HP 800 CIFS/9000 Client Release Note, June 2002 - Page 9

Troubleshooting Information for PAM-NTLM, Recommended Configuration Values

Page 9 highlights

Chapter 1 CIFS/9000 Client A.01.08 Features and Fixes in Recent Releases In another case, swinstall, when used to install any software, will stop or exit, forcing the user to set mount_all_filesystems=false. The patch is available at either of these web sites: Americas and Asia-Pacific: http://us-support.external.hp.com/ Europe: http://europe-support.external.hp.com/ Troubleshooting Information for PAM-NTLM • If you are having difficulty accessing the password server configured in smb.conf, PAM-NTLM can utilize an lmhosts file on the local system to look up its address. To utilize this functionality, create the file, /etc/opt/samba/lmhosts, containing entries, one per line, in the following format where netbios_name is the password server used by PAM-NTLM. ip_address netbios_name • If you are going to remove the PAM-NTLM fileset (or the entire CIFS/9000 Client) from your system, ensure that all references to the libpam_ntlm.1 library have been removed from /etc/pam.conf. Your system can become inaccessible if PAM-NTLM is configured in /etc/pam.conf but the PAM-NTLM libraries are removed from the system. • Use caution when editing /etc/pam.conf. You should have a good understanding of the PAM framework before modifying this file. A misconfigured /etc/pam.conf can make the system inaccessible or cause a serious security breach, such as allowing root access to anyone, without a password. See the reference to pam.conf in section 4 of the HP-UX manpages and in the PAM-NTLM Configuration section in Installing and Administering the CIFS/9000 Client. Recommended Configuration Values HP recommends changing the value of the following three configuration parameters to their new default values: • runAsUser • requestTimeout • nfsAttributeCaching (you will need to add this one) 9

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18

CIFS/9000 Client A.01.08
Features and Fixes in Recent Releases
Chapter 1
9
In another case,
swinstall
, when used to install any software, will stop
or exit, forcing the user to set
mount_all_filesystems=false
.
The patch is available at either of these web sites:
Americas and Asia-Pacific:
http://us-support.external.hp.com/
Europe:
http://europe-support.external.hp.com/
Troubleshooting Information for PAM-NTLM
If you are having difficulty accessing the password server configured
in
smb.conf
, PAM-NTLM can utilize an
lmhosts
file on the local
system to look up its address. To utilize this functionality, create the
file,
/etc/opt/samba/lmhosts
, containing entries, one per line, in the
following format where netbios_name is the password server used by
PAM-NTLM.
ip_address
<one or more tabs or spaces>
netbios_name
If you are going to remove the PAM-NTLM fileset (or the entire
CIFS/9000 Client) from your system, ensure that all references to the
libpam_ntlm.1
library have been removed from
/etc/pam.conf
. Your
system can become inaccessible if PAM-NTLM is configured in
/etc/pam.conf
but the PAM-NTLM libraries are removed from the
system.
Use caution when editing
/etc/pam.conf
. You should have a good
understanding of the PAM framework before modifying this file. A
misconfigured
/etc/pam.conf
can make the system inaccessible or
cause a serious security breach, such as allowing root access to
anyone, without a password. See the reference to
pam.conf
in section
4 of the HP-UX manpages and in the PAM-NTLM Configuration
section in
Installing and Administering the CIFS/9000 Client
.
Recommended Configuration Values
HP recommends changing the value of the following three configuration
parameters to their new default values:
runAsUser
requestTimeout
nfsAttributeCaching
(you will need to add this one)