
280
OES 2 SP2: Planning and Implementation Guide
n
ov
do
cx (e
n)
22
Ju
n
e 20
09
The Password policies governing the users who need access to these services must be selected
during service configuration. The services auto-create default password policies for
themselves, but the Password policies to use here must be the actual policies governing users
who need access to these services.
There must be at least one writable replica of NMAS
TM
version 3.2 or later having the user
object trying to access the AFP or CIFS server. NMAS 3.2 is already present on OES 2 and
OES 2 SP2 servers, as well as on servers with eDirectory 8.8.2 installed. On OES 1 and
NetWare
®
servers with a lone writable replica of a AFP or CIFS user, NMAS should be
upgraded by upgrading to the Novell
®
Security Services 2.0.6 on eDirectory 8.7.3 SP10 or
eDirectory 8.8.2.
The file access services will provide access/visibility to the users as per the trustee rights they
have on the volumes and files.
In addition, Samba (on both DSFW and non-DSFW servers) has the following additional
requirements:
The users must be LUM-enabled on the server.
The users must be members of a LUM-enabled group on the server holding the volumes.
Samba users must be created in a container or partition that has a <Samba-qualified password
policy> assigned to it.
K.2.2 eDirectory contexts
AFP:
Requires that user contexts be specified during the YaST configuration. These are the
contexts under which the user objects will be searched for during an authentication. In a name-
mapped (existing tree) install, if the context resides in a DSfW domain, the context can be
specified either in the domain name format (Active Directory format) or in the X.509 format.
CIFS:
The eDirectory contexts of users can be specified either in the domain name format
(Active Directory format) or in the X.509 format.
Samba:
Depends on LUM to search for the user in eDirectory and therefore doesn’t require an
eDirectory context.
K.2.3 Password Policies and Assignments
AFP:
Creates a default Password policy as part of the AFP configuration. This policy is created
in the security container as an example. It is not automatically attached to any user objects.
AFP requires the Password policies governing the AFP users to be specified as part of AFP
configuration. For this purpose, AFP displays all Password policies in the tree and requires the
OES admin to select the relevant policies. The Default AFP Policy is implicitly selected in the
configuration process.
CIFS:
Similar in behavior to AFP with respect to password policies, it creates the Default
CIFS Policy under the security container.
Samba:
Creates a default password policy, but does not attach this policy to any user.
DSFW:
The password policy in a DSfW environment is modeled after Active Directory
Password policies. There is a single Password policy at the domain level, and it is configured
during provisioning. eDirectory allows you to set policies at the user or container level.
However, this is not recommended in a DSfW environment.
Содержание OPEN ENTERPRISE SERVER 2 SP2 - ADMINISTRATION
Страница 4: ...4 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 14: ...14 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 24: ...24 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 26: ...26 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 76: ...76 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 80: ...80 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 82: ...82 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 98: ...98 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 122: ...122 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 148: ...148 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 178: ...178 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 208: ...208 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 216: ...216 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 224: ...224 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 232: ...232 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 234: ...234 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 242: ...242 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 244: ...244 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 248: ...248 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 252: ...252 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 256: ...256 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 276: ...276 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 278: ...278 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 288: ...288 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...