To simplify user management, you should create one or more groups and associate users with those groups. Groups let you manage multiple users at the same time.
Some actions can only be performed at the group level. For example, enabling users for LUM requires making them members of a group that is enabled for LUM.
For the exercises in this guide, you will create two groups:
LUMUsers: This group is used to LUM-enable some of the users you have created. Having the group lets us explore how LUM works and directly experience the SSH security precautions that are built into OES 2.
AllUsers: This group is for all of the eDirectory user objects, including those that are LUM-enabled and those that have only traditional Novell services access.
IMPORTANT:Creating a group named users seems logical to many eDirectory administrators.
Unfortunately, all SLES 10 servers already have a system-created local group named users, and creating a duplicate group in eDirectory causes problems.
For more information, see Avoiding POSIX and eDirectory Duplications
in the OES 2 SP3: Planning and Implementation Guide.
To create the required group objects:
In iManager >
, click > .In the LUMUsers.
field, typeThe name contains uppercase and lowercase letters simply to illustrate that case is preserved in object names. Some administrators use mixed case to improve readability.
Click the
icon next to the field.Browse to the USERS container object.
Click
> .Click the
tab.Click the
icon next to the field.Browse to the USERS container and click the down-arrow next to it
Select the following User objects:
linux1_lum-edir
linux2_lum-edir
ncp_lum-edir
nss_lum-edir
Click
> > .Click
.In the AllUsers.
field, typeClick the
icon and select the USERS object’s fully distinguished name (FDN).Click
> .Click the
tab.Click the
icon next to the field.Shift-click
, drag the mouse down to select all the users, then click .All of the users are added to the list.
Click
> > .Do not close iManager. Continue with the next section, Enabling the LUMUsers Group for Linux User Management (LUM).