home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.sys.sgi
- Path: sparky!uunet!caen!U.Chem.LSA.UMich.EDU!hillig
- From: hillig@U.Chem.LSA.UMich.EDU (Kurt Hillig)
- Subject: Re: Install problem
- Message-ID: <-YF=J_@engin.umich.edu>
- Date: Tue, 17 Nov 92 09:43:07 EST
- Organization: Department of Chemistry, University of Michigan, Ann Arbor
- References: <YFF=#z@engin.umich.edu> <srp.721956667@cgl.ucsf.edu> <1992Nov17.014909.12730@leland.Stanford.EDU>
- Keywords: Install CDROM remote
- Nntp-Posting-Host: u.chem.lsa.umich.edu
- Lines: 62
-
- In article <1992Nov17.014909.12730@leland.Stanford.EDU> dhinds@leland.Stanford.EDU (David Hinds) writes:
- >In article <srp.721956667@cgl.ucsf.edu> srp@cgl.ucsf.edu (Scott R. Presnell) writes:
- > >hillig@U.Chem.LSA.UMich.EDU (Kurt Hillig) writes:
- > >
- > > [deleted...]
- > >
- > > > When I run inst on a remote machine, I can't get it to communicate with
- > > > the 360 server:
- > >
- > >1) Are all the client machines in /etc/hosts.equiv on uranium?
- > >2) or is the uranium:~guest/.rhosts file set correctly?
- >
- >I think this is the real problem.
- >
- > >3) It is my recollection that the remote user of inst under 3.3.X was
- > >"inst," consequently the .rhosts file had to let "inst" use the login..
- > >i.e. the <server>:~guest/.rhosts file had:
- > >
- > > hostname1 inst
- > > hostname2 inst
- >
- >It seems to do it as user 'guest', not 'inst'.
- >
- > - David Hinds
- > dhinds@allegro.stanford.edu
-
- Bingo! I had used "inst" in the ~guest/.rhosts file - which I believe
- was a "leftover" from 3.3.3....
-
- But this screws up the security, doesn't it? I disable the guest account
- on the server because I don't want people getting on it without a password,
- but I can't keep the remote users from leaving guest unprotected. If I
- have to specify "guest" instead of "inst" in the server's .rhosts file, then
- guest users on the remote machine still have passwordless access to the server.
-
- Is my memory right that inst used to use the username "inst"? If so, what's
- the rationale for changing this?
-
- Looking at section 3.3 (p. 3-6) of the Iris Software installation Guide, they
- suggest setting up an "instuser" account on the server, and in its home
- directory's .rhosts file adding lines of the form:
-
- client.internet.name instuser
-
- But this doesn't work either. Since "instuser" isn't defined on the client
- but only on the server, inst still can't get in unless the instuser account
- has no password. And creating an instuser account on the client doesn't
- help since inst tries to connect to the server as "guest", not as "instuser".
-
- So, from my point of view, it looks like the documentation is wrong -
- at least when I follow the directions it doesn't work - and inst's use
- of "guest" rather than "inst" leaves a security hole that I can't easily
- plug without upsetting some of my users (some of whom just love having
- a passwordless guest account!).
-
- Am I still missing something?
-
- --
- Kurt Hillig
- Dept. of Chemistry I always tell the khillig@umich.edu
- University of Michigan absolute truth Telephone (313)747-2867
- Ann Arbor, MI 48109-1055 as I see it. hillig@chem.lsa.umich.edu
-