LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 12-22-2004, 10:11 AM   #1
gdl
LQ Newbie
 
Registered: Dec 2004
Location: MI
Distribution: RH9
Posts: 3

Rep: Reputation: 0
Exclamation NIS login/lockout


I'm a newbie to Linux, but not to Unix/Solaris, so maybe I'm just confused about where
things go, but I've been struggling almost two weeks, and all I've done is make matters worse.
Here's what's going on:

I'm running RH9 (2.4.20-8), NIS on two servers: kidrock and kwame. kidrock is the primary, and kwame is the secondary. There has been a problem with adding new users where after adding them on kidrock, the maps don't get pushed out correctly to kwame and the other clients. (I inherited this system!)

After having my id added and it working for a while, with a little more work, I've managed to lock myself out of NIS completely.

On the primary (kidrock), I:
1) modified /etc/yp.conf to list itself as the server
ypserver kidrock

2) set securenets to allow access to local host and all ips on network (we're
behind a firewall)

3) made the map, which was pushed to the client

On the client, restarted ypbind (but I have to have ypserv running because other clients point to kwame, and it doesn't work without it on for some reason).

When I run yptest for my user id, all the test pass, and I'm in the list. After restarting ypbind on my local machine, when I try to ssh to any machine (which I was logged in to before I started messing with stuff), I get rejected because the system doesn't know who I am. In /var/log/messages file
I get this:

Dec 22 09:50:32 kwame ypserv[18896]: refused connect from 192.168.0.121:37579 to procedure ypproc_all
Dec 22 09:51:52 kwame ypserv[18896]: refused connect from 192.168.0.121:33074 to procedure ypproc_match
Dec 22 09:51:53 kwame ypserv[18896]: refused connect from 192.168.0.121:37581 to procedure ypproc_all

(121 is my local machine). All of the other users in the database can log in via NIS fine, but not my user id. Portmap is running correctly, hosts.allow allows all connection from the network. I'm pulling my hair out! (What little I have!) Does anyone have something I can look at? Also, will this allow me to add new users and push them out correctly?

Thanks!
 
Old 12-22-2004, 11:18 AM   #2
gdl
LQ Newbie
 
Registered: Dec 2004
Location: MI
Distribution: RH9
Posts: 3

Original Poster
Rep: Reputation: 0
One other item:

Although the users can log into their own machines, they can not ssh to any other machine.
And, there's the error when opening a terminal that says:

id: cannot find name for user ID <IDNUM>

for all users. This is just frustrating!
 
Old 01-03-2005, 08:39 AM   #3
gdl
LQ Newbie
 
Registered: Dec 2004
Location: MI
Distribution: RH9
Posts: 3

Original Poster
Rep: Reputation: 0
Just to follow up for future people looking for this problem:

I was able to solve this problem (temporarily at least) by changing the ypserv.conf file.
The "security" entry field which was set to "port" by default, was changed to "none" to
always allow access regardless of which port number. This worked almost instantly.
Why did it ever work before and not now, I don't know. Since we're on a private side
of a firewall, I'm not as concerned about this security issue for now. I need to check
to see which port number is being used and see if I can set it to something less than
1024 so that this will work as it's supposed to.

Any way, it works now!
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
NIS login zapperabhi Linux - Networking 0 02-21-2004 09:39 PM
NIS Login zapperabhi Linux - Software 0 02-19-2004 09:58 PM
Login Lockout John Manion Linux - Newbie 1 11-16-2003 12:53 AM
login failed with NIS (YP) davidsh Linux - General 0 07-09-2002 11:49 AM
NIS Login kenw Linux - Networking 2 12-14-2001 04:24 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 07:07 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration