
Users and Groups
151
n
ov
do
cx (e
n)
22
Ju
n
e 20
09
Table 15-1
Linux User Management
Linux Requires POSIX Users
Linux requires that all users be defined by standard POSIX attributes, such as username, user ID
(UID), primary group ID (GID), password, and other similar attributes.
Linux Users Can Be Local or Remote
Users that access a Linux server can be created in two ways:
Locally (on the server):
Local users are managed at a command prompt (using commands
such as
useradd
) or in YaST. (See the useradd(8) man page and the YaST online help for more
information.) These local users are stored in the
/etc/passwd
file. (See the passwd(5) man
page for more information.)
IMPORTANT:
As a general rule on OES 2 servers, the only local user account that should
exist is
root
. All other user accounts should be created in eDirectory and then be enabled for
Linux access (LUM). You should never create duplicate local and eDirectory user accounts.
For more information, see
Section 6.2, “Avoiding POSIX and eDirectory Duplications,” on
page 62
.
Remotely (off the server):
Remote users can be managed by other systems, such as LDAP-
compliant directory services. Remote user access is enabled through the Pluggable
Authentication Module (PAM) architecture on Linux.
The Linux POSIX-compliant interfaces can authenticate both kinds of users, independent of where
they are stored and how they are managed.
The root User Is Never LUM-Enabled
The OES 2 user management tools prevent you from creating an eDirectory user named
root
, thus
replacing the
root
user on an OES 2 server. If
root
were to be a LUM user and eDirectory became
unavailable for some reason, there would be no root access to the system.
Even if eDirectory is not available, you can still log into the server through Novell Remote Manager
and perform other system management tasks as the
root
user.
Valid POSIX Users
Authentication
eDirectory Authenticated Services
Some services on OES 2 servers
must be accessed by POSIX
users.
eDirectory users can function as
POSIX users if they are enabled
for Linux access (LUM).
When the system receives an
action request, it can authenticate
both local POSIX users and users
who have been enabled for Linux
access.
Users can potentially access
PAM-enabled services, Samba
shares, and Novell Remote
Manager as either local or
eDirectory users.
By default, only the
openwbem
command (required for server
management) is enabled for
eDirectory access.
Содержание OPEN ENTERPRISE SERVER 2 SP2 - ADMINISTRATION
Страница 4: ...4 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 14: ...14 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 24: ...24 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 26: ...26 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 76: ...76 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 80: ...80 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 82: ...82 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 98: ...98 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 122: ...122 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 148: ...148 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 178: ...178 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 208: ...208 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 216: ...216 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 224: ...224 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 232: ...232 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 234: ...234 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 242: ...242 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 244: ...244 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 248: ...248 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 252: ...252 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 256: ...256 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 276: ...276 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 278: ...278 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 288: ...288 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...