Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

students failing to run keylogin get locked out of their accounts once global read access of the password table is disabled

Posted on 2003-10-21
4
Medium Priority
?
207 Views
Last Modified: 2013-12-27
I have inherited a set of nis+ systems, which I think has not been properly configured.  My own nis+ knowledge is not sufficient yet to solve the dilemma.

currently the passwd.org_dir table is gloabally readable - not a good thing.  If I restrict read access with a nistbladm -u  passwd=w-r passwd.org_dir then users who have neglected to run keylogin and change their passwords get locked out and I have to jump through hoops to change their password and then do a chkey -p

How can I tell if a user has run keylogin.  If I could generate a list of those who have not run keylogin I could figure out which accounts I have to fix.  FYI rather a lot, 4K+, of accounts..




0
Comment
Question by:AlastairNeil
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
4 Comments
 
LVL 18

Expert Comment

by:liddler
ID: 9597165
Can't you either tell all users to run keylogin or put it into everyone's .profile, so it run's the next time they login and the deletes itself from their .profile
i.e.
something like:
for file in ls /home/*/.profile
do
cp .profile .profile.sav
echo keylogin >> .profile
echo mv .profile.sav .profile >> .profile
done
0
 

Author Comment

by:AlastairNeil
ID: 9598993
There has been a message in the motd for weeks instructing everyone to keylogin and change passwords, however students being students a percentage of them will ignore it and a percentage of them will not access their account until they actually need to work on a project.

Putting keylogin in the .profile does not really address my problem, I could easily wrap keylogin in a script that logs the uid of those running it, but I want to find those that have already run it, or more importantly those that have not run it yet.
0
 

Accepted Solution

by:
modulo earned 0 total points
ID: 10850668
PAQed, with points refunded (100)

modulo
Community Support Moderator
0

Featured Post

Important Lessons on Recovering from Petya

In their most recent webinar, Skyport Systems explores ways to isolate and protect critical databases to keep the core of your company safe from harm.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

When you do backups in the Solaris Operating System, the file system must be inactive. Otherwise, the output may be inconsistent. A file system is inactive when it's unmounted or it's write-locked by the operating system. Although the fssnap utility…
Why Shell Scripting? Shell scripting is a powerful method of accessing UNIX systems and it is very flexible. Shell scripts are required when we want to execute a sequence of commands in Unix flavored operating systems. “Shell” is the command line i…
Learn several ways to interact with files and get file information from the bash shell. ls lists the contents of a directory: Using the -a flag displays hidden files: Using the -l flag formats the output in a long list: The file command gives us mor…
Learn how to find files with the shell using the find and locate commands. Use locate to find a needle in a haystack.: With locate, check if the file still exists.: Use find to get the actual location of the file.:

636 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question