Solved

recommend secure & efficient Unix LDAP (equiv of Windows AD)

Posted on 2016-08-15
6
119 Views
Last Modified: 2016-08-19
UNIX ID Management/Administration is one of the most tedious job since we have to login interactively to each of the server when there is a request to create/delete a sysadmin (or apps support) user in the hundreds of Unix servers.

We have AIX, Sparc Solaris 10 & 11 & a few Solarix Intel & a few RHEL : almost all of them are physical ie non-VM.

Our compliance privileged user management & access tool is CyberArk (ie sysadmins have to go thru it)

A few options:

a) have a centralized tool like HPSA or Nagios which we could centrally send a "useradd" or "userdel" command
     to the servers : but this is not as good as wintel AD-like solution because accounts are still locally created
     & every 60-90 days have to login manually by the owners to change password.
     Also, in Solaris, root accounts that expire will cause root cron jobs to fail

b) years ago I heard of Sun's NIS+ solution but this can't be used with AIX & RHEL or can it?

c) solution must not have adverse impact or unwieldy to apps like Oracle DB, Oracle Financials,
    TripWire, Netbackup
0
Comment
Question by:sunhux
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
6 Comments
 
LVL 40

Accepted Solution

by:
omarfarid earned 500 total points
ID: 41757380
0
 

Author Comment

by:sunhux
ID: 41757622
Will NIS solution ease the issue of expired root causing root cron jobs to fail in Solaris,
such as allowing us to change root password centrally?
0
 

Author Comment

by:sunhux
ID: 41757624
Can oracle, tripwire & Netbackup accounts be migrated from local accounts
to NIS accounts without the need to reinstall these apps?
0
Free learning courses: Active Directory Deep Dive

Get a firm grasp on your IT environment when you learn Active Directory best practices with Veeam! Watch all, or choose any amount, of this three-part webinar series to improve your skills. From the basics to virtualization and backup, we got you covered.

 
LVL 40

Assisted Solution

by:omarfarid
omarfarid earned 500 total points
ID: 41757634
Are you refereeing to OS accounts or application / DB accounts?

OS accounts (usernames) can be.
0
 
LVL 40

Assisted Solution

by:omarfarid
omarfarid earned 500 total points
ID: 41757637
to answer your other question, users will be managed centrally.
0
 

Author Comment

by:sunhux
ID: 41757680
I'm referring to OS accounts (eg: oracle that could be found in /etc/passwd)


Internally, some parties prefer to use a Wintel solution;  is there any product that
runs on Wintel that could perform such UNIX LDAP for AIX, Solaris & RHEL?
0

Featured Post

Threat Trends for MSPs to Watch

See the findings.
Despite its humble beginnings, phishing has come a long way since those first crudely constructed emails. Today, phishing sites can appear and disappear in the length of a coffee break, and it takes more than a little know-how to keep your clients secure.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Join Greg Farro and Ethan Banks from Packet Pushers (http://packetpushers.net/podcast/podcasts/pq-show-93-smart-network-monitoring-paessler-sponsored/) and Greg Ross from Paessler (https://www.paessler.com/prtg) for a discussion about smart network …
Google Drive is extremely cheap offsite storage, and it's even possible to get extra storage for free for two years.  You can use the free account 15GB, and if you have an Android device..when you install Google Drive for the first time it will give…
Learn how to find files with the shell using the find and locate commands. Use locate to find a needle in a haystack.: With locate, check if the file still exists.: Use find to get the actual location of the file.:
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.
Suggested Courses

751 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question