分类:
2010-02-26 19:11:40
openldap2-client-2.2.24-4.12pam_ldap-169-28.4ldapcpplib-0.0.3-21.3nss_ldap-215-59.5yast2-ldap-client-2.9.29-0.4heimdal-tools-0.6.1rc3-55.9heimdal-lib-0.6.1rc3-55.15autofs-3.1.7-900.1xntp-4.2.0a-23.8yast2-ntp-client-2.9.15-0.2
passwd: compatgroup: compathosts: files dnsnetworks: files dnsservices: filesprotocols: filesrpc: filesethers: filesnetmasks: filesnetgroup: filespublickey: filesbootparams: filesautomount: files nisaliases: filespasswd_compat: ldapgroup_compat: ldap
……BASE_CONFIG_DN="ou=ldapconfig,dc=MOODISK,dc=com"……BIND_DN="cn=Administrator,dc=MOODISK,dc=com"……
auth: use_ldapaccount: use_ldappassword: use_ldapsession: none
host ldapserver.MOODISK.com ldapslave.MOODISK.combase dc=MOODISK,dc=comldap_version 3pam_password cryptssl start_tlsnss_map_attribute uniqueMember memberpam_filter objectclass=posixAccountnss_base_passwd dc=MOODISK,dc=comnss_base_shadow dc=MOODISK,dc=comnss_base_group dc=MOODISK,dc=com
[libdefaults]clockskew = 300default_realm = MOODISK.COM[realms]MOODISK.COM = {kdc = krb5server.MOODISK.comdefault_domain = MOODISK.comadmin_server = krb5server.MOODISK.comkpasswd_server = krb5server.MOODISK.com}[domain_realm].MOODISK.com = MOODISK.COM[logging]default = SYSLOG:NOTICE:DAEMONkdc = FILE:/var/log/kdc.logkadmind = FILE:/var/log/kadmind.log[appdefaults]pam = {ticket_lifetime = 1drenew_lifetime = 1dforwardable = trueproxiable = falseretain_after_close = falseminimum_uid = 0debug = false}
auth: use_krb5 use_ldapaccount: use_krb5 use_ldappassword: use_krb5 use_ldapsession: none
passwd: compatgroup: compathosts: files dnsnetworks: files dnsservices: filesprotocols: filesrpc: filesethers: filesnetmasks: filesnetgroup: filespublickey: filesbootparams: filesautomount: ldap filesaliases: filespasswd_compat: ldapgroup_compat: ldap
……#限定登陆的组和机器AllowGroups oracle notes admin rootAllowUsers *@adminconsole1_ip *@adminconsole2_ip#限制安控办的人登陆DenyGroups security#关闭反解释,加快登陆速度UseDNS no#30分钟客户没有响应后断开连接ClientAliveInterval 600ClientAliveCountMax 3#起用kerberos验证GSSAPIAuthentication yesGSSAPICleanupCredentials yes……# vim /etc/ssh/ssh_config……GSSAPIAuthentication yesGSSAPIDelegateCredentials yes……
……server szxntp01-in.MOODISK.comserver szxntp02-in.MOODISK.com……
/bin/date >/root/.bash_history
history -a/bin/date >>/root/.bash_history/bin/logger -f /root/.bash_history/usr/bin/kdestroy