LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Other *NIX Forums > Solaris / OpenSolaris
User Name
Password
Solaris / OpenSolaris This forum is for the discussion of Solaris, OpenSolaris, OpenIndiana, and illumos.
General Sun, SunOS and Sparc related questions also go here. Any Solaris fork or distribution is welcome.

Notices


Reply
  Search this Thread
Old 12-15-2009, 12:30 AM   #1
LinuxLover
Member
 
Registered: Feb 2004
Distribution: Centos 7 x86_64 , Rocky Linux 8 (aarch64)
Posts: 196

Rep: Reputation: 32
RBAC role with Ldap user


I am using openldap for user authentication on Solaris 10 machines.

Now I want to use rbac when I create the role in system it create succefully.But when I try to add some user It give me error message.

Code:
-bash-3.00# usermod -R operrole ktahir01
UX: usermod: ERROR: ktahir01 is not a local user.



How can I add ldap users in rbac role?
 
Old 12-15-2009, 02:07 AM   #2
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
you'd change the group on the ldap server, not the local machine.
 
Old 12-15-2009, 02:23 AM   #3
LinuxLover
Member
 
Registered: Feb 2004
Distribution: Centos 7 x86_64 , Rocky Linux 8 (aarch64)
Posts: 196

Original Poster
Rep: Reputation: 32
Thanks for you reply,

Sir, can you elabroate litte bit in detail.
How can I add this in ldap.

You mean I need to create role on ldap etc ?
 
Old 12-15-2009, 02:33 AM   #4
jlliagre
Moderator
 
Registered: Feb 2004
Location: Outside Paris
Distribution: Solaris 11.4, Oracle Linux, Mint, Debian/WSL
Posts: 9,789

Rep: Reputation: 492Reputation: 492Reputation: 492Reputation: 492Reputation: 492
The message (and usermod documentation) is rightly telling this command is only for local users, i.e. those defined in /etc/passwd.
For ldap users, the SolarisAuthAttr container should be updated instead.

Last edited by jlliagre; 12-15-2009 at 02:34 AM.
 
Old 12-15-2009, 11:13 AM   #5
LinuxLover
Member
 
Registered: Feb 2004
Distribution: Centos 7 x86_64 , Rocky Linux 8 (aarch64)
Posts: 196

Original Poster
Rep: Reputation: 32
Thanks for you reply,

Quote:
For ldap users, the SolarisAuthAttr container should be updated instead

Sir where is that SolarisAuthAttr container ?
 
Old 12-15-2009, 02:59 PM   #6
jlliagre
Moderator
 
Registered: Feb 2004
Location: Outside Paris
Distribution: Solaris 11.4, Oracle Linux, Mint, Debian/WSL
Posts: 9,789

Rep: Reputation: 492Reputation: 492Reputation: 492Reputation: 492Reputation: 492
There should be a top branch named ou=SolarisAuthAttr that will contain these user settings on your directory server.
The auth_attr table should also be set to be searched in ldap in /etc/nsswitch.conf.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
RBAC related question.. saagar Solaris / OpenSolaris 2 07-20-2009 09:06 PM
LDAP server not starting as user LDAP klnasveschuk Fedora 1 02-15-2007 04:49 AM
rbac not OK AbrahamJose Solaris / OpenSolaris 4 11-20-2006 10:27 PM
Rbac linuxtesting2 Solaris / OpenSolaris 1 08-23-2006 04:57 AM

LinuxQuestions.org > Forums > Other *NIX Forums > Solaris / OpenSolaris

All times are GMT -5. The time now is 11:30 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration