisplay?top=/hpux/onlinedocs/J4269-90031/J4269-90031_top.html&con=/hpux/onlinedocs/J4269-90031/00/00/7-con.html&toc=/hpux/onlinedocs/J4269-90031/00/00/7-toc.html&searchterms=Directory%7cLDAP%7cintegration%7cActive&queryid=20040625-124537
SEP
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО06-25-2004 07:12 AM
тАО06-25-2004 07:12 AM
Re: partial smb authentication? Can this be done?
passwd : file ldap in /etc/nsswitch.conf.
Refer /etc/nsswitch.ldap for examples.
Anil