
Security
221
n
ov
do
cx (e
n)
22
Ju
n
e 20
09
When an NCP volume is created on a Linux POSIX or NSS volume, some of the behavior described
above is modified. For more information, see the
OES 2 SP2: NCP Server for Linux Administration
Guide
, particularly the “
NCP on Linux Security
” section.
21.2.2 User Restrictions: Some OES 2 Limitations
Seasoned NetWare administrators are accustomed to being able to set the following access
restrictions on users:
Account balance restrictions
Address restrictions
Intruder lockout
Login restrictions
Password restrictions
Time restrictions
Many of the management interfaces that set these restrictions (iManager, for example), might seem
to imply that these restrictions apply to users who are accessing an OES 2 server through any
protocol.
This is generally true, with two important exceptions:
Maximum number of concurrent connections in login restrictions
Address restrictions
These two specific restrictions are enforced only for users who are accessing the server through
NCP. Connections through other access protocols (for example, HTTP or CIFS) have no concurrent
connection or address restrictions imposed.
For this reason, you probably want to consider not enabling services such as SSH and FTP for LUM
when setting up Linux User Management. For more information on SSH and LUM, see
Section 11.4, “SSH Services on OES 2,” on page 93
.
For more information on Linux User Management, see
“Linux User Management: Access to Linux
for eDirectory Users” on page 149
. For more information on the services that can be PAM-enabled,
see
Table 15-2 on page 152
.
Subdirectory and file
visibility
Permissions granted to a file or directory
apply to only the file or directory. Users
can't see parent directories along the path
up to the root unless permissions are
granted (by setting the UID, GID, and mode
bits) for each parent.
After permissions are granted, users can
see the entire contents (subdirectories and
files) of each directory in the path.
When users are given a trustee
assignment to a file or directory,
they can automatically see each
parent directory along the path up
to the root. However, users can’t
see the contents of those
directories, just the path to where
they have rights.
Feature
POSIX / Linux
Novell Trustee Model on OES 2
Содержание OPEN ENTERPRISE SERVER 2 SP2 - ADMINISTRATION
Страница 4: ...4 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 14: ...14 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 24: ...24 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 26: ...26 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 76: ...76 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 80: ...80 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 82: ...82 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 98: ...98 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 122: ...122 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 148: ...148 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 178: ...178 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 208: ...208 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 216: ...216 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 224: ...224 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 232: ...232 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 234: ...234 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 242: ...242 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 244: ...244 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 248: ...248 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 252: ...252 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 256: ...256 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 276: ...276 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 278: ...278 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 288: ...288 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...