ENHANCED SECURITY ULTRIX 4.1

Dave Brillhart dcb at dave.mis.semi.harris.com
Thu Mar 7 07:21:10 AEST 1991


This weekend, we are are planning to enable the ENHANCED security features
on our  2 5830's, a 5820, and a 5500.  Currently we are only using the
standard BSD security [features?] with a seperate host file and passwd file
on each (acutally 2 are trying to use YP). We are also planning to run BIND/
Hesiod and Kerberos in an effort to use a secure single host file and single
user authorization file for all systems.

We've run across a few gotchas before this weekend, like:

  o  All passwords become invalid and are non-recoverable.
  o  You cannot su to a priv account from a non-secure terminal.

I'm sure this will be an interesting weekend. If anyone can save me a
a few late night hours with tips/hints/suggestions/..., I'd appreciate it.

-- Dave Brillhart
     Harris Semiconductor
     Palm Bay, FL
     (407) 729-5430 



More information about the Comp.unix.ultrix mailing list