NIS/YP and /etc/master.passwd

I'm trying to get a bundle of servers (10.4.10 Server) configured to use NIS for their local authentication. This is required in order for myself and our other unix admins to gain access to the host in a standard way.
I can get the machine to authenticate of NIS (using the Directory Services app), however it then lets ALL users log in.
I need to make the standard +@netgroup:::::: directives work in /etc/passwd or /etc/master.passwd - however it appears that the OS is completely ignoring these files - despite having ticked the box for "Use BSD local files (/etc) for authentication" in the NIS configuration window.
I've tried restricting access with various combinations of the BSD Local Files and NIS Domain check boxes being checked.
If "Use NIS domain for authentication" is checked, then all users can log in (via ssh). If not, no users can. So I figure I should not use NIS for auth, but instead use local files and then specify that certain netgroups are allowed in. This also does not work.
On all my other unix hosts, we use something like this in /etc/passwd:
+sysadminnetgroup::::::
+::::::/bin/false
Thus creating the effect of allowing all our sys admins, and denying all other users. This works brilliantly, since we do want some users to access certain hosts (i.e. a couple of public hosts for the students programming in C) - but don't want them accessing everything. I can't just set their shell in NIS to /bin/false for this reason.
In short, how can I make my macs auth from NIS, but then restrict which users can actually log in?

Applying that same thing to the rest of the commands, and I finally got it done. Thanks so much.
It's weird that whatever she did to make it so this had to be done was fixed by just doing these commands.

Similar Messages

  • What does it mean?? /etc/master.passwd:No such file or directory fou

    So I finally got the Mac after 7 years of savings and when I installed FinalCut turned it off and then turned it back on this screen shows up stating
    /etc/master.passwd:No such file or directory found
    -sh-2.05b# CSRHIDTransitionDriver::stop
    IOBluetoothHCIController:: start Idle Timer Stopped
    I tried restarting I tried the PRAM and those don't work. What do I do to fix this situation. I am so sad that when I am ready to get to work on my computer this problem arises. Experts Please Help!!

    That is an odd error. I assume you are running OS 10.5. Pease open the Terminal application in the Utilities folder. Paste this command into Terminal:
    <pre style='font-family: Monaco;width: 90%; margin: auto; padding: 5px; border: 1px solid #B1B5B9; background: #EEEFF1;'>ls /etc/master.passwd</pre>
    then press "return". You should see something like this:
    -rw------- 1 root wheel 3088 Sep 23 15:37 /etc/master.passwd
    If you do not, then the file has somehow gone missing. If the file looks OK, it's possible your permissions need repairing, or that some daemon is not running.

  • Please Help!! /etc/master.passwd: no such file or directory.

    :( after I had restored my iMac with mount -uw /....
    I had lost everything even my etc and var folder, and after I had finished restore I started up my iMac with a black screen saying /etc/master.passwd: no such file or directory. -sh-2.05b. I had tried all everything I could do and nothing seem to happen, and also I don't have my install disk or any disc, would you please help me I won't to use my computer again.

    Boot to the Recovery HD partition, Command + r keys at startup, or the Online Internet recovery system, Command + Option/Alt + r keys at startup and hold them down until you see a globe on the screen and from the resulting Mac OS X Utilities screen that comes up with either select Reinstall Mac OS X.
    Not sure what you were trying to do, you aren't making that clear with the terminal command you supposedly used, but whatever it was fouled up your system and you will need to reinstall OS X or restore from a Time Machine backup.

  • Macbook pro says /etc/master.passwd: no such file or directory

    macbook pro says /etc/master.passwd: no such file or directory

    A quick search seems to point to the same answer:
    Your master password file is corrupt. You must reinstall OS X to fix it.
    I realise that doesn't help, but its the only answer I found.

  • EMac wont startup i get /etc/master.passwd: no such file on directory -sh-2.05b

    please help!! ive searched everywhere just to get a link to an article that people said worked but dosnt anymore!!! everytime i turn on computer i get that code, i deleated some files then restarted the computer to get it.... anything i can do??
    i think it was ios 10.4

    Hi, do you have the 104 Install Disc(s), if so bootup hold ing c key & do an A&I...
    About the Archive and Install feature, which can give you a new OS, yet preserve your files and settings if you have enough room on your HD...
    http://docs.info.apple.com/article.html?artnum=107120
    Just be sure to select Preserve Users & Settings.

  • Another start up issue - master passwd: invalid argument

    Hi,
    I am having problems starting my G4 Power Mac (OSX 10.4.6)
    When I switch my mac on, after the initial apple logo I am faced with a black screen and the following message:
    /etc/master.passwd: Invalid argument
    -sh: /etc/profile: Invalid argument
    -sh-2.05b#
    I have restarted in safe mode holding down shift and i arrive at the same screen.
    I have not changed my username or password recently or tampered with any system settings. I'm mystified. Hope somebody can help.
    Many thanks,
    Tom
    Power Mac G4   Mac OS X (10.4.6)  

    Maybe I should start a new post for this but since I performed what that article suggested I am now having some very unusual problems with my finder.
    I can not shut down or restart from the apple drop down menu.
    My dock has disappeared.
    I can not drag files on my desktop.
    Any thoughts greatly received.
    Tom

  • /etc/group and /etc/passwd corrupted

    My /etc/group and /etc/passwd (and possibly others) are corrupted (my silly error handling pacnew files). I tried restoring the backups (group- and similar) and also ran grpconv, pwdconv,, pwck without fixing things.  I've edited the files, using those in another machine as a template but no luck.
    Various commands (e.g. ssh) fail with the message:
                                     No user exists for uid 1000
    Before I give up and reinstall, is there any way I can restore things to how they should be?

    Thanks for replies. I can't recreate my user because it's already there. I can log in as ac without difficulty and do most things - just a few (mportant) fail.
    I don't understand why it keeps saying the user ac is uid 1000. After reading the wikis I think my /etc/group and /etc/passwd are correct. /etc/passwd has:
                ac:x:1000:100::/home/ac:/bin/bash
    and /etc/group has:
               users:x:100:ac
               ac:x:100:ac
    I'm not sure the last line should be there, but removing it doesn't help. The entries on a second machine are similar.
    I'll sleep on it to see if I think of something else to try in the morning, otherwise I'll have to reinstall tomorrow.

  • [SOLVED] Today's update of /etc/group, /etc/passwd and /etc/gshadow

    Hello,
    During the regular updates I received an update of /etc/groups. I wonder what I should do here, as there are some differences between the old file and the pacnew one. I suppose that when I use the command to add my user to a group, it gets written into this file. So, just recklessly moving the pacnew file in the place of the old one, will mess up all my groups, won't it?
    Then what should I do? All the entries in the pacnew file are also present in the old one, so I guess I could just delete the pacnew one and keep the old one. Am I right?
    EDIT: The same goes to /etc/passwd and /etc/gshadow.
    Last edited by Unia (2012-10-06 09:51:23)

    teateawhy wrote:
    If you had the uuid user before like me the uuid line in your own files is different from the pacnew file. You have to delete the uuid line near the bottom in your old file. Then insert the new uuid entry including the new number in the place near the top suggested by the pacnew file. Keep the other lines untouched, then save your changes and delete the pacnew files.
    Edit: On a system that has actually been modified from a default install the new files will for sure be different to the old ones.
    Thanks, teateawhy!  I currently have this listed in /etc/passwd:
    uuidd:x:998:998::/:/sbin/nologin
    And this is in the .pacnew file:
    uuidd:x:68:68:uuidd:/:/sbin/nologin
    So, I can just copy the entry from the .pacnew file, overwriting the old entry, right?
    What I don't understand is how the two numbers 998 representing the UID and GID can suddenly change to 68.  Shouldn't they have to correspond with some other reference or list of users/groups...?
    I'm sure it's fine to just replace the entry as you suggested, but I wondered if there was a way to double-check which uid/gid should be used?  It's not that I don't trust you, but I don't fully understand how these group/passwd files work and I'm trying to get my head round it all.
    Cheers,
    esuhl

  • Login Process & Security of /etc/passwd and /etc/shadow

    Guys,
    I have few questions, Please help me out.
    1. What is the Solaris 8 and Solaris 9 environment's boot files ?
    2. While Logging into Solaris Operating Environment , which is file is responsible for Login Process ? Through which file/command the username and password is cross checked with /etc/passwd and /etc/shadow ?
    3. We all know that /etc/passwd come with -rw-r--r-- permission and /etc/shadow comes with -r--------. I did a chmod and assigned 000 to both the files. But Still I am able to change the password for the normal user. And as a root I am still able to cat the contents of both the files.
    Help me understand these concepts.
    Thank you.
    Arut

    Sounds like you're very new to Solaris:
    1. What is the Solaris 8 and Solaris 9 environment's boot files ?/kernel/genunix is the primary boot file. The directory structure in /kernel is also boot related. /usr/kernel is also boot related.
    2. While Logging into Solaris Operating Environment , which is file is responsible for Login Process ? Through which file/command the username and password is cross checked with /etc/passwd and /etc/shadow ?Generally three files are related: /etc/passwd, /etc/shadow, and the program /bin/login. Some applications will process /etc/passwd and /etc/shadow on their own and bypass /bin/login - but for you're purposes this is a good general answer.
    As a minor example (and if I remember correctly), say someone uses telnet to log into a system. Telnet prompts for the login ID. Once input, it passes forks off /bin/login with the login ID. /bin/login reads the user password information from /etc/shadow and takes the first two bytes from the password field (column 2 using : as field seperator) which is the crypt salt (see crypt man page). /bin/login prompts for the password which the user inputs. /bin/login takes the user input password and the salt value read from /etc/shadow for that user and pushes it through crypt. It then takes the resultant crypt output and compares it against what it read from /etc/shadow - if they matches the user has input the right password. If not, it prompts the user again with a password prompt.
    3. We all know that /etc/passwd come with -rw-r--r-- permission and /etc/shadow comes with -r--------. I did a chmod and assigned 000 to both the files. But Still I am able to change the password for the normal user. And as a root I am still able to cat the contents of both the files.To change your password you run the passwd command. That command is SUID root - so for a short period of time you become root within the context of that process. Root is basically god mode and doesn't care about file access priviledges generally. So that fact that /etc/passwd and /etc/shadow have 000 file access permissions doesn't matter - root can still read and write to them.

  • How to recover /etc/passwd and /etc/shadow files

    hi
    Unfortunetly I have a big problem is that someone crash the /etc/passwd and /etc/shadow files from my running server, and my all users are not to able to login. so please can any one help me how to recover this files or any ideas for make these files...
    thanks
    Mohammed Tanvir

    Hello
    It is not working.Pla help me this bit critical
    Step followed
    01.Boot from the cdrom and mount root partision.
    02.Deleted the exsisting file /etc/passwd and /etc/shadow
    03.copy the opasswd and oshadow to the etc directory as passwd and shadow
    04.Umount the root partision
    05.Reeboot the system
    thanks
    Roshantha

  • [SOLVED] /etc/passwd and /etc/shadow -- pwck shows missing groups

    I recently found out about the pwck and grpck commands to check for errors/inconsistencies in the passwd, group, shadow and gshadow files...  grpck returns no errors, but pwck returns this:
    user 'avahi': no group 84
    user 'postgres': no group 88
    user 'ntp': no group 87
    pwck: no changes
    These are the relevant lines from /etc/passwd:
    avahi:x:84:84:Avahi daemon:/:/bin/false
    postgres:x:88:88:PostgreSQL user:/var/lib/postgres:/bin/bash
    ntp:x:87:87:Network Time Protocol:/var/lib/ntp:/bin/false
    There are lines for those users in /etc/shadow... but...  I'm not sure what I need to do to fix the problem.
    I think I understand enough, now, to maintain the files in future, but would anyone know I can fix this?
    Last edited by esuhl (2012-10-08 20:22:05)

    2ManyDogs wrote:I don't know how to fix the errors, but I'm really curious about why you decided to run those commands. Were you having a problem you thought might be ralated to groups and/or passwords? What are groups 84, 97, and 88?
    Ha!  Well... when I started using Arch I really didn't know much about Linux and I an update providing some .pacnew files (/etc/group, gshadow, passwd, shadow) and... well...  I don't know what I did, but I think it was probably not what I should have done(!).  I used grpck in the past and got no errors and it suddenly occurred to me today that there should be an equivalent for checking /etc/passwd... so that's why I just ran the commands now.  Everything seems to be working, however...
    I don't have an entry for groups 84, 87 and 88 in my /etc/group file...  Hmmm...
    I tried running this command to find any files associated with that group, but only get the following:
    [root@i7pc tim]# find / -gid 88
    find: `/run/user/1000/gvfs': Permission denied
    find: `/proc/1806/task/1806/fd/5': No such file or directory
    find: `/proc/1806/task/1806/fdinfo/5': No such file or directory
    find: `/proc/1806/fd/5': No such file or directory
    find: `/proc/1806/fdinfo/5': No such file or directory
    I get similar output for the other groups, so... can I just delete them from /etc/passwd and /etc/shadow?
    I notice I have the avahi package installed, however, and group 84 relates to user 'avahi'... so...  surely I need the avahi user...?
    Last edited by esuhl (2012-10-07 23:09:30)

  • How are attribute and text master data tables linked in SAP R/3?

    Hello,
    how are attribute and text master data tables linked in SAP R/3?
    Most tables with attribute master data like T001 for company codes,
    have a text master data table T001T (add "T" to table name).
    When looking at the content of table T001 via transaction se11,
    the text are automatically joined.
    But for some tables there is no "T"-table (e.g. table TVBUR for sales offices
    has no text table TVBURT), but in se11 you get texts. There is an address
    link in TVBUR, but the Name1, etc. are empty.
    a) Where are the text stored?
    b) How does the system know of the link?
    Hope someone can help!
    Best regards
    Thomas

    Hi Thomas
    The master and text table are not linked by name, of course, if you see the text table, it has the same key fields of master table, only it has the field key spras and the field for description.
    The link beetween the tables is done by foreign key: if you check the text table TVKBT u need to see how the foreign key for field VKBUR is done:
    -> Foreing key with table TVBUR
    -> Foreing key field type -> KEY FIELD FOR A TEXT TABLE
    ->Cardinality-> 1-:CN
    It's very important the attribute sets for Foreing key field type, if it's KEY FIELD FOR A TEXT TABLE, it'll mean the table is a text table: i.e. that mean the master table is a check table for the text table, where the foreign key type is for text table.
    U can find out the text table of master table by SE11: GoTo->Text Table
    U can fined some information in table DD08L.
    Max

  • Working on IDOC OUTBOUND FOR Vendor Master and Customer Master

    Hi Group,
    I need to create IDOC's for Vendor master and customer master using ALE. Whenever they create vendor/customer or changes to vendor/customer should create IDOC's.
    Can anyone please help me out how to proceed? I know that we can use CREMAS/DEBMAS and CREMAS04/CREMAS...But I would like to know how to use those.
    Thank-You,
    Venky

    Hi Sai,
    Welcome to group.
    Related to CREMAS/DEBMAS, for your situation, you can use the change pointers.  With this, when ever there is an change/create, it will create an entry in CDHDR & CDPOS and based on that it will create the IDOCs for these.
    Activate the change pointers for these message types and run the application RBDMIDOC periodically (whenever you want).  This application will create the IDOCs based on your entries.
    To activate the change pointers, the TCODEs are
    BD50 Checking change pointer is activated for Message Type
    BD52 Checking which fields are configured change pointer to create.  (please make sure, an entry will exist in BDCP table)
    I hope you know the remaining configuration related to partner profile entries (WE20) i.e. to which system you want to send the idocs and Inbound or Outbound etc.
    Let me know if you need further info.
    shylesh

  • Proposal of partner function and related master record in sales order

    Hi Gurus,
    As we know, a partner determination procedure is used to propose partner functions and the master data tied to them in the sales order.
    I need to confirm the following if understanding is correct:
    1. 1st a customer master record is entered with all the partner functions, say, SP SH PY BP and 9E (PE partner type).
    The respective master record values like who is the SP SH PY BP and 9E are specified in the partner function tab also.
    This customer master is assigned to a account group.
    2. a Partner determination procedure is created and the same partner functions assigned to it.
    Next, this procedure is assigned to the account group.
    3. When I create an order for this customer, the sales order's partner function tab should automatically be populated with the partner functions and the respective master data value as defined in the customer master record.
    Questions:
    1. What if the partner determination procedure was not defined with 9E Partner function but the customer master record is?
    2. What if the customer master record was not defined with 9E but the partner procedure is?
    3. Why the partner procedure need to define the partner functions if its assigned to account group to which the customer master is assigned to already?
    4. If the partner function 9E is not proposed in the sales order, can user manually enter this partner function and the respective master record value in the sales order partner function tab?
    Have a great day!
    regards
    M Russo

    Hi,
    1. What if the partner determination procedure was not defined with 9E Partner function but the customer master record is?
    If the partner determination procedure is not defiend you can not maintain same in customer master the system will through you error message PE is missing.
    2. What if the customer master record was not defined with 9E but the partner procedure is?
    It depends how you want propose the same,
    According the function it behaves, you can make this field is mandatory if you want the same is to customer master
    3. Why the partner procedure need to define the partner functions if its assigned to account group to which the customer master is assigned to already?
    normally the standard partner procedure follows as it is SP SH BL PY Still if you want add some other partners(agent,employee,contact person...etc.) you can define the same in the procedure.
    4. If the partner function 9E is not proposed in the sales order, can user manually enter this partner function and the respective master record value in the sales order partner function tab?
    As you can refer the second point if you set as optional you can enter the same in customer master partner function tab.
    Hope this can helps,
    Thanks and Best Regards,
    Muralidharan S

  • Difference between Consolidation, Harmonization and Central master data man

    Hi ..Expertise
    Consolidation is use to identify duplicate records and merge them into one record.
    Harmonization is the process of pushing the new cleansed data back out to your partner systems.
    Central master data management means you create records within MDM and then you distribute (Syndicate) this centrally created data to your Remote Systems.
    My Question is her after Consolidation both Harmonization and Central master data management is doing the same thing i.e. sending the clean data to the other system. What is the difference between these two? Please explain me with an example or scenario..

    Hi Yugandhar,
    There are three basic scenarios that we follow in MDM:
    Data Consolidation
    Data Harmonization
    Central Master Data Management
    Consolidation :
    Conolidation (matching , normalization, cleansing) and storage of master data imported from client system. Entails capabilities to identify identical and similar objects spread across the local systems , build consolidated master data.
    Key Capabilities:
    1. Cleansing and de-duplication
    2. Data normalization including categorization and taxonomy management
    3. New interactive consolidation capabilities
    Data Harmonization :
    In case of Harmonization we generally aim at reaching high quality master data within heterogeneous system landscapes. Here the main focus is on ensuring high quality of master data within the connected systems and then distributing the Master data
    Key Capabilities:
    1. Automated synchronization of globally relevant master data information
    2. New Interactive distribution capabilities
    Central Master Data Management :
    In case of CMDM, it is not always the scenario that the Client wants to go for the above two scenario`s, but CMDM is always required as it helps us to maintain the Business data effectively and efficiently.
    After MDM is put into the business scenario all the operations related to the Master records are done in MDM only. For Eg: Creating a record, Deleting a record, Distributing a record etc.
    Now it is the work of CMDM to centrally maintain the data and check that no duplicate enteries can be created.
    And all the various systems that are attached to MDM gets the updates from CMDM with the help of Syndication Process or Distribution Process.
    Key Capabilities:
    1. Central creation and maintenance of data
    2. Ongoing master data quality
    Hope this would be helpful !!!!!!!!!
    Regards,
    Parul

Maybe you are looking for

  • Office 2013 SP1 fails with code 17302 - SCCM 2007 R2

    Hi, I am trying to deploy Office 2013, along with SP1, in the following order: 1. Prompt to close all office apps and continue (vbs) 2. Installation of Office 2013, using modified msp. 3. Restart 4. Installation of SP1 with command line /passive /nor

  • SPEED SPEED SPEED

    hi all. how do i get my mac to run faster? all programmes run slow. i am a graphic designer so i have Adobe CS2 quark etc.. PLEASE HELP dwhuggs!

  • Pro*C installed under ORACLE_HOME different from that of the RDBMS???

    I have Oracle 10g r2 installed on a RHAS4 server. I installed Oracle developer suite 10.1 on this server. In the installation procedures, there are specific instructions to not install it under the ORACLE_HOME for an existing database installation. O

  • Problem when getting from truststore

    Hi, I have a problem that when using SSL and getting trusted cert from truststore. When using System.setProperty("javax.net.debug", "all");, although the cert is not in valid date, I can get see that the cert is added like following when using jdk1.4

  • SP16 Theme Editor and Themes

    Hi, Where i can find SP16 Theme Editor and Themes. I couldn't found SAP Note 854870 which is suppose to have link to downlod Theme Editor for different SP. Thanks Rahul