Installation Overview
Chapter
2
Installation
75
Deciding the User and Group for Your Netscape Servers
For security reasons, it is always best to run UNIX-based production servers with
normal user privileges. That is, you do not want to run the servers with
root
privileges. However, you will have to run Directory Server with root privileges if
you are using the default Directory Server ports. If Directory Server is to be started
by Administration Server, Administration Server must run either as
root
or as the
same user as Directory Server.
You must therefore decide what user accounts you will use for the following
purposes:
•
The user and group under which you will run Directory Server.
If you will not be running the Directory Server as root, it is strongly
recommended that you create a user account for all Netscape servers. You
should not use any existing operating system account, and must not use the
nobody
account. Also you should create a common group for the directory
server files; again, you must not use the
nobody
group.
•
The user and group under which you will run Administration Server.
For installations that use the default port numbers, this must be root. However,
if you use ports over 1024, then you should create a user account for all
Netscape servers, and run Administration Server as this account.
As a security precaution, when Administration Server is being run as
root
, it
should be shut it down when it is not in use.
You should use a common group for all Netscape servers, such as gid
Netscape
, to
ensure that files can be shared between servers when necessary.
Before you can install Directory Server and Administration Server, you must make
sure that the user and group accounts you will use exist on your system.
Defining Authentication Entities
As you install Directory Server and Administration Server, you will be asked for
various user names, distinguished names (DN), and passwords. This list of login
and bind entities will differ depending on the type of installation that you are
performing:
Содержание Certificate Management System 6.2
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 2 June 2003...
Страница 22: ...22 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 30: ...Documentation 30 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 70: ...Support for Open Standards 70 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 84: ...Uninstalling CMS 84 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 164: ...How a Registration Manager Works 164 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 322: ...Configuring the Server s Security Preferences 322 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 380: ...ACL Reference 380 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 564: ...Managing Policy Plug in Modules 564 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 744: ...1 3 Organization Security Policies 744 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 750: ...Object Identifiers 750 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 796: ...DNs in Certificate Management System 796 Netscape Certificate Management System Administrator s Guide June 2003...
Страница 828: ...Managing Certificates 828 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 844: ...The SSL Handshake 844 Netscape Certificate Manager System Administrator s Guide June 2003...
Страница 862: ...862 Netscape Certificate Management System Administrator s Guide June 2003...