
96
OES 2 SP2: Planning and Implementation Guide
n
ov
do
cx (e
n)
22
Ju
n
e 20
09
5
Click
Linux User Management
.
6
Type the eDirectory Admin password in the appropriate field, then click
OK > Next
.
7
In the list of allowed services, click
sshd
.
8
Click
Next > Next > Finish
.
Each LUM-enabled group in eDirectory, except the system-created Samba group, now shows
SSH as an allowed service. The Samba group shows the service as not allowed (or literally
speaking,
sshd
is not checked).
Enabling Users for LUM
There are numerous ways to enable users for LUM.
For example, in iManager >
Linux User Management
there are options for enabling users (and
choosing a Group in the process) or enabling groups (and enabling users in the process). Linux
enabling is part of the process required for Samba access. And finally, there are also command line
options.
For specific instructions, refer to “
Managing User and Group Objects in eDirectory
” in the
OES 2
SP2: Novell Linux User Management Technology Guide
.
After you configure the server’s firewall to allow SSH, add SSH as an allowed service, and LUM-
enable the eDirectory users you want to have SSH access, if those same users are not also enabled
for Samba on the server, they now have SSH access to the server.
On the other hand, if you have installed Samba on the server, or if you install Samba in the future,
the users who are configured for Samba access will have SSH access disabled.
To restore access for users impacted by Samba, see
“Providing SSH Access for Samba Users” on
page 97
.
Of course, many network administrators limit SSH access to only those who have administrative
responsibilities. They don’t want every LUM-enabled user to have SSH access to the server.
If you need to limit SSH access to only certain LUM-enabled users, continue with
“Restricting SSH
Access to Only Certain LUM-Enabled Users” on page 96
.
Restricting SSH Access to Only Certain LUM-Enabled Users
SSH Access is easily restricted for one or more users by making them members of a LUM-enabled
group and then disabling SSH access for that group. All other groups assignments that enable SSH
access are then overridden.
1
Open iManager in a browser using its access URL:
http://
IP_Address
/iManager.html
where
IP_Address
is the IP address of an OES 2 server with iManager 2.7 installed.
2
In the
Roles and Tasks
list, click
Groups > Create Group
.
3
Type a group name, for example NoSSHGroup, and select a context, such as the container
where your other Group and User objects are located. Then click
OK
.
4
In the
Roles and Tasks
list, click
Directory Administration > Modify Object
.
5
Browse to the group you just created and click
OK
.
Содержание OPEN ENTERPRISE SERVER 2 SP2 - ADMINISTRATION
Страница 4: ...4 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 14: ...14 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 24: ...24 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 26: ...26 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 76: ...76 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 80: ...80 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 82: ...82 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 98: ...98 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 122: ...122 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 148: ...148 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 178: ...178 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 208: ...208 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 216: ...216 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 224: ...224 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 232: ...232 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 234: ...234 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 242: ...242 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 244: ...244 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 248: ...248 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 252: ...252 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 256: ...256 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 276: ...276 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 278: ...278 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...
Страница 288: ...288 OES 2 SP2 Planning and Implementation Guide novdocx en 22 June 2009...