Great Circle Associates Firewalls
(April 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: SATAN on Solaris
From: matt @ uts . EDU . AU (Jas (Matthew K))
Date: Fri, 7 Apr 1995 11:04:19 +1000 (EST)
To: bdamicro!scott @ Sun . COM (Scott Abrutyn)
Cc: firewalls @ greatcircle . com, bret @ real . com, laurent @ grafnetix . qc . ca
In-reply-to: <9504061423 . AA17239 @ constellation . tolkein> from "Scott Abrutyn" at Apr 6, 95 11:23:57 am

Scott Abrutyn wrote this...
> 
> > Of course I am new to NIS+ (only went over it 1 day in a Slowaris SA class,
> > and havent used it since), so I could be mistaken..
> 
> misinformation fyi to the group,
> NIS+ only uses secure RPC mode if you configure it that way.  The default
> is not secure RPC.
this is direct from Name Services Administration Guide p94 (Solaris
2.4 documentaion).

2	Security level 2, the default, is the highest level of
	security currently provided by NIS+. It only authenticates
	requests that use DES credentials. Requests that use LOCAL
	credentials or none at all are assigned the access rights
	granted to the Nobody class. Requests that use invalid DES
	credentials are denied.

DES credentials use SecureRPC. The net effect of this minus all the
tech speak is that NIS+ uses SecureRPC by default, why else would you
give every user SecureRPC credentials for?

			Matt	
-- 
#!/bin/sh
echo '16i[q]sa[ln0=aln100%Pln100/snlbx]sbA0D3F204445524F42snlbxq'|dc;exit
Matthew Keenan   Systems Programmer   Information Technology Division
      University of Technology     Sydney Australia

It's nice to be in a position where people apologize because they
assume there's humor in your work, based on past experience,
but they're not sure where it is. -- Rob Pike


References:
Indexed By Date Previous: Re: SATAN on Solaris
From: matt @ uts . EDU . AU (Jas (Matthew K))
Next: Re: Detecting failures
From: "David P. Kemp" <dpkemp @ afterlife . ncsc . mil>
Indexed By Thread Previous: Re: SATAN on Solaris
From: bdamicro!scott @ Sun . COM (Scott Abrutyn)
Next: pc running SCO Open Server Network as firewall
From: cxh @ mba . com (Cynthia He)

Google
 
Search Internet Search www.greatcircle.com