Red Hat LINUX VIRTUAL SERVER 4.6 - ADMINISTRATION Installationshandbuch Seite 258

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 296
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 257
238 z/VM and Linux on IBM System z: The Virtualization Cookbook for Red Hat Enterprise Linux 6.0
We've found POSIX group membership management to be one of our more challenging
issues overall. Some older systems (e.g. solaris <= 8 or 9) enforce the old POSIX limit of no
more than 16 secondary groups. Further, the primary group concept is annoying -
conceptually, in any organization with modest member mobility, which primary group do they
get? If one assumes that the primary group is meaningful, e.g. reflective of someone's
function, role, or job, what about people who do two or more things (E.g. student *and*
employee) or people who transfer, but will have a transitional period?
Our not so great compromise was to first use NIS-style netgroups via LDAP for anything we
can. In particular, we use a mutation of netgroups to control individual's authorization to log in
via the use of service search descriptors, and also for sudo privileges. Second in our
environment all meaningful POSIX groups are secondary groups. For primary groups we
adopt the linux convention of creating a separate POSIX group for each individual: e.g. userA
gets a group userA as her primary group. This has the problem of a huge proliferation of
groups, though, and several LDAP clients, in particular AIX, have issues with that.
1
1
Source: http://www2.marist.edu/htbin/wlvindex?linux-390
Seitenansicht 257
1 2 ... 253 254 255 256 257 258 259 260 261 262 263 ... 295 296

Kommentare zu diesen Handbüchern

Keine Kommentare