Auditing System Users - Novell OPEN ENTERPRISE SERVER - PLANNING AND IMPLEMENTATION GUIDE 12-2010 Implementation Manual

Planning and implementation guide
Hide thumbs Also See for OPEN ENTERPRISE SERVER - PLANNING AND IMPLEMENTATION GUIDE 12-2010:
Table of Contents

Advertisement

System Group Purposes
Table I-9
System User or Group Name Associated Service
Iprint (POSIX)
iprintgrp (eDirectory)
ncsgroup
novell_nogroup
novlxtier
server_name-W-
SambaUserGroup
shadow
www
I.9 Auditing System Users
It is the nature of the Linux operating system and the POSIX security model that the
access to all system information stored on the local server. Due to this fact, some organizations
choose to monitor the activities of privileged users.
282 OES 2 SP3: Planning and Implementation Guide
Purpose
iPrint
The iPrint daemons use the group ID (gid) of this
group to run.
If iPrint is moved to NSS, the iprintgrp group is
created in eDirectory.
NCS
ncsclient
CIMOM
This group is created by CIMOM but is not currently
used.
XTier
The XTier daemons use the group id (gid) of this
group to run.
Apache (wwwrun) is a group member because it
needs XTier socket access.
When NSS is installed on the Linux server, this group
is removed from the local system and created in
eDirectory. This is required because members of this
group must have access to NSS data, and all NSS
access is controlled through eDirectory.
Samba (Novell)
All users granted Samba access are originally
assigned to this group, which disables SSH access
for them on the server. For more information, see
"The Samba connection:" on page
QuickFinder
Used by QuickFinder and other Web services.
Apache
Apache (wwwrun) and tomcat (novlwww) use the
group ID (gid) of this group to run.
Tomcat
QuickFinder requires that all users who manage the
QuickFinder
service (including the eDirectory Admin user) belong
to this group.
User
access to an Apache domain socket.
When NSS is installed on the Linux server, this group
is removed from the local system and created in
eDirectory. This is required because members of this
group must have access to NSS data, and all NSS
access is controlled through eDirectory.
is a member of this group.
is in the group because it needs
novlxsrvd
92.
user has
root

Advertisement

Table of Contents
loading

This manual is also suitable for:

Open enterprise server 2 sp3

Table of Contents