Managing OES 2
95
6
Click the
Linux Profile
tab.
7
Select the
Enable Linux Profile
option.
8
In the Add UNIX Workstation dialog box, browse to and select the UNIX Workstation objects
for the servers you are restricting SSH access to, then click
OK > OK
.
9
Click
Apply > OK
.
10
In the Roles and Tasks list, click
Modify Object
, browse to the group again, then click
OK
.
11
Click the
Other
sub-tab.
12
In the
Unvalued Attributes
list, select
uamPosixPAMServiceExcludeList
, then click the
left-arrow to move the attribute to the
Valued Attributes
list.
13
In the Add Attribute dialog box, click the plus sign (+) next to the empty drop-down list.
14
In the
Add item
field, type
sshd
, then click
OK > OK
.
15
Click the
Members
tab.
16
Browse to and select the User objects that shouldn’t have SSH access, then click
OK
.
17
Click
Apply > OK
.
Providing SSH Access for Samba Users
There are two options for providing SSH access to users who have been enabled for Samba access:
You can remove the user from the
server_name
-W-SambaUserGroup.
IMPORTANT:
This presupposes that the user is a member of a different LUM-enabled group
that also provides access to the server. If the user was enabled for LUM only as part of a Samba
configuration, then removing the user from the Samba group breaks access to Samba and the
user does not have SSH access.
You can change access for the entire Samba group by moving the
uamPosicPAMServiceExcludeList attribute from the
Valued Attributes
list to the
Unvalued
Attributes
list, using the instructions in
“Restricting SSH Access to Only Certain LUM-Enabled
Users” on page 94
as a general guide.
NOTE:
Although the option to disable SSH access through the
Modify Group
iManager plug-
in is much more simple and straightforward, that option is not working as of this writing.
Although the plug-in appears to deselect
sshd
as an allowed service, the service is still selected
when group information is reloaded. Novell plans to address this issue in the near future.
Содержание OPEN ENTERPRISE SERVER - CONVERSION GUIDE 12-2010
Страница 12: ...12 OES 2 SP3 Planning and Implementation Guide...
Страница 24: ...24 OES 2 SP3 Planning and Implementation Guide...
Страница 50: ...50 OES 2 SP3 Planning and Implementation Guide...
Страница 74: ...74 OES 2 SP3 Planning and Implementation Guide...
Страница 78: ...78 OES 2 SP3 Planning and Implementation Guide...
Страница 80: ...80 OES 2 SP3 Planning and Implementation Guide...
Страница 96: ...96 OES 2 SP3 Planning and Implementation Guide...
Страница 146: ...146 OES 2 SP3 Planning and Implementation Guide...
Страница 176: ...176 OES 2 SP3 Planning and Implementation Guide...
Страница 210: ...210 OES 2 SP3 Planning and Implementation Guide...
Страница 218: ...218 OES 2 SP3 Planning and Implementation Guide...
Страница 226: ...226 OES 2 SP3 Planning and Implementation Guide...
Страница 234: ...234 OES 2 SP3 Planning and Implementation Guide...
Страница 236: ...236 OES 2 SP3 Planning and Implementation Guide...
Страница 244: ...244 OES 2 SP3 Planning and Implementation Guide...
Страница 246: ...246 OES 2 SP3 Planning and Implementation Guide...
Страница 250: ...250 OES 2 SP3 Planning and Implementation Guide...
Страница 254: ...254 OES 2 SP3 Planning and Implementation Guide...
Страница 258: ...258 OES 2 SP3 Planning and Implementation Guide...
Страница 284: ...284 OES 2 SP3 Planning and Implementation Guide...
Страница 286: ...286 OES 2 SP3 Planning and Implementation Guide...
Страница 294: ...294 OES 2 SP3 Planning and Implementation Guide...