Here are some options for establishing the appropriate UNIX user ID for your SPD Server
processes:
Establish a dedicated UNIX account for the SPD Server administrator. Always execute the
rc.spds script from that account.
The rc.spds script that starts the SPD Server processes should use the setuid bit. It does not
matter who executes the script, the user ID of the shell executing the script is the script
owner. This ensures that SPD Server processes run with the correct UNIX user ID.
At system startup, use the UNIX
su
command to establish the proper UNIX user ID for
the shell that executes the rc.spds script. To start the environment manually, you must enter
the password for each UNIX account in your
su
command, unless you are root when you
execute the
su
command.
SPD Server User IDs
The SPD Server system uses its own layer of access controls that overlay UNIX access
permissions. SPD Server processes run in the context of a UNIX user ID, and that user
owns all of the resulting SPD Server file resources that are created.
The SPD Server password file allows better access control to SPD Server's data resources
than a native UNIX user ID. Many sites do not want to give UNIX accounts to SPD Server
system users, but still want protection and ownership of the data resources created in the
SPD Server environment. In this case, SPD Server user IDs provide the extra layer of access
control.
The SPD Server administrator needs to be familiar with the psmgr utility in SPD Server.
If you do not use SPD Server user IDs, you still need the SPD Server password file. Without
the SPD Server password file, the SPD Server host process does not function correctly. To
disable the use of SPD Server user IDs at your site, specify the -NOACL option when you
start SPD Server.
If you use SPD Server user IDs, add them to the SPD Server password file that was created
during installation. The
psmgr
command reads its commands from
stdin
so you can pipe
commands to it from another command, script, or input file.
LDAP Password Authentication
LDAP Authentication causes SPD Server to authenticate an SPD Server user password
using LDAP, rather than using the password in the password database. LDAP
authentication allows an SPD Server user to have the same user ID and password as their
UNIX logon, as long as the UNIX logon meets the SPD Server character restrictions for
user IDs and passwords.
You can select the mode of password authentication with server parameters. You can
choose between using psmgr or LDAP. Once selected, all authentication is performed using
the selected mode. When you use LDAP authentication, an SPD Server user must be entered
in the SPD Server password database, in order to maintain other information that SPD
Server requires, such as a user's groups and access levels.
For more information about SPD Server LDAP authentication, see "SPD Server Password
Manager."
LDAP Password Authentication
33
Summary of Contents for Scalable Performance Data Server 4.5
Page 1: ...SAS Scalable Performance Data Server 4 5 Administrator s Guide...
Page 7: ...Part 1 Product Notes Chapter 1 SPD Server 4 5 Product Notes 3 1...
Page 8: ...2...
Page 12: ...6...
Page 63: ...Part 3 Migration Chapter 5 SPD Server 3 x to SPD Server 4 5 Conversion Utility 59 57...
Page 64: ...58...
Page 70: ...64 Chapter 5 SPD Server 3 x to SPD Server 4 5 Conversion Utility...
Page 72: ...66...
Page 76: ...70 Chapter 6 Using the SPD Server Name Server to Manage Resources...
Page 94: ...88 Chapter 7 Administering and Configuring SPD Server Using the SAS Management Console...
Page 98: ...92 Chapter 8 SPD Server SQL Query Rewrite Facility...
Page 116: ...110 Chapter 10 Configuring Disk Storage for SPD Server...
Page 128: ...122 Chapter 11 Setting Up SPD Server Parameter Files...
Page 154: ...148...
Page 198: ...192 Chapter 14 ACL Security Overview...
Page 212: ...206 Chapter 15 Managing SPD Server Passwords Users and Table ACLs...
Page 214: ...208...
Page 224: ...218 Chapter 16 SPD Server Operator Interface Procedure PROC SPDO...
Page 236: ...230 Chapter 18 SPD Server Table List Utility Spdsls...
Page 256: ...250 Chapter 19 SPD Server Backup and Restore Utilities...
Page 264: ...258 Chapter 20 SPD Server Directory Cleanup Utility...
Page 270: ......