Re: multihost master.passwd sync

From: Gunnar Flygt (flygt_at_sr.se)
Date: 05/27/03

  • Next message: Andy Harrison: "Re: multihost master.passwd sync"
    Date: Tue, 27 May 2003 21:33:59 +0200
    To: Eric Anderson <anderson@centtech.com>
    
    

    On Tue, May 27, 2003 at 02:04:56PM -0500, Eric Anderson wrote:
    > Michael Collette wrote:
    > >On Tuesday 27 May 2003 11:30 am, Andy Harrison wrote:
    > [..snip..]
    > >>>NIS [yp(8)] ?
    > >>
    > >>Lord no... even if you setup a backup nis server, an ailing master server
    > >>can really screw up your day.
    > >>
    > >>I think I thought of a solution though. root cronjob to pgp encrypt the
    > >>file, change perms so that it can be accessed by a user that is allowed to
    > >>copy the file to the target host. The file is in encrypted using the
    > >>public key of root the target machine, so only root on the target will be
    > >>able to pgp extract the file.
    > >
    > >
    > >Why not just preconfigure SSH keys between the boxes and scp the file
    > >across? Seems like a lot of extra work to bring PGP into the mix.
    > >
    > >Personally, I'm real curious about utilizing an LDAP backend to replace
    > >NIS. Read a bit about it, but haven't had a chance to play with it just
    > >yet. It sounds like a far more elegant solution for what you're looking
    > >to do as well. Assuming it all works as advertised that is.
    >
    > I've started this exact process - replacing my NIS gunk with LDAP.. Not
    > too far through yet, but I'll try to keep good notes for anyone else who
    > may want them..

    I've installed 5.1-beta on a box that should do nss_ldap, so that I
    don't have to setup any users directly on that server. The ldap
    server will be in the corporate network, and the 5.1-RELEASE in
    a DMZ as ftp-server.

    I'm interested in all input I can get, to get the whole thing going.

    >
    > Eric
    >
    >
    > --
    > ------------------------------------------------------------------
    > Eric Anderson Systems Administrator Centaur Technology
    > Attitudes are contagious, is yours worth catching?
    > ------------------------------------------------------------------
    >
    > _______________________________________________
    > freebsd-security@freebsd.org mailing list
    > http://lists.freebsd.org/mailman/listinfo/freebsd-security
    > To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"

    -- 
    Gunnar Flygt
    OPC Data
    Sveriges Radio
    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
    

  • Next message: Andy Harrison: "Re: multihost master.passwd sync"

    Relevant Pages

    • Re: smbfs 2 GB file size limit
      ... Was your issue with reading from or writing to a SMB share? ... What is the server software and OS version? ... What error message are you getting from your FreeBSD client? ... Did you really mean to say scp or cp? ...
      (freebsd-questions)
    • Re: smbfs 2 GB file size limit
      ... >> Was your issue with reading from or writing to a SMB share? ... >> What is the server software and OS version? ... > Did you really mean to say scp or cp? ... > specifying it's dialect capabilities in the smb negotiation. ...
      (freebsd-questions)
    • Re: scp requieres scp1?
      ... >> If the server doesn't support SSH1, it doesn't support scp. ... SSH connection to the server using your local SSH client program, ...
      (comp.security.ssh)
    • Baffling SSH/SCP problem continues - any gurus around?
      ... scp to transfer files from my RH 6.2 server I had recently upgraded. ... Today I rebuilt them both again (openssl 0.9.6d and openssh 3.2.3p1), ... and still, although ssh to the server works fine, scp is still broken. ... openssl and openssh work just fine on the local machine. ...
      (comp.security.ssh)
    • Baffling SSH/SCP problem continues - any gurus around?
      ... scp to transfer files from my RH 6.2 server I had recently upgraded. ... Today I rebuilt them both again (openssl 0.9.6d and openssh 3.2.3p1), ... and still, although ssh to the server works fine, scp is still broken. ... openssl and openssh work just fine on the local machine. ...
      (comp.security.ssh)