Implementing Your Proxy User Plan - Novell OPEN ENTERPRISE SERVER - PLANNING AND IMPLEMENTATION GUIDE 12-2010 Implementation Manual

Planning and implementation guide
Hide thumbs Also See for OPEN ENTERPRISE SERVER - PLANNING AND IMPLEMENTATION GUIDE 12-2010:
Table of Contents

Advertisement

Such policies create complications for the proxy user design. Proxy user passwords are stored on the
local system to enable the OES services to log in to eDirectory. Every time a password change is
forced in eDirectory, services stop working until the password is sychronized on the server.
These problems can be avoided by:
Not assigning proxy users a password policy that enforces password expiration.
Not using real user credentials for proxy users. See
Proxy User" on page
If password expiration policies cannot be avoided, or a security policy dictates that proxy user
passwords must be changed periodically, we strongly urge you to implement an automatic password
change routine as explained
Otherwise you should probably do the following.
Ensure that the responsible administrator knows or has a record of each proxy user's password
and is aware of when each password expires.
Before passwords expire, change them in eDirectory and reset them on the server. See the
information in
Changing Proxy Passwords Automatically
You can configure your server so that your proxy users are regularly assigned new system-generated
passwords by doing the following:
1 Open the file
2 List the FQDN of each proxy user on the server that you want to automatic password
management set up for.
For example you might insert the following entries:
cn=OESCommonProxyUser_myserver.o=novell
cn=myproxy.o=novell
3 Save the file.
4 Enter the following commands:
cd /opt/novell/proxymgmt/bin
change_proxy_pwd.sh -A Yes
I.5 Implementing Your Proxy User Plan
The proxy users in OES can be configured at different levels within eDirectory, depending on your
needs.
IMPORTANT: If you plan to use the Common Proxy User, you can ignore this note.
The brief instructions that follow assume that you are installing into an existing tree and not
leverageing the Common Proxy User.
For new trees, you will need to install and configure eDirectory on the first server without
configuring any other OES services.
278 OES 2 SP3: Planning and Implementation Guide
274.
in"Changing Proxy Passwords Automatically" on page
Table
I-7.
/etc/opt/novell/proxymgmt/proxy_users.conf
"Avoid Assigning an Admin User As a
in a text editor.
278.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Open enterprise server 2 sp3

Table of Contents