HP UX LDAP-UX Integration Software manual Windows, Active Directory AD, Kerberos Services

Page 5

PAM:

login,su….application… …..

PAM Library

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

….

 

 

PAM_UNIX

 

 

PAM_LDAP

 

PAM_Kerberos

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

NSS:

 

 

 

 

 

 

 

 

 

 

 

 

 

 

getpwnam()

 

 

getgrnam()

….

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

NSS Engine

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

….

 

 

NSS_FILES

 

 

 

NSS_NIS

 

 

 

NSS_LDAP

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Application services

Reads /etc/pam.conf to see which authentication module to use

Authentication modules

APIs to access user/system information

Reads /etc/nsswitch.conf to decide which name service module to use

Name service modules

Windows 2000

Following two primary Windows 2000 features built on top of existing industry standards improve Windows 2000’s capability to interoperate with UNIX platforms:

Active Directory (AD):

This is an LDAP based directory which Windows 2000 uses to store all its data. LDAP is an open internet standard. The support of LDAP allows Windows 2000 to interoperate with other vendors’ LDAP directory enabled applications.

Kerberos Services:

Kerberos is the primary authentication method for Microsoft clients connecting to Windows 2000 server. Kerberos is an industry standard for network security. With the support of Kerberos authentication, Windows 2000 is able to authenticate Kerberos clients regardless of what platforms the clients reside on.

Active Directory and Kerberos are integrated seamlessly in the Windows 2000 operating system. Active Directory domain controllers are automatically configured to provide Kerberos with authentication services, and by default, all Windows 2000 computers are configured to operate as Kerberos clients.

Services for UNIX (SFU):

5

Image 5
Contents White Paper Copyright Notices Legal NoticesIntroduction PAM Kerberos HP-UX and Windows 2000 Integration ProductsPAM and NSS Services for Unix SFU Kerberos ServicesWindows Active Directory ADNIS Server NIS Integration How HP-UX and Windows 2000 Products IntegrateHP-UX Client Windows 2000 ServerNIS+PAMKerberos HP-UX client Ldap + PAMKerberos HP-UX Client Windows 2000 Server Ldap IntegrationHP-UX Client Windows 2000 Server NIS vs. Ldap Integration Benefits of Integration Common AuthenticationCommon Data Repository Single Point of Account ManagementInstall Active Directory into your Windows 2000 server Configuring Windows 2000 and HP-UX Using NIS IntegrationInstall SFU 2.0, including Server for NIS Add an account for HP-UX client machine to ADPAM Kerberos Configuration NIS Client ConfigurationAdd a host key to the /etc/krb5.keytab file Add the Kerberos services to /etc/servicesCreate /etc/krb5.conf Synchronize the HP-UX clock to the Windows 2000 clock Change /etc/pam.conf to use PAM KerberosPassword sufficient /usr/lib/security/libpamunix.1 Active Directory Configuration Configuring Windows 2000 and HP-UX Using Ldap IntegrationSoftware Installation Verify profile cache LDAP-UX Client Services ConfigurationRun the setup tool Change Name Service Switch NSS to use Ldap Configure a proxy userSecurity Add and delete user accounts AdministrationAdd and delete groups Password expiration Manage account and password policiesUser forced to change password Login procedureMigration Appendix a Setting a Proxy User’s Access Rights Read memberUid Read msSFUPassword Read msSFUName
Related manuals
Manual 214 pages 54.35 Kb Manual 65 pages 7.83 Kb