Installation Overview
Chapter
2
Installation
73
Deciding the User and Group for Your Netscape Servers
For security reasons, it is always best to run UNIX-based production servers with
normal user privileges. That is, you do not want to run the servers with
root
privileges. However, you will have to run Directory Server with root privileges if
you are using the default Directory Server ports. If Directory Server is to be started
by Administration Server, Administration Server must run either as
root
or as the
same user as Directory Server.
You must therefore decide what user accounts you will use for the following
purposes:
•
The user and group under which you will run Directory Server.
If you will not be running the Directory Server as root, it is strongly
recommended that you create a user account for all Netscape servers. You
should not use any existing operating system account, and must not use the
nobody
account. Also you should create a common group for the directory
server files; again, you must not use the
nobody
group.
•
The user and group under which you will run Administration Server.
For installations that use the default port numbers, this must be root. However,
if you use ports over 1024, then you should create a user account for all
Netscape servers, and run Administration Server as this account.
As a security precaution, when Administration Server is being run as
root
, it
should be shut it down when it is not in use.
You should use a common group for all Netscape servers, such as gid
Netscape
, to
ensure that files can be shared between servers when necessary.
Before you can install Directory Server and Administration Server, you must make
sure that the user and group accounts you will use exist on your system.
Defining Authentication Entities
As you install Directory Server and Administration Server, you will be asked for
various user names, distinguished names (DN), and passwords. This list of login
and bind entities will differ depending on the type of installation that you are
performing:
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...