LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Other *NIX Forums > AIX
User Name
Password
AIX This forum is for the discussion of IBM AIX.
eserver and other IBM related questions are also on topic.

Notices


Reply
  Search this Thread
Old 11-02-2009, 01:48 AM   #1
antonis_m
LQ Newbie
 
Registered: Nov 2009
Location: Cyprus
Distribution: Ubuntu
Posts: 2

Rep: Reputation: 0
How to sychronize user accounts - All time monitor


Hi all,

I'm not sure if what i need is possible. I'm trying to sycronize user accounts between the live site and DR site. Unfortunately we do not use any of the well known effective apps (LDAP, Active Directory). We have about 3000 users working for the bank which are required to change passwd every 10 days. How can i make sure that user accounts will stay sychronized at any time. Cron @ every 5 min is my best option? is there a way to monitor passwd file at all time and when the command passwd is called my script will act accortingly?

I tried to use a custom passwd command that will overwrite the /bin/passwd command to suit my needs. (Dissaster!!! it didn't work)

So i'm left with a custom deamon that calls rsync all time and if there is a change it will update. (To much I/O) and i'm not sure what the side effects will be.

Do you know of any alternative solution?

Thanks in advance.
 
Old 11-02-2009, 05:56 AM   #2
cantab
Member
 
Registered: Oct 2009
Location: England
Distribution: Kubuntu, Ubuntu, Debian, Proxmox.
Posts: 553

Rep: Reputation: 115Reputation: 115
I know nothing about AIX, but I have a less-technical idea: can you tell the users to run a different command to change their password? Then you make that command do whatever you need it to do.
 
Old 11-03-2009, 03:24 PM   #3
looseCannon
Member
 
Registered: Dec 2003
Location: Little Rock, AR
Distribution: Fedora Core 2, AIX, HP-UX, Solaris, Whitebox
Posts: 193

Rep: Reputation: 31
There are 5 files that contain all of the information about user accounds in AIX. You **could** copy the files to the DR system on a regular basis to keep the accounts in synch. I've done this for a couple of systems before. Keep in mind, that if this hiccups just a little bit there is potential to have a system you cannot log into so you will want to make this as bullet proof as possible.

The 5 files are

/etc/group
/etc/passwd
/etc/security/group
/etc/security/passwd
/etc/security/user

!!!!!MAKE BACKUPS, MAKE BACKUPS, MAKE BACKUPS, MAKE BACKUPS, MAKE BACKUPS!!!!!
 
Old 11-04-2009, 12:55 AM   #4
antonis_m
LQ Newbie
 
Registered: Nov 2009
Location: Cyprus
Distribution: Ubuntu
Posts: 2

Original Poster
Rep: Reputation: 0
Thanks looseCannon

Seems that this is my best option.

I tried it up and it works fine when i include all the files you list.
First time i tried it i couldn't log on to the system (Just like you said!!). Offcourse i had a backup even though i was testing it on the development machine. I think i will follow this solution.

I'm thinking of some alternatives that i have no expirience with.

1. A NIS server (also known as yellow pages). Sounds like a good solution but i'm not sure about security and if it can handle so many users (3000).

2. Kerberos ???

Thanks again appriciate all the help
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Difference betwwen : Locked User Account & Disabled User Accounts in Linux ? avklinux Linux - Security 1 02-04-2009 02:30 PM
Kpilot does not sychronize jayhel Arch 0 11-21-2006 10:16 PM
how to monitor all accounts run all commands from login to present? BRAHmS Solaris / OpenSolaris 4 08-20-2004 12:00 PM
sychronize samba and unix password at user creation JohanLingen Programming 1 10-10-2003 07:34 PM
samba and 2 accounts logins at the same time problem hugosoto Linux - Networking 1 10-23-2002 07:46 PM

LinuxQuestions.org > Forums > Other *NIX Forums > AIX

All times are GMT -5. The time now is 05:15 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration