home *** CD-ROM | disk | FTP | other *** search
- Xref: sparky comp.sys.sgi.admin:14 comp.security.misc:2263
- Newsgroups: comp.sys.sgi.admin,comp.security.misc
- Path: sparky!uunet!mcsun!sun4nl!fwi.uva.nl!casper
- From: casper@fwi.uva.nl (Casper H.S. Dik)
- Subject: Re: [Q] C2 security or Shadow...
- Message-ID: <1992Dec15.133254.9160@fwi.uva.nl>
- Keywords: C2, NIS, security
- Sender: news@fwi.uva.nl
- Nntp-Posting-Host: adam.fwi.uva.nl
- Organization: FWI, University of Amsterdam
- References: <1992Dec15.062659.7909@worak.kaist.ac.kr>
- Date: Tue, 15 Dec 1992 13:32:54 GMT
- Lines: 25
-
- jwjung@kaist.ac.kr (Jung Joo-won) writes:
-
- >Does anybody know about C2 security on SGI?
- >(or shadow password mechanism which can go along with NIS...)
-
- >We have 4 workstations and they are tightly coupled with NFS and NIS(YP).
- >The server(master) machine is Iris 4D, and clients are Sun4 and Mips.
- >But, as you know, the NIS without C2 has great security hole.
- >(If you got the domain name, you could get anything from that domain.)
-
- Why do you think that NIS with C2 is more secure?
- You have three possibilities:
-
- - make only Sun servers and install patch #100482-0x (x >= 2)
- or
- - filter all packets in the range 0-1024 that are incoming.
- or
- - make the NIS servers totally inaccessible from the outside
-
- There are no shadow password mechanisms that work between vendors
- with distributed password databases and work out of the box.
-
- I hope that NIS+ will make it to other vendors.
-
- Casper
-