NIS Compat problem on Solaris 5.9

From: Paul Clayton (Paul.Clayton@intecbilling.com)
Date: Tue Jul 18 2006 - 07:05:25 EDT


I have a rather odd problem on two Solaris 9 servers.
Hardware 280R, 2 cpu, 8Gb Ram, 72Gb internal disk x2.

Each server is identical in Solaris patch level and hardware.

OK Here is the problem.
Server one I run the NIS server and it is also a client. User list is about
180 users in total.
Server two is a NIS client only.

I have configured netgroups to keep my users in check. I am running in compat
mode.
The problem I have, is this. There are two users "prmsun" and "testas".

Each of these users belong to a netgroup and the appropriate netgroups are
resident in the password file.

On server one, I can login using "testas", but not "prmsun".
On server two I cannot login using either of these users.
Now here is the strange thing. Other users who have netgroups set up on these
server have access, and can login with no problem.
I have switched on debugging.
If I use "su" with these two users, they work ok, but not ftp,telnet or
rlogin. The only message I get back is a failure in pam_unix_auth, which
suggests that something is not getting handled correctly.
To obviate mistakes, the user and netgroup entry has been remade 3 times, and
the password changed many times, but with no luck.
Some thing is odd in the compat mode for NIS.
IF I drop compat mode and use just
Passwd: files nis
Group: file nis

Then all works ok, but allows other users access.

Any help will be appreciated.

Regards

Paul Clayton
Global Unix Co-ordinator
Intec Billing
240 Main Rondebosch
Cape Town
Tel: +27(0)21 6588000
Fax: +27(0)21 6588001
Mobile: +27(0)83 2853403
--------------------------------------------------------

This e-mail and any attachments are confidential and may also be legally
privileged and/or copyright material of Intec Telecom Systems PLC (or its
affiliated companies). If you are not an intended or authorised recipient
of this e-mail or have received it in error, please delete it immediately
and notify the sender by e-mail. In such a case, reading, reproducing,
printing or further dissemination of this e-mail or its contents is strictly
prohibited and may be unlawful.
Intec Telecom Systems PLC does not represent or warrant that an attachment
hereto is free from computer viruses or other defects. The opinions
expressed in this e-mail and any attachments may be those of the author and
are not necessarily those of Intec Telecom Systems PLC.
_______________________________________________
sunmanagers mailing list
sunmanagers@sunmanagers.org
http://www.sunmanagers.org/mailman/listinfo/sunmanagers



This archive was generated by hypermail 2.1.7 : Wed Apr 09 2008 - 23:40:24 EDT