Re: Trying to replace NIS+

From: Rich Teer (rich.teer_at_rite-group.com)
Date: 08/27/03


Date: Wed, 27 Aug 2003 19:22:51 GMT

On 27 Aug 2003, B.A.Baumgart wrote:

> I am trying to replace our present NIS+ implementation. My current setup
> is about 100 machines, with about 20 users that need to be able to login
> to any of the machines. The users home directory is NFS mounted. Yep,
> perfect use of NIS or NIS+. NIS+ was chosen because of security issues.
>
> We use Windows for our administrative tasks. All of these 20 users have

You're using Windoze, yet are concerned with security issues?!
Windoze is your biggest security issue.

> Found several products that did password synchronization. Seemed labor-
> intensive, and prone to errors. Also would be a NIS+ to LDAP conversion,
> then an LDAP to LDAP/AD syncronization conversion. There is one of me.

My understanding is the SunONE Directory (i.e., LDAP) Server that
comes with Solaris 9 will authenticate Captive Directory users.

> Looked at Microsoft's AD plugin. It would work, except it works by
> looking like a NIS server, complete with NIS security issues.

Again, you're using M$ software, so NIS security is not your biggest
concern.

> My current thought (and question) is this. All of these twenty users has
> an RSA Security SecurID card. I have played with RSA's PAM module. Is
> it possible to do local password authentication, but retreive uid/gid
> information from NIS maps? This would eliminate the open clear-text
> password transmission and open password files of NIS, but would
> centralize the uid/gid information.
>
> Am I onto something here, or is it back to the drawing board?

I'm not sure, but I know the LDAP server with Solaris supports
strong encryption over the wire. That would be where I'd be
inclined to look.

-- 
Rich Teer, SCNA, SCSA
President,
Rite Online Inc.
Voice: +1 (250) 979-1638
URL: http://www.rite-online.net


Relevant Pages

  • Re: One login for multiple machines
    ... get authenticated from remote server (thus not need to create ... network) a centrally-stored login on a Linux server for Windows PCs ... I've excerpted some relevant info from two web pages on NIS and LDAP... ... It is for this reason that LDAP ...
    (Ubuntu)
  • Re: Centralized authentication
    ... >A few people suggested NIS+. ... Virtually all of our boxes are FreeBSD, ... >don't know very much about either server. ... >setup and get working than an LDAP server. ...
    (FreeBSD-Security)
  • Re: Directory Server LDAP/LDIF import - working yet not working???
    ... I then generated LDIF files from the /etc files on our NIS ... > 10,000-foot understanding of LDAP. ... > I already downloaded the various LDAP BluePrints and Directory Server ...
    (comp.unix.solaris)
  • Re: Sparc Solaris NIS client Linux NIS server
    ... >>>fairly trivial to auto create NIS users based on Windows ... >> LDAP works much, much better for providing single-source authentication. ... Security is a problem, ...
    (comp.os.linux.setup)
  • Re: Customizing Security
    ... > We have data center that has server running in multiple operating ... > centralizing all the security information on one security and policy ... LDAP and your environment are a perfect match, ... can store email and contact info of users (not only internal ones, ...
    (comp.os.linux.security)