Re: multihost master.passwd sync

From: Eric Anderson (anderson_at_centtech.com)
Date: 05/27/03

  • Next message: Andy Harrison: "Re: multihost master.passwd sync"
    Date: Tue, 27 May 2003 14:04:56 -0500
    To: Michael Collette <metrol@metrol.net>
    
    

    Michael Collette wrote:
    > On Tuesday 27 May 2003 11:30 am, Andy Harrison wrote:
    [..snip..]
    >>>NIS [yp(8)] ?
    >>
    >>Lord no... even if you setup a backup nis server, an ailing master server
    >>can really screw up your day.
    >>
    >>I think I thought of a solution though. root cronjob to pgp encrypt the
    >>file, change perms so that it can be accessed by a user that is allowed to
    >>copy the file to the target host. The file is in encrypted using the
    >>public key of root the target machine, so only root on the target will be
    >>able to pgp extract the file.
    >
    >
    > Why not just preconfigure SSH keys between the boxes and scp the file across?
    > Seems like a lot of extra work to bring PGP into the mix.
    >
    > Personally, I'm real curious about utilizing an LDAP backend to replace NIS.
    > Read a bit about it, but haven't had a chance to play with it just yet. It
    > sounds like a far more elegant solution for what you're looking to do as
    > well. Assuming it all works as advertised that is.

    I've started this exact process - replacing my NIS gunk with LDAP.. Not
    too far through yet, but I'll try to keep good notes for anyone else who
    may want them..

    Eric

    -- 
    ------------------------------------------------------------------
    Eric Anderson	   Systems Administrator      Centaur Technology
    Attitudes are contagious, is yours worth catching?
    ------------------------------------------------------------------
    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
    

  • Next message: Andy Harrison: "Re: multihost master.passwd sync"

    Relevant Pages

    • Re: multihost master.passwd sync
      ... even if you setup a backup nis server, ... > copy the file to the target host. ... > public key of root the target machine, so only root on the target will be ... > able to pgp extract the file. ...
      (FreeBSD-Security)
    • Re: multihost master.passwd sync
      ... even if you setup a backup nis server, ... file to the target host. ... root the target machine, so only root on the target will be able to pgp extract ...
      (FreeBSD-Security)