home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.sys.hp
- Path: sparky!uunet!mcsun!sunic!ugle.unit.no!Steinar.Haug
- From: Steinar.Haug@delab.sintef.no (Steinar Haug)
- Subject: Re: Sun Vs. HP system administration
- In-Reply-To: alek@spatial.com's message of Wed, 26 Aug 1992 05:27:41 GMT
- Message-ID: <STEINAR.HAUG.92Aug26161118@delab.sintef.no>
- Sender: news@ugle.unit.no (NetNews Administrator)
- Organization: SINTEF DELAB, Trondheim, Norway.
- References: <9208251944.AA15570@gadget.evb.com> <1992Aug26.052741.24845@spatial.com>
- Date: 26 Aug 92 16:11:18
- Lines: 32
-
- In article <1992Aug26.052741.24845@spatial.com> alek@spatial.com writes:
- >>* Can I set up my HP as a client of Solbourne (yellow pages) ?
- >> I think the answer is YES but how hard is it to get this
- >> setup working.
- >Yes - see /etc/netnfsrc - it's pretty trivial. BTW, all of my YP/NIS Slaves
- >are Suns, so I've only test the YP client side of the HP's.
-
- We have used 9000/400 running 8.0 (and earlier 7.05) as YP/NIS slave servers.
- Seems to work just fine, but there are security problems:
-
- 1. HP's YP implementation doesn't have (the equivalent of) the latest security
- patch from Sun (100482-02). Thus anybody who can guess your YP domainname can
- dump your passwd map, and find your passwords (by using crack or similar
- programs) at their leisure. Sun's patch enables you to control which hosts
- (which IP addresses) are allowed to access your YP servers.
-
- 2. As far as I know HP hasn't picked up Sun's ypbind modifications. This means
- that the ypbind process on your HP systems can be made to rebind to another
- YP server *from the outside* (somebody out in the big IP world doing an RPC
- call to your ypbind process). ypbind on Suns (as of around SunOS 4.1 or so)
- will refuse this - unless explicitly allowed through startup options.
-
- So, because of point 1 above, we have shut down all our HP slave servers,
- and now use only Suns as YP servers.
-
- I must admit that I'm really looking forward to HP-UX 9.0, in the hopes that
- HP will have addressed at least some of these problems...
-
- Steinar Haug, system/networks administrator
- SINTEF DELAB, University of Trondheim, NORWAY
- Email: Steinar.Haug@delab.sintef.no,
- sthaug@idt.unit.no, steinar@tosca.er.sintef.no
-