home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!destroyer!sol.ctr.columbia.edu!ursa!RABINOWITZ@bear.com
- From: RABINOWITZ@bear.com (Ari Rabinowitz)
- Newsgroups: vmsnet.networks.tcp-ip.multinet
- Subject: What does an account need for the NFS Server to work?
- Message-ID: <29642@ursa.UUCP>
- Date: 13 Aug 92 20:18:27 GMT
- Sender: news@ursa.UUCP
- Organization: Bear Stearns & Co.
- Lines: 60
- X-News-Reader: VMS NEWS 1.20
-
- Hi all,
-
- I am attempting to set up the NFS server on our Vax to allow access
- from a group of suns. The sun users do not now have accounts on our
- vaxes, and we don't want them to have accounts. We do, however, have to
- create accounts so that the NFS server can map their UID/GID's to a
- valid UIC on our Vax. We are doing this by creating dummy accounts on
- the Vax, and I want to know what these dummy accounts need in order to
- allow the NFS server to work.
-
- We had previously planned to use rcp for this, but Ken informed me via
- Email that the Multinet server does not distinguish between a remote rcp
- command and a remote rshell command, so if we allowed them to copy, they
- could run any command on the Vax. We aren't comfortable with that, so
- we are trying this route. All suggestions will be greatfully accepted.
-
- This is how we have the accounts set up now, will it work?
-
- Username: ULTRIX_NFS12 Owner: ULTRIX NFS FILE TRANSFER
- Account: ULTRIX UIC: [213,14] ([ULTRIX_NFS12])
- CLI: DCL Tables: DCLTABLES
- Default: NL:[ULTRIX_NFS12]
- LGICMD: NL:
- Flags: Restricted DisPwdDic
- Primary days: Mon Tue Wed Thu Fri
- Secondary days: Sat Sun
- Primary 000000000011111111112222 Secondary 000000000011111111112222
- Day Hours 012345678901234567890123 Day Hours 012345678901234567890123
- Network: ----- No access ------ ----- No access ------
- Batch: ----- No access ------ ----- No access ------
- Local: ----- No access ------ ----- No access ------
- Dialup: ----- No access ------ ----- No access ------
- Remote: ----- No access ------ ----- No access ------
- Expiration: (none) Pwdminimum: 6 Login Fails: 0
- Pwdlifetime: 180 00:00 Pwdchange: 13-AUG-1992 15:11
- Last Login: (none) (interactive), (none) (non-interactive)
- Maxjobs: 1 Fillm: 75 Bytlm: 40000
- Maxacctjobs: 0 Shrfillm: 0 Pbytlm: 0
- Maxdetach: 0 BIOlm: 1024 JTquota: 1024
- Prclm: 2 DIOlm: 1024 WSdef: 1600
- Prio: 6 ASTlm: 50 WSquo: 2000
- Queprio: 0 TQElm: 500 WSextent: 6000
- CPU: (none) Enqlm: 600 Pgflquo: 40000
- Authorized Privileges:
- TMPMBX NETMBX
- Default Privileges:
- TMPMBX NETMBX
-
- Can we restrict it more than this? Does it make any difference? As you
- can probably tell, we don't want those sun users doing anything except
- accessing the exported directories.
-
- What other security concerns, if any, should we have?
-
- Thanks,
- Ari
-
- Ari Rabinowitz rabinowitz@bear.com for VMS and personal mail
- WorkStation Administrator ari@bear.com for sun/HP Un*x mail
- Bear Stearns
-