Do the following:
1. Create one proxy user object per OES server (preferably in the same container as the server)
and set the password.
2. Use this proxy user and password as the proxy user for all the services on that particular OES
server.
I.5.5 Individual Proxy User Per-Server-Per-Service
This is the installation default if the Common Proxy User is not utilized as explained in
"Options for Limiting the Number of Proxy Users," on page
I.6 Proxy Users and Domain Services for
Windows
Proxy users are not used in DSfW.
The Services part of the Trusted Computed Base has the rights to read users' supplemental
credentials for authentication. A separate Kerberos process reads user passwords and performs the
authentication. Another event handler in eDirectory creates the supplemental credentials for the user
whenever the password is changed for that user.
However, the DNS Proxy User is closely associated with DSfW and can leverage the Common
Proxy User available in SP3.
I.7 System Users
SLES and OES create system users on the local Linux system to provide user IDs (uids) to service
processes. These users have rights to local files, such as configuration files.
The services that rely on system users do not have passwords because they don't need to log in.
They simply use their associated user IDs.
When NSS is installed, some of these users are moved to eDirectory and LUM enabled. This is done
to provide access to NSS data, to keep the user IDs the same across multiple servers, and to facilitate
clustering and shared volumes.
Table I-2
lists the various system users that are used by OES services.
System User Purposes
Table I-8
System User or
Group Name
arkuser
280 OES 2 SP3: Planning and Implementation Guide
Associated Service
Purpose
Archive and
The service uses PostgreSQL as its metadata store, and
Versioning
PostgreSQL must run as a low-privileged user.
Services
arkuser
275.
is that low-privileged user.
Table I-6,
Need help?
Do you have a question about the OPEN ENTERPRISE SERVER - PLANNING AND IMPLEMENTATION GUIDE 12-2010 and is the answer not in the manual?
Questions and answers