NIS+ and FNS Administration Guide
  Cerca solo questo libro
Scarica il manuale in formato PDF

Index

Symbols

# (hash character)
.....nsswitch.conf file comments238
.....shell promptsxxxii
$ (dollar sign)
.....NIS_PATH variable use44
.....shell promptsxxxii
" (quotation marks) in fully qualifiednames42
* (asterisk)
.....in group member listing176
.....regular expression symbol220
- (dash), in netgroup table input fileformat413
- (minus sign)
.....access rights operator121, 122
.....group names175
.....nsswitch.conf compatibility with+/- syntax235, 242 to 243
+ (plus sign)
.....access rights operator121, 122
.....nsswitch.conf compatibility with+/- syntax235, 242 to 243
.....regular expression symbol220
. (dots)
.....ending domain names315
.....ending NIS+ object names24
.....in/etc/auto* table names318
.....host names and41 to 42
.....NIS+ namespace object names23
.....NIS+ principal names vs. Secure RPCnetnames42
.....regular expression symbols220
/ (slashes)
.....double slashes in organizationnames283
.....trailing, in organization names284
.....in UNIX filenames23
= (equals sign) as access rightsoperator121, 122
? (question mark) as regular expressionsymbol220
@ (at sign) in group member listing176
\ (backslash)
.....bootparams table input fileformat407
.....regular expression symbol220
| (pipe symbol) as regular expressionsymbol220

Numerics

0 security level
.....described59
.....servers running at level 0319
1 security level59
2 security level59

A

-A
.....nisaddent option227
.....nischttl option204, 205
.....nistbladm option211, 213
-a
.....nisaddent option226, 227, 228, 230
.....nisdefault option124, 125
.....nisgrpadm option177, 179 to 180
.....nisping option200
.....nistbladm option211 to 212
.....nisupdkeys option107
.....rpc.nispasswdd option171
a access rights121
"abort_transaction" message311 to 312
access control
.....administrative rights68
.....changing283
.....changing access rights19
.....checking282 to 283
.....NIS+ access rights67 to 68
.....Solaris security54 to 55
access requests by clients31 to 32
access rights109 to 135
.....See also authorization; permissions;security
.....administrative rights68
.....authorization classes110, 111 to 112
.....changing112 to 113
............group of objects or entries134 to 135
............object and entry accessrights128 to 130
............ownership of objects orentries132 to 134
.....concatenation111 to 112
.....defaults112, 119
............changing112 to 113, 126 to 127
............displaying values126
............overriding112
............resetting127
............setting125 to 127
......displaying118 to 119
............NIS+ defaults124 to 125
......introduction110 to 120
......levels (directory, table, column andentry)
............examples114 to 115
............security113 to 114
............types of rights and objects actedupon116 to 117
......niscat command requirements176
......nisgrpadm commandrequirements177
......passwd command requirements148
......removing
............for columns132
............for objects or entries129
......specifying in commands112, 120 to 123
............column access rights130 to 132
............-D option112, 124, 125, 127 to 128
............default security values125 to 127
............nondefault values at creationtime127 to 128
......storage location117
......syntax
............class121, 122
............group122
............objects123
............operator121, 122
............owner122
............rights122
............table entries123
......types67 to 68, 110 to 111
............levels and116 to 117
addresses
......See also IP addresses
......name service overview2 to 8
......NIS maps10 to 11
......NIS+ root reference285 to 286
......physical addresses vs. descriptivenames4 to 8
administration
......access rights109 to 135
.....administrative rights68
.....credential informationadministration96 to 98
.....credential information foradministrators91
.....directories183 to 205
.....federating NIS+ with global namingsystems285 to 289
.....file system namespace291 to 299
.....FNS in NIS+253 to 284
.....groups173 to 182
.....keys99 to 107
.....NIS+ administrator68
.....NIS+ directories183 to 205
.....NIS+ tables207 to 231
.....passwords144 to 172
.....printer namespace301 to 304
.....removing credential information97 to 98
aging passwords158 to 168
.....aging vs. expiration164
.....calculating dates152 to 153
.....date of last change150
.....described158 to 159
.....expiration date for passwordprivilege151 to 152, 164 to 166
.....forcing users to changepasswords159
.....maximum days before changing150 to 151, 160, 170
.....maximum days between logins151, 166 to 167
.....minimum days before changing150, 161, 170
.....nobody class and147
.....operations affected159
.....passwd file defaults168 to 171
............MAXWEEKS setting170
............MINWEEKS setting170
............nsswitch.conf file and168
............PASSLENGTH setting169, 171
............principles169
............WARNWEEKS setting170
.....setting criteria for multiple users168
......turning off aging163
......turning off privilege expiration166
......warning of required change151, 162 to 163, 170
......world class and147
aliases
......host names261
......mail aliases11
all hosts context258, 260
all users context258, 261 to 262
API (application programmer's interface)for NIS+20
application programmer's interface (API)for NIS+20
applications337
asterisk (*)
......in group member listing176
......regular expression symbol220
at sign (@) in group member listing176
attributes
......adding attributes or values276, 278
......listing277
......managing and examining276 to 278
......modifying values278
......removing attributes or values277
......replacing278
AUTH_SYS security59
authentication
......See also authorization; credentials
......credential/authentication process74 to 79
............authentication components75
............credentials vs. credentialinformation74 to 75
............login phase75, 76 to 77
............preparation phase75, 76
............request phase76, 77 to 79
......defined12, 17
......DES credentials60 to 61
......described56
......process56 to 57
......Solaris Secure RPC gate55
"authentication denied" message321
"authentication error" message321
authorization
.....See also access rights; authentication;permissions
.....defined12, 17
.....described56, 63
.....NIS+ authorization classes63 to 67, 110
............access right syntax121, 122
............displaying access rights118 to 119
............group63, 65 to 66, 110, 111
............hierarchy of objects and66 to 67
............nobody64, 66, 110, 111
............owner63, 64, 110, 111
............world63, 66, 110, 111
.....passwd command requirements148
.....process57
auto_home table
.....auto_master table and404, 405
.....columns404
.....described46, 404
.....example405
.....nsswitch.conf file category238
auto_master table
.....auto_home table and404, 405
.....columns405
.....described46, 405
.....examples405 to 406
.....nsswitch.conf file category238
automounter293 to 294
.....multiple locations298
.....troubleshooting318
.....variable substitution298 to 299
automounter maps
.....auto_home table46, 404 to 405
.....auto_master table listing406

B

-B
.....nisinit option195, 196
.....rpc.nisd option
............killing the daemon312, 337
............starting with DNS-forwardingcapabilities193, 194
backslash (\)
......bootparams table input fileformat407
......regular expression symbol220
bindings
......See also contexts
......access control
............changing283
............checking282 to 283
......composite names to references273 to 275
......displaying267 to 268
......NIS vs. NIS+316
......printers301
......removing for composite names275
......renaming275
blanks in object names317
bold typeface in this manualxxxii
bootparams file406
bootparams NIS map10
bootparams table
......columns406 to 407
......described45, 406
......example407
......input file format407
Bourne shell default promptsxxxii
browsing
......See also displaying; listing
......FNS structures using NIS+commands280 to 281
"busy try again later" message332

C

-C
......nisinit option195, 196
......nisping option
............checkpoint operations failconsistently309
............checkpointing52, 199, 200 to 201
............performance sluggish when inprogress333
......nisupdkeys option106
-c
.....nisgrep option221
.....nisgrpadm option177, 178 to 179
.....nisinit option195, 196
.....nismatch option221
.....nistbladm option130 to 131, 209 to 210
.....rpc.nispasswdd option172
c access rights,See create access rights
C column type210
C shell
.....default promptsxxxii
.....nischttl syntax205
cache manager
.....See also time-to-live (TTL)
.....described196
.....starting18, 197
.....stopping197
cache, directory,See directory cache
cached public keys problems83 to 84
"callback" message311 to 312
"Can't find suitable transport"message315
"cannot [do something] with log"message337
"cannot find" message315
"cannot get public key" message321
"Cannot obtain initial context"message343
case-sensitivity for table columns210
Changing key message whenAddingkey message expected320
checking access control282 to 283
checkpoint operations
.....checkpointing directories199, 200 to 201
.....described52
.....disk space problems and338
.....fail consistently309
.....performance sluggish during333
child directories24
chkey command
.....after changing root password141
......changing NIS+ principal keys100 to 102
......creating credential information usingdummy password93 to 95
......described69
......re-encrypting existing privatekey100, 101
......requirements101
"chkey failed" message321
clearing
......See also removing
......directory cache197
......keys106
clients
......client-server computing4
......cold-start file32
......defined4, 31
......domain access31 to 32
....../etc/.rootkey file preexisting331
......home domain31
......initializing
............NIS+ clients19
............workstation clients194 to 196
......NIS map for diskless clients10
......NIS+ directories22
......NIS+ tables and31
......overview31 to 32
......removing NIS+245 to 246
......servers as36 to 37
......servers vs.27
closing,See stopping
cold-start file
......changing credentials326
......creation326
......credential-related information85, 323
......described32
......initializing clients by196
......updating keys106
column level
......access rights
............adding to existing table131 to 132
............create rights117
............described113 to 114
............destroy rights117
............example114 to 115
............modify rights117
............read rights116
............removing132
............specifying during tablecreation130 to 131
............types and objects actedupon116
.....authorization classes and67
.....column types210
.....searching
............first column221
............multiple columns222
............particular column222
............regular expressions220
column separators for NIS+ tables404
commands
.....See alsospecific commands
.....access right specification112, 120 to 123
............column access rights130 to 132
............default security values125 to 127
............nondefault values at creationtime127 to 128
............syntax121 to 123
.....browsing FNS structures using NIS+commands280 to 281
.....credential-related commands69, 87 to 88
.....FNS context management267 to 276
.....group-related commands174
.....NIS+ administration commands18 to 20
.....NIS+ security (password, credential,and key) commands69
.....shell prompts in examplesxxxii
common key77
compat source fornsswitch.conffile235, 243
composite names
.....binding to references273 to 275
.....destroying named objects276
.....displaying bindings267 to 268
......removing from namespace275 to 276
contexts
......See also bindings
......changing ownership283
......checking naming inconsistencies279 to 280
......creating individually
............all hosts context258, 260
............all users context258, 261 to 262
............debugging258
............displaying information258
............file context266
............fncreate commandoverview257 to 258
............generic context258, 264 to 265
............namespace identifiercontext258, 266 to 267
............organization context259
............printer context264
............service context263
............single host context260
............single user context262
............site context265
......debugging creation258
......displaying the binding267 to 268
......files
............administering299
............creating294 to 299
......host-related contexts
............cannot be created345
............cannot be removed346
......initial context343
......listing contents269 to 272
......managing and examining267 to 276
......mapping to NIS+ objects280
......printers302 to 304
......user-related contexts
............cannot be created345
............cannot be removed346
continue switch action option236
corrupted credentials319, 327 to 328
corrupted files
......database or log file311 to 312
....../var/nis/data directory316
Courier typeface in this manualxxxii
create access rights
.....See also access rights
.....described67 to 68, 111
.....levels and116 to 117
.....syntax122
cred table85 to 86
.....adding credentials18
.....changing keys100 to 102
.....checking credentials319
.....columns86, 408
.....credential-related information84, 323
.....DES credential information61
.....described45, 85, 407
.....linking408
.....missing entry329
.....passwd command and keys148
credentials73 to 98
.....See also authentication; security
.....administering credentialinformation96 to 98
.....authentication process74 to 79
............authentication components75
............credentials vs. credentialinformation74 to 75
............login phase75, 76 to 77
............preparation phase75, 76
............request phase76, 77 to 79
.....changing DES credentials326 to 327
.....checking319
.....commands69, 87 to 88
.....corrupted or missing319, 327 to 328
.....creating18
.....creating information86 to 96
............administrator information91
............dummy password example93 to 95
............methods86 to 87
............NIS+ principal information91 to 96
............other domain example95
............preparation phase76
............principal name syntax91
............Secure RPC netname syntax90
............user principal example93
............usingnisaddcred87 to 90
............workstation example96
......credential information vs.74 to 75
......DES credentials79 to 84
............authentication process77 to 79
............changing326 to 327
............contents79
............creating80 to 82
............cred table columns86
............cred table for information61
............described60 to 61
............NIS+ credentials vs.60
............nisaddcred creation ofinformation89 to 90
............Secure RPC netname79
............verification field80
......displaying information88
......LOCAL credentials
............cred table columns86
............described61 to 62
............nisaddcred creation ofinformation89
......machine credentials60
......NIS+ table407 to 408
......outdated information322 to 327
......overview59 to 60
......passwd command and147
......removing88
......removing information97 to 98
......Solaris Secure RPC gate55
......storing information84 to 85, 322 to 324
......updating information322 to 324
............usingnisaddcred87 to 88
............where information is stored84 to 85
............your own credentialinformation97
......updating public keys324 to 327
......user credentials60
......user types and credential types62
......Youname do not have Secure RPCcredentials errormessage319
ctx_dir directory
.....checkpointing256
.....creating255
.....replicating256
.....verifying creation255

D

-D
.....access right override option112, 124, 125, 127 to 128
.....fncreate option258
.....nisaddent option227
.....nisgrpadm option179
.....nisln option223
.....passwd option148, 155
-d
.....fnattr option277
.....nisaddent option227, 231
.....nisdefault option124
.....nisgrpadm option177, 179
.....nisls option185
.....nistbladm option211
d access rights,See destroy access rights
dash (-)
.....See also minus sign (-)
.....netgroup table input file format413
Data Encryption Standard credentials,SeeDES credentials
data.dict file, caution againstrenaming22
database corrupted (NIS+)312
date of last password change
.....calculating152 to 153
.....displaying154 to 155
.....setting150
debugging context creation258
defaults
.....access rights
............changing112 to 113
............specifying112, 119
.....displaying usingnisdefaultscommand124 to 125
.....listing for NIS+ objects19
......nsswitch.conf search criteria236 to 237
......nsswitch.conf template file241
......password settings168 to 172
......security level59
......setting security values125 to 127
deleting,See removing
DES credentials79 to 84
......authentication process77 to 79
......changing326 to 327
......contents79
......creating80 to 82
......cred table columns86
......cred table for information61
......described60 to 61
......NIS+ credentials vs.60
......nisaddcred creation ofinformation89 to 90
......Secure RPC netname79
......verification field80
DES key77, 81
destroy access rights
......See also access rights
......described67 to 68, 111
......levels and116, 117
......syntax122
destroying,See removing
directories183 to 205
......See also files and file systems
......access rights granted by servers120
......adding replica to existingdirectory187, 189 to 190
......automounter293 to 294
......cannot deleteorg_dir orgroups_dir311
......checking for public keys88
......checkpointing199, 200 to 201
......creating19
............on parent server188
............usingnismkdir command187 to 188
......creation byfncreate command257
......credential-related information84, 323
......disassociating replicas191
.....expanding into NIS+ domain225
.....expanding into NIS-compatibledomain225
.....fully qualified names40
.....home directory contains uppercaseletters334
.....listing contents19
............terse listing185 to 186
............usingnisls command184 to 187
............verbose listing186 to 187
.....listing object properties184
.....namespace24 to 25
............removing19
............UNIX directories vs.23, 24
.....NIS+22
............hierarchy and authorizationclasses66 to 67
............master server255
.....nis_cachemgr command196 to 197
.....niscat command184
.....nischttl command203 to 205
.....nisinit command194 to 196
.....nislog command201 to 202
.....nisls command184 to 187
.....nismkdir command187 to 190
.....nisping command198 to 201
.....nisrmdir command190 to 191
.....nisshowcache command197 to 198
.....propagating into client files326
.....public key propagation325
.....removing
............namespace19
............usingnisrmdir command190 to 191
.....rpc.nisd command192 to 194
.....server connection to27
.....Solaris permissions matrix55
directory cache
.....See also time-to-live (TTL)
.....cache manager
............described196
............starting18, 197
............stopping197
.....cached public keys problems83 to 84
......changing credentials326
......clearing197
......credential-related information84, 323
......directory object accumulation by34 to 35
......displaying contents197 to 198
......example33
......initializing33, 326
......listing contents19
......overview32 to 35
directory level
......access rights
............create rights116
............destroy rights117
............modify rights117
............read rights116
............types and objects actedupon116
......authorization classes and66
directory objects,See directories
disk space requirements for FNS onNIS+254
disk space, insufficient310, 338
diskless workstations
......See also workstations
......configuration information table406 to 407
......described406
......NIS map10
displaying
......See also listing; read access rights
......access control282 to 283
......access rights118 to 119
............NIS+ defaults124 to 125
......bindings267 to 268
......context creation information258
......credential information88
......defaults usingnisdefaultscommand124 to 125
......directory cache contents197 to 198
......NIS+ table contents18
......NIS_DEFAULTS variable values126
......password information154 to 155
......size of application or process337
.....time of last update for server198, 199
.....time-to-live values203
.....transaction log contents201 to 202
.....transaction logs (NIS+)310
DNS and Bindxxxi
DNS maps,nsswitch.conf specificationof sources404
dns source fornsswitch.conf file235
DNS table, editing286 to 287
DNS,See Domain Name System (DNS)
dollar sign ($)
.....NIS_PATH variable use44
.....shell promptsxxxii
Domain Name System (DNS)
.....See also name services
.....domains defined8
.....federating NIS+ under286 to 287
.....name service overview2 to 8
.....NIS with9
.....NIS+ differences15
.....NIS-compatibility mode and DNS-forwarding18
............starting the NIS+ daemon193, 194
.....nsswitch.conf file and DNSforwarding241 to 242
.....overview8
.....resolver8
domain names (NIS+)
.....dot (.) ending315
.....troubleshooting310 to 311
.....warning against changing329
domains
.....adding replica servers326
.....changing machine to differentdomain329
.....client access31 to 32
.....creating credential information inanother domain95
.....described25
.....DNS domains8
.....expanding directories into NIS+domain225
......expanding directories into NIS-compatible domain225
......fully qualified names40
......home domain
............described31
............servers36 to 37
......hosts with same name42
......name changing329
......namespace structure25 to 26
......NIS vs. DNS9
......NIS+ vs. DNS15
......passwd command and otherdomains148
......removing groups and179
......Secure RPC netnames80
......server connection to27
dots (.)
......ending domain names315
......ending NIS+ object names24
....../etc/auto* table names318
......host names and41 to 42
......NIS+ namespace object names23
......NIS+ principal names vs. Secure RPCnetnames42
......regular expression symbols220
dummy password for creating credentialinformation93 to 95
dumping NIS+ table information to afile231

E

editing the DNS table286 to 287
encryption,See keys
ending,See stopping
entry level
......access rights
............adding rights128 to 129
............create rights117
............described114
............destroy rights117
............example114 to 115
............modify rights117
............read rights116
............removing rights129
............syntax123
............types and objects actedupon116
.....adding an entry to a table211 to 213
.....authorization classes and67
.....changing groups135
.....changing ownership133
.....changing time-to-live205
.....modifying entries213 to 214
.....removing entries
............multiple entries215
............single entry214
equals sign (=) as access rightsoperator121, 122
erasing,See removing
error messages284
.....See also troubleshooting (FNS);troubleshooting (NIS+);specific messages or clauses ofmessages
.....alphabetic listing349 to 402
.....alphabetization rules in thismanual351
.....context349 to 350
.....during login attempt139 to 140
.....during password changeattempt141 to 142
.....name service switch statusmessages236
............default responses237
.....object not found problems314 to 318
............automounter cannot beused318
............blanks in name317
............domain levels not correctlyspecified315
............files missing or corrupt316
............incorrect path315
............object does not exist316
............replica lagging or out-of-sync316
............symptoms315
............syntax or spelling error315
.....RPC error messages350
.....severity threshold level349
......status codes349
......tracing cause349 to 350
/etc files, adding information to NIS+tables18
/etc tables,nsswitch.confspecification of sources404
/etc/bootparams file406
/etc/defaults/passwd file168 to 171
......MAXWEEKS setting170
......MINWEEKS setting170
......nsswitch.conf file and168
......PASSLENGTH setting169, 171
......principles169
......WARNWEEKS setting170
/etc/group file, adding group tablecontents410
/etc/nsswitch.conf file
......auto_home and auto_master tableinformation238
......comments in238
......compatibility with +/- syntax235, 242 to 243
......described12
......DNS-forwarding control241 to 242
......fails to perform correctly314
......files pointer168 to 171
......format234 to 238
......overriding withpasswd -rcommand146
......overview233 to 234
......passwd entry144, 145 to 146, 339
......passwd_compat: nisplusentry235
......search criteria
............defaults236 to 237
............overview235
............switch action options236
............switch status messages236
......sources235
......specifying information sources404
......syntax errors238
......template files
............default template241
............described233 to 234
............examples240 to 241
............overview239
.....timezone table and238
.....See also name service switch
/etc/nsswitch.files file
.....described233 to 234, 239
.....example241
.....using239
/etc/nsswitch.nis file
.....described233 to 234, 239
.....example240
.....using239
/etc/nsswitch.nisplus file
.....described233 to 234, 239
.....example240
.....using239, 241
/etc/passwd file
.....adding passwd table contents416
.....changing passwords in NIS+environment330
.....credential-related information85, 324
.....NIS+ password and login passwordin330
/etc/.rootkey file
.....changing machine to differentdomain329
.....preexisting331
/etc/syslog.conf file, severitythreshold for error reporting349
Ethernet addresses
.....ethers table408 to 409
.....NIS maps10
ethers table
.....columns408
.....described46, 408
.....Ethernet address form409
ethers.byaddr NIS map10
ethers.byname NIS map10
examining,See browsing; displaying;listing
executing,See starting
expanding directories
.....into NIS+ domain225
.....into NIS-compatible domain225
expiration date for passwordprivilege164 to 166
......aging vs. expiration164
......calculating152 to 153
......displaying154 to 155
......setting151 to 152, 164 to 165
......turning off privilege expiration166
expired password139 to 140, 322
explicit group members174, 175
explicit group nonmembers175
export command andNIS_DEFAULTSvalues126 to 127

F

-f
......fncreate option
............all hosts context260
............all users context262
............overview258
......nisaddent option228
......nisrm option192
......passwd option159
-F,rpc.nisd option193
Federated Naming Service
......See also name services
......browsing FNS structures using NIS+commands280 to 281
......described8
......error messages284
......name service overview2 to 8
......setting up
............FNS namespace setup255 to 256
............NIS+ service setup254 to 255
............replicating FNS service256
............resource requirements254
......troubleshooting284, 343 to 348
............context cannot be removed bycreator346
............fndestroy/fnunbind does notreturn "operationfailed"347 to 348
............fnlist does not listsuborganizations345
............host-related contexts cannot becreated345
............initial context cannot beobtained343
............initial context containsnothing343
............"name in use" messages346 to 347
............"no permission" messages344
............user-related contexts cannot becreated345
federating
.....NIS+ with global namingsystems285 to 289
............obtaining NIS+ rootreference285 to 286
............under DNS286 to 287
............under X.500288 to 289
files and file systems
.....See also directories;specific files
.....contexts
............creating266
............ownership266
.....dumping NIS+ table information to afile231
.....input file forfncreate_fs(1M)
............alternate format299
............creating295 to 297
.....loading NIS+ tables from textfiles227, 228 to 229
.....namespace administration291 to 299
............automounter293 to 294
............file context administration299
............file context creation294 to 299
............NFS file servers292 to 293
............overview291 to 294
.....NFS file servers292 to 293
.....NIS+ files and directories22
.....NIS+ namespace compared to UNIXfile system23 to 24
.....printer context administration302
.....Solaris permissions matrix55
files source fornsswitch.conffile235
fnattr command
......adding attributes276
......listing attributes277
......modifying attribute values278
......other options278
......overview276
......removing attributes277
fnbind command
......binding composite names toreferences273 to 274
......options273
......syntax267
fnbind -r command
......binding composite names toreferences274 to 275
......options273
......syntax267
fnbind -s command, "name in use"message347
fncheck command279 to 280
fncreate command
......all hosts context creation258, 260
......all users context creation258, 261 to 262
......debugging context creation258
......file context creation266
......FNS namespace setup255 to 256
......generic context creation258, 264 to 265
......host-related contexts cannot becreated345
......namespace identifier contextcreation258, 266 to 267
......NIS_GROUP environment variablesetting255
......options258
......organization context creation259
......overview257 to 258
......printer context creation264
......service context creation263
......single host context creation260
......single user context creation262
......site context creation265
......syntax257
......-t option345
.....user-related contexts cannot becreated345
fncreate -s command
....."name in use" message347
fncreate_fs(1M) command
.....command-line input297 to 299
.....input file
............alternate format299
............creating295 to 297
.....multiple locations298
.....options294
.....overview294 to 295
.....syntax294
.....variable substitution298 to 299
fndestroy command
.....context cannot be removed346
.....destroying named objects276
....."operation failed" not returned347 to 348
.....syntax267
fnlist command
.....displays nothing in initialcontext343
.....listing context contents269 to 272
.....options269
.....suborganizations not listed345
.....syntax267
fnlookup command
.....displaying bindings267 to 268
.....options267
.....syntax267
fnrename command
.....renaming existing bindings275
.....syntax267
FNS,See Federated Naming Service
fns_hosts table281
fns_rserver creation256
fnunbind command
....."name in use" message346
....."operation failed" not returned347 to 348
.....removing composite names275
.....syntax267
forgotten password339
fs context type266
......See also files and file systems
ftp command and password aging159
fully qualified names
......characters acceptable in42
......dot (.) ending24, 315
......group names40 to 41
......host names41 to 42
......indexed names41
......name-expansion facility43
......NIS+ domain names40
......NIS+ principal names42
......NIS+ server host names336 to 337
......NIS+ table names40 to 41
......NIS+ table search paths48 to 50
......overview37 to 39

G

-g
......nisdefault option124
......nisls option185
g access rights121
generic context creation258, 264 to 265
generic context type264 to 265
Generic system error message310
GIDs, NIS maps10, 11
glossary419 to 428
group authorization class
......access rights111
............displaying for objects118 to 119
............syntax122
......described63, 65 to 66
group file, adding group tablecontents410
group IDs, NIS maps10, 11
group level and authorization classes66
group table
......adding contents to/etc/groupfiles410
......columns410
......described46, 409
group.bygid NIS map10
group.byname NIS map10
groups
.....adding members179 to 180
.....administration173 to 182
.....authorization class63, 65 to 66
.....cannot add user309
.....changing
............entry's group135
............object's group134
.....creating178 to 179
.....described173
.....displaying directory's groupowner185
.....fully qualified names40 to 41
.....group table409 to 410
.....listing members180 to 181
.....listing object properties175 to 176
.....member types174
.....netgroup NIS maps11
.....netgroup table411 to 413
.....NIS maps10
.....niscat command usage175 to 176
.....nisgrpadm command19, 177 to 182
............related commands174
.....nonmember types175
.....removing179
.....removing members181
.....specifying member types174 to 175
.....testing principals formembership182
groups_dir directory
.....cannot be deleted311
.....creating19
.....described24, 65
.....fully qualified names40 to 41

H

-H
.....nisinit option195
.....nisupdkeys option106
-h
.....niscat option216
.....nisdefault option124
.....nisgrep option221
.....nislog option201
......nismatch option221
hard disk space requirements for FNS onNIS+254
hard disk space, insufficient310, 338
hash character (#)
......nsswitch.conf file comments238
......shell promptsxxxii
home directory, uppercase letters in334
home domain
......described31
......servers36 to 37
/home mount point404
host context type260
host name
......initializing clients by195
......NIS+ queries hang afterchanging336 to 337
hostname context type260
hosts
......aliases261
......context creation
............all hosts258, 260
............single host260
......context ownership260, 261
......domains with same name42
......fully qualified names41 to 42
......NIS maps10
hosts table
......columns410
......described45, 410
hosts.byaddr NIS map10
hosts.byname NIS map10
hung system,See system hang problems
hyphen,See dash (-); minus sign (-)

I

-i
......nis_cachemgr option197
......nisrm option192
I column type210
identifier of Secure RPC netnames80
identifiers, namespace, contextcreation258, 266 to 267
illegal object problems308 to 309
Illegal object type message308
implicit group members174, 175
implicit group nonmembers175
in.named daemon8
inactivity maximum339
inconsistencies in context naming,checking279 to 280
indexed names41, 123
initial context343
.....See also contexts
initializing
.....directory cache33, 326
.....NIS+ client or server19
.....reinitializing NIS+ clients329
.....root master server195, 196
.....server or client with preexisting/etc/.rootkey file331
.....workstation clients194 to 196
input file forfncreate_fs(1M)
.....alternate format299
.....creating295 to 297
input file format requirements404
installation (NIS+), server slow at startupafter335
"insufficient permission" message318, 321, 331
Internet
.....See also Domain Name System (DNS)
.....Ethernet addresses table408 to 409
.....network masks table forsubnetting413
.....networks table414
.....NIS connection9
.....NIS map of services11
.....NIS+ connection16
.....protocols table416
.....services table417
"invalid principal name" message313
IP addresses
.....See also addresses
......hosts table410
......netmasks table413
......updating107
italic typeface in this manualxxxii

K

keylogin command
......authentication57
......creating DES credentials and81
......described69, 76
......Secure RPC password different fromlogin password76, 82 to 83, 99 to 100, 330 to 331
keylogin process99 to 100
keylogout command69, 76 to 77
keys
......See also public keys; private keys
......administration99 to 107
......authentication process77 to 79
......cached public keys problems83 to 84
......changing keys
............chkey command100 to 102
............nonroot server keys105
............root keys from anothermachine104
............root keys from root102
............root replica keys from thereplica104 to 105
......clearing106
......commands69
......common key77
......creation bynisaddcred89
......DES key (random key or random DESkey)77
......NIS map11
......passwd command and148
......re-encrypting existing privatekey100, 101
......Secure RPC password different fromlogin password76, 82 to 83, 99 to 100, 330 to 331
......updating public keys20, 105 to 107, 324 to 327
............examples107
............nisupdkeys commandarguments106
............nisupdkeys commandoverview105 to 106
............updating IP addresses107
.....where information is stored84 to 85, 323
keyserv command69
keyserv daemon failure328
"keyserv fails to encrypt" message321
keyserver
.....credential-related information84, 323
.....keyserv daemon failure328
killing,See stopping
Korn shell default promptsxxxii

L

-L
.....fnbind option273, 274
.....fnlookup option267
.....nischttl option204 to 205
.....nisln option223
.....nisls option185
-l
.....fnattr option277
.....fnlist option269, 271 to 272
.....nisgrpadm option177, 180 to 181, 182
.....nisls option185, 186 to 187
.....passwd option158
launching,See starting
less thanN days since the last changemessage141, 161
levels of access
.....examples114 to 115
.....security113 to 114
.....types of access rights and116 to 117
levels of security
.....described58 to 59
.....password commands and59
.....servers running at level 0319
.....setting for NIS+ daemon193
linking NIS+ tables, cred table408
links (XFN)
......creating and binding273, 274
......displaying binding267
links, symbolic,See symbolic links
listing
......See also displaying; read access rights
......attributes and their values277
......browsing FNS structures using NIS+commands280 to 281
......context contents269 to 272
......context naming inconsistencies279 to 280
......directory contents184 to 187
............nisls command options185
............terse listing185 to 186
............verbose listing186 to 187
......directory object properties184
......fnlist does not listsuborganizations345
......fns_hosts table contents281
......group members180 to 181
......group object properties175 to 176
......initial context contains nothing343
......NIS+ directory contents19
......NIS+ object defaults19
......NIS+ objects used by FNS280 to 281
......NIS+ shared cache contents19
......printing references used forbinding273, 274
......suborganizations usingnisls345
......table contents217
......table object properties217 to 218
loading NIS+ tables226 to 231
......methods of populating tables51 to 52
......replacing, merging, orappending226
......using NIS maps227, 229 to 231
......using text files227, 228 to 229
LOCAL credentials
......cred table columns86
......described61 to 62
......nisaddcred creation ofinformation89
locked password322
locking passwords157
.....unlocking158
log files
.....checkpointing52
.....corrupted311 to 312
.....naming convention52
.....slow startup and334
.....too large309, 334, 338
.....transaction log
............cannot be truncated310
............described29
............displaying contents201 to 202
............replica updating process28 to 30
logging in
.....authentication process75, 76 to 77
.....maximum days between logins151
.....maximum login time period172
.....process138
.....remote logins
............netgroup table411 to 413
............user cannot remote log in toremote domain340
.....Solaris security54 to 55
.....troubleshooting
............Login incorrectmessage139, 157, 166, 321
............NIS+ password and loginpassword in/etc/passwd file330
............password expiredmessage139 to 140
............password will expiremessage140, 162
............Permission deniedmessage140
............Secure RPC password differentfrom login password76, 82 to 83, 99 to 100, 330 to 331
............Too many failures - trylater message139
............Too many tries; try againlater message139
............user cannot log in339
............user cannot log in after passwordchange313 to 314, 340
............user cannot remote log in toremote domain340
......user login same as machinename319 to 320
logging out, private key security76 to 77
login command
......password aging and159
......Secure RPC password different fromlogin password99 to 100
Login incorrect message139, 157, 166, 321

M

-M
......nisaddent option227
......niscat option216
......nisgrep option221
......nisls option185
......nismatch option221
......rpc.nisd option334
-m
......fnattr option278
......nisaddent option226, 227, 228, 229, 230
......nisls option185
......nismkdir option187
......nistbladm option213 to 214
m access rights,See modify access rights
machine credentials60, 62
......See also credentials
machine domain names
......dot (.) ending315
machines
......changing domains329
....../etc/.rootkey file preexisting331
......reinitializing NIS+ clients329
......root password change causesproblem332
mail aliases11
mail aliases table46, 411
mail.aliases NIS map11
mail.byaddr NIS map11
Managing NFS and NISxxxi
mapping FNS contexts to NIS+objects280
maps (DNS),nsswitch.confspecification of sources404
maps (NIS)
.....described10
.....loading NIS+ tables from18, 51, 229 to 231
.....NIS+ table types matching maps229 to 231
.....NIS+ tables vs.16
.....nsswitch.conf specification ofsources404
.....table of10 to 11
Master server busy, full dumprescheduled message341
master servers
.....See also servers
.....defined9, 12
.....displaying time of last update198, 199
.....listing directory contents from185
.....listing table entries from216, 221
.....NIS9
.....NIS+12, 15
.....replicas and28
.....root master server
............defined28
............initializing195, 196
MAXWEEKS default for passwords170
memory, insufficient337
messages,See error messages
minus sign (-)
.....See also dash (-)
.....access rights operator121, 122
.....group names175
.....nsswitch.conf compatibility with+/- syntax235, 242 to 243
MINWEEKS default for passwords170
modify access rights
.....See also access rights
......described67 to 68, 110
......levels and116, 117
......syntax122
mount points
......auto_home table404
......auto_master table405
mounting directories293 to 294
mounts, remote, netgroup table411 to 413

N

n access rights121
"name in use" messages
......fnbind -s command347
......fncreate -s command347
......fnunbind command346
name service switch14, 233 to 243
......See alsonsswitch.conf file
......action options236
......described17, 233
......overview233 to 234
......status messages236
name services
......See also Domain Name System (DNS);Federated Naming Service;NIS; NIS+
......advantages4 to 8
......overview2 to 8
......forprinter contextadministration302 to 304
names,See composite names; domainnames (NIS+); fully qualifiednames
namespace21 to 44
......See also fully qualified names
......administration problems308 to 311
............cannot add user to group309
............cannot deleteorg_dir orgroups_dir311
............cannot truncate transaction logfile310
............checkpoint fails consistently309
............disk space insufficient310
............domain name confusion310 to 311
............illegal object problems308 to 309
............logs grow too large309
............nisinit fails309
............symptoms308
.....database problems311 to 312
............multiplerpc.nisdprocesses311 to 312
............symptoms311
.....directories24 to 25
.....DNS namespace8
.....domain structure25 to 26
.....naming conventions37 to 43
............characters acceptable42
............directory object names40
............host names41 to 42
............name-expansion facility43
............NIS+ domain names40
............NIS+ principal names42
............overview37 to 39
............table entry names41
............tables and group names40 to 41
.....NIS+ clients31 to 32
.....NIS+ principals30
.....NIS_PATH variable
............overview43 to 44
............performance and44
.....performance problems335
.....removing
............NIS+ directories and replicas19
............NIS+ namespace248 to 250
............NIS+ objects19
.....servers27 to 30
.....servers as clients36 to 37
.....structure of NIS+ namespace22 to 24
.....UNIX file system compared to23 to 24
.....updating process28 to 30
namespace identifiers
.....context creation258, 266 to 267
.....context ownership267
naming inconsistencies, checking forcontexts279 to 280
netgroup NIS map11
netgroup table
......columns412
......described46, 411
......examples412
......input file format412
netgroup.byhost NIS map11
netgroup.byuser NIS map11
netgroups
......group table409 to 410
......NIS maps11
netid.byname NIS map11
netmasks table
......columns413
......described46, 413
......example413
netmasks.byaddr NIS map11
netnames (Secure RPC)
......creation bynisaddcred89
......DES credentials80
......syntax90
Network Information Control Center(NIC)414
network information services,See DomainName System (DNS); FederatedNaming Service; name services;NIS; NIS+
network masks, NIS maps11
network numbers and name servicenames4 to 5
networks table46, 414
networks.byaddr NIS map11
networks.byname NIS map11
newkey command69
NIC (Network Information ControlCenter)414
NIS
......See also name services
......DNS with9
......DNS-forwarding control242
......Internet connection9
......maps
............described10
............loading NIS+ tables from18, 51, 229 to 231
............NIS+ table types matchingmaps229 to 230
............NIS+ tables vs.16
............nsswitch.conf specification ofsources404
............table of10 to 11
.....name service overview2 to 8
.....NIS+ compatibility problems312 to 314
............nsswitch.conf file fails toperform correctly314
............symptoms312 to 313
............user cannot log in after passwordchange313 to 314
.....NIS+ vs.
............advantages of NIS+12 to 13
............differences13 to 16
.....NIS-compatibility mode of NIS+17 to 18
............DNS-forwarding and18, 193, 194
............expanding directories into NIS-compatible domain225
............security issues18, 55
............starting the NIS+ daemon193 to 194
.....nsswitch.conf compatibility with+/- syntax235, 242 to 243
.....nsswitch.nis file, described233 to 234
.....overview8 to 11
.....printer context administration302
NIS maps
.....nsswitch.conf specification ofsources404
nis source fornsswitch.conf file235
NIS+11 to 20
.....See also name services; NIS+ tables;security
.....administration commands18 to 20
.....application programmer's interface(API)20
.....changing passwords330
......checking if running341
......daemon
............credential-relatedinformation84, 323
............starting193 to 194
............stopping194
......described11 to 12
......DNS differences15
......DNS-forwarding control242
......federating with global namingsystems285 to 289
............obtaining NIS+ rootreference285 to 286
............under DNS286 to 287
............under X.500288 to 289
......files and directories22
......FNS administration253 to 284
............access control checking282 to 283
............browsing FNS structures usingNIS+ commands280 to 281
............error messages284
............FNS attribute management276 to 278
............FNS context creation257 to 267
............FNS context management267 to 276
............maintaining consistency betweenNIS+ and FNS278 to 280
............mapping FNS contexts to NIS+objects280
............replicating FNS service256
............resource requirements254
............setting up FNS namespace255 to 256
............setting up NIS+ service forFNS254 to 255
............troubleshooting284
......groups, group table409 to 410
......hierarchical structure13
......incremental updates13, 15
......Internet connection16
......name service overview2 to 8
......name service switch, described17
.....NIS compatibility problems312 to 314
............nsswitch.conf file fails toperform correctly314
............symptoms312 to 313
............user cannot log in after passwordchange313 to 314
.....NIS vs.
............advantages of NIS+12 to 13
............differences13 to 16
.....NIS-compatibility mode17 to 18
............DNS-forwarding and18, 193, 194
............expanding directories into NIS-compatible domain225
............security issues18, 55
............starting the NIS+ daemon193 to 194
.....nsswitch.conf compatibility with+/- syntax235, 242 to 243
.....nsswitch.nisplus file
............described233 to 234
.....overview11 to 20
.....printer context administration303 to 304
.....removing245 to 250
............NIS+ from client machine245 to 246
............NIS+ from server246 to 248
............NIS+ namespace248 to 250
.....root reference285 to 286
.....security
............See also access rights; credentials;passwords; permissions
............access rights67 to 68
............administrator68
............authorization classes63 to 67, 110
............commands69
............credentials andauthentication59 to 62
............NIS vs. NIS+13
............overview56 to 58
............password commands59
............principals58
............security levels58 to 59
......Solaris 1.x and17 to 18
......tables,See NIS+ tables
......troubleshooting307 to 348
............miscellaneous problems341 to 342
............namespace administrationproblems308 to 311
............namespace databaseproblems311 to 312
............NIS compatibility problems312 to 314
............object not found problems314 to 318
............ownership and permissionproblems318 to 321
............security problems321 to 332
............slow performance problems332 to 336
............system hang problems332 to 337
............system resource problems337 to 338
............user problems338 to 341
NIS+ and DNS Setup and ConfigurationGuidexxxi
NIS+ and FNS Administration Guide
......intended audiencexxix
......organizationxxix to xxxi
......overviewxxix
......related booksxxxi
......required knowledgexxix
......shell promptsxxxii
......typographic conventionsxxxii
NIS+ tables45 to 52, 403 to 418
......See also column level; entry level;nistbladm command; tablelevel;specific tables
......access rights113 to 117
............how servers grant rights119 to 120
......adding entries211 to 213
......adding information from/etc files orNIS maps18
......administration207 to 231
.....alternate sources of information233 to 234
.....changing entries213 to 214
.....changing time-to-live for entries203, 205
.....clients and31
.....column requirements209
.....column separators404
.....column types210
.....creating
............unpopulated tables19, 50 to 51
............usingnistbladmcommand209 to 210
.....creating links223
.....displaying contents18
.....dumping table information to afile231
...../etc files corresponding to404
.....expanding directories into NIS+domain225
.....expanding directories into NIS-compatible domain225
.....fully qualified names40 to 41
.....indexed names41
.....input file format requirements404
.....listing object properties217 to 218
.....listing table contents217
.....loading information226 to 231
............loading from NIS maps227, 229 to 231
............loading from text files227, 228 to 229
............methods of populating tables51 to 52
............replacing, merging, orappending226
.....NIS maps and matching tables229 to 230
.....NIS maps vs.16
.....nisaddent command226 to 231
.....niscat command216 to 218
.....nisgrep command219 to 222
.....nisln command222 to 223
.....nismatch command219 to 222
.....nissetup command224 to 225
.....nistbladm command208 to 216
......nsswitch.conf specification ofsources404
......preconfigured tables16, 45 to 46
......removing211
......removing entries
............multiple entries215
............single entry214
......searching for entries19
............first column221
............multiple columns222
............particular column222
............regular expressions220
......setting up50 to 52
......structure45 to 50
............columns and entries47 to 48
............search paths48 to 50
......system tables16, 45 to 46
............creating50 to 51
......updating process52
NIS+ Transition Guidexxxi
nis_cachemgr program196 to 197
......cached public keys problems83 to 84
......described18, 196
......not running335
......starting the cache manager18, 197
NIS_COLDSTART file
......See also cold-start file
......changing credentials326
......creation326
......credential-related information85, 323
......initializing clients by196
......updating keys106
NIS_DEFAULTS variable
......access right defaults112, 119
......changing defaults112 to 113, 126 to 127
......displaying values126
......group object properties176, 178
......overriding112
......resetting to original values127
......setting default security values125 to 127
nis_dump_svc: one replica isalready resyncingmessage342
NIS_DUMPLATER error code constant342
NIS_GROUP environment variable179, 255
NIS_PATH variable
.....overview43 to 44
.....performance and44, 333
NIS_SHARED_DIRCACHE file
.....See also directory cache; time-to-live(TTL)
.....changing credentials326
.....credential-related information84, 323
.....initializing326
.....starting the cache manager18, 196 to 197
nisaddcred command
.....Changing key message320
.....creating credential information87 to 88
............administrator information91
............dummy password example93 to 95
............NIS+ principals' information91 to 96
............other domain example95
............principal name syntax91
............process of creation89 to 90
............related commands88
............Secure RPC netname syntax90
............user principals example93
............workstation example96
.....described18, 69
.....public key generation325
.....removing credential information97 to 98
.....updating your own credentialinformation97
nisaddent command226 to 231
.....described18
.....dumping table contents to a file231
.....loading data from files52, 228 to 229
......loading data from NIS maps51, 229 to 231
......overview226
......populating tables52
......replacing, merging, orappending226
......specifying nondefault securityvalues127 to 128
......syntax227
niscat command216 to 218
......checking access control282 to 283
......checking directories for publickeys88
......checking permissions319
......described18, 154, 215
......listingfns_hosts contents281
......listing object properties
............directories184
............groups175 to 176
............tables217 to 218
......listing table contents217
......Server busy. Try againmessage336
......syntax216
......viewing access rights118 to 119
nischgrp command283
......changing entry's group135
......changing object's group134
......described19, 174
nischmod command283
......adding access rights128 to 129
......changing context access control283
......described19
......removing access rights129
nischown command283
......changing context ownership283
......changing entry ownership133
......changing object ownership133
......described19
nischttl command203 to 205
......changing object's time-to-live204 to 205
......changing table entry's time-to-live205
......described19
.....options204
.....overview203 to 204
nisclient command
.....Changing key message320
.....cold-start file creation326
.....credential information creation76, 87
.....removing NIS+ installed by245 to 246
NIS-compatibility mode17 to 18
.....DNS-forwarding and18, 193, 194
.....expanding directories into NIS-compatible domain225
.....security issues18, 55
.....starting the NIS+ daemon193 to 194
nisdefaults command
.....described19, 174
.....displaying NIS+ defaults124 to 125
.....displaying subsets of values125
.....displaying time-to-live values203
.....options124
.....terse format125
.....verbose format125
nisgrep command219 to 222
.....checking existence of NIS+password329
.....described19, 219
.....nismatch compared to219
.....regular expressions220
.....searching tables
............first column221
............multiple columns222
............particular column222
.....syntax220
nisgrpadm command
.....access rights required177
.....adding group members179 to 180
.....creating groups178 to 179
.....described19, 177
.....listing group members180 to 181
.....related commands174
.....removing group members181
.....removing groups179
.....specifying group member types175
.....syntax175, 177
......testing principals formembership182
nisinit command
......cold-start file creation326
......described19
......fails309
......initializing clients194 to 196
......initializing root master server195, 196
nisln command222 to 223
......creating a link223
......described19, 222
......syntax223
nislog command201 to 202
nisls command184 to 187
......browsing FNS structures280 to 281
......checking existence of objects316
......checking transaction log310
......described19, 174
......displaying suborganizations345
......listing directory contents
............terse listing185 to 186
............verbose listing186 to 187
......options185
......verifyingctx_dir creation255
nismatch command219 to 222
......checking credentials319
......described19, 219
......displaying credential information88
......nisgrep compared to219
......regular expressions220
......searching tables
............first column221
............multiple columns222
............particular column222
......syntax220
nismkdir command187 to 190
......adding replica to existingdirectory187, 189 to 190
......creating directories187 to 188
......described19
......master server assignment255
......org_dir creation51
......problems running on replica189
......public key propagation325
.....replicating FNS service256
.....specifying nondefault securityvalues127 to 128
nispasswd command
.....described19, 154
.....security issues59
.....usingpasswd instead140, 144
nisping -C command
.....checkpoint operations failconsistently309
.....checkpointing52
.....checkpointing directories199, 200 to 201
.....performance sluggish when inprogress333
nisping command198 to 201, 256
.....checkpointingctx_dirdirectory256
.....described198 to 199
.....displaying time of last update198, 199
.....performance sluggish when inprogress333
.....pinging replicas199 to 200
nisplus source fornsswitch.conffile235
nispopulate script
.....creating credential information87
.....populating NIS+ tables51 to 52
nisrm command
.....described19, 191
.....options192
.....removing nondirectory objects192
nisrmdir command
.....cannot deleteorg_dir orgroups_dir311
.....described19, 190
.....disassociating replicas fromdirectories191
.....removing directories190 to 191
nisserver script, creating NIS+tables51
nissetup command224 to 225
.....creating NIS+ tables51
......described19, 174, 224
......expanding directory into NIS+domain225
......expanding directory into NIS-compatible domain225
......syntax224
nisshowcache command
......described19
......displaying directory cachecontents197 to 198
nistbladm command148 to 153, 208 to 216
......adding access rights to existing tablecolumns131 to 132
......adding entries to tables211 to 213
......changing entries213 to 214
......creating NIS+ tables51, 209 to 210
......described20, 148 to 149, 208
......passwd command vs.149
......password operations148 to 153
............calculating number of days152 to 153
............expiration date for passwordprivilege151 to 152, 164 to 166
............maximum days beforechanging150 to 151
............maximum days betweenlogins151, 166 to 167
............minimum days beforechanging150
............setting criteria for multipleusers168
............shadow column fields (passwdtable) and149 to 152
............turning off password privilegeexpiration166
............warning of required change151
......populating NIS+ tables52
......removing column access rights132
......removing entries
............multiple entries215
............single entry214
......removing tables211
......security-related options130
.....setting column access rights whencreating tables130 to 131
.....setting nondefault table paths333
.....specifying nondefault securityvalues127 to 128
.....syntax208
............columnspec components209
.....table search paths50
.....turning off password aging164
nisupdkeys command
.....arguments106
.....cached public keys problems83
.....described20, 69
.....examples107
.....updating directory objects after keychange91, 104, 105
.....updating IP addresses107
.....updating keys manually324 to 327
.....updating public keys105 to 107
"no memory" message337
"no permission" messages (FNS)344
"no public key" message321
nobody authorization class
.....access rights111
............displaying for objects118 to 119
.....described64, 66
.....password-aging constraints and147
....."permission denied" errors82 to 83
"not exist" message315
"not found" message315
"not responding" message332
NOTFOUND switch status message236
.....default response237
nsid context type266 to 267
nsswitch.conf file
.....See also name service switch
.....auto_home and auto_master tableinformation238
.....comments in238
.....compatibility with +/- syntax235, 242 to 243
.....described12
.....DNS-forwarding control241 to 242
.....fails to perform correctly314
......files pointer168 to 171
......format234 to 238
......overriding withpasswd -rcommand146
......overview233 to 234
......passwd entry144, 145 to 146, 339
......passwd_compat: nisplusentry235
......search criteria
............defaults236 to 237
............overview235
............switch action options236
............switch status messages236
......sources235
............compatibility with +/-syntax235, 242 to 243
......specifying information sources404
......syntax errors238
......template files
............default template241
............described233 to 234
............examples240 to 241
............overview239
......timezone table and238
nsswitch.files file
......described233 to 234, 239
......example241
......using239
nsswitch.nis file
......described233 to 234, 239
......example240
......using239
nsswitch.nisplus file
......described233 to 234, 239
......example240
......using239, 241
number sign (#)
......nsswitch.conf file comments238
......shell promptsxxxii

O

-O
......fnattr option278
......fnbind option273
-o
.....fncreate option
............all users context261
............organization context260
............overview258
............single user context262
.....niscat option
............listing directory objectproperties184
............listing group objectproperties175 to 176
............listing table objectproperties216, 217 to 218
o access rights121
"object problem" messages308
objects
.....See also directories
.....access rights
............adding rights128 to 129
............removing rights129
............syntax123
.....administrative rights68
.....changing groups134
.....changing ownership133
.....changing time-to-live204 to 205
.....defined23
.....destroying named objects276
.....hierarchy and authorizationclasses66 to 67
.....listing object properties
............directories184
............groups175 to 176
............tables217 to 218
.....NIS+ objects permissions matrix56
.....removing nondirectory objects191 to 192
.....request authentication76, 77 to 79
opening,See starting
"operation failed" message not returnedwithfndestroy/fnunbind347 to 348
operator syntax for access rights121
org context type259
org_dir directory
......cannot be deleted311
......creating19, 50 to 51
......cred table for407 to 408
......described24
......fully qualified names40 to 41
organizational units
......contexts
............creating259
............ownership260
......double slashes in organizationnames283
......trailing slash in organizationnames284
"out of disk space" message338
owner authorization class
......access rights111
............displaying for objects118 to 119
............syntax122
......described63, 64
ownership
......changing
............authorization class65
............entry ownership133
............group owner of NIS+ object19
............object ownership133
............owner of NIS+ object19
......displaying directory's groupowner185
......owner authorization class63, 64
......troubleshooting318 to 321
............credentials missing orcorrupted319, 327 to 328
............server running at security level0319
............symptoms318
............user login same as machinename319 to 320

P

-P
......nisaddcred option91, 92
......nisaddent option227
......nischttl option204, 205
-p
.....chkey option100
.....nisaddcred option90, 92
.....nisdefault option124
.....nistbladm option50
parent directories24
partially qualified names
.....defined37
.....name-expansion facility43
PASSLENGTH default for passwords171
passwd command145 to 148
.....access rights required148
.....aging passwords158 to 168
............aging vs. expiration164
............calculating dates152 to 153
............date of last change150
............described158 to 159
............forcing users to changepasswords159
............maximum days beforechanging160
............minimum days beforechanging161
............nobody class and147
............operations affected159
............turning off aging163
............warning of required change162 to 163
............world class and147
.....changing passwords
............another's password156
............choosing passwords142 to 143
............failures142
............forcing users to changepasswords159
............root password141, 157
............your password140 to 142, 156
.....credentials and147
.....described20, 69, 145
.....displaying passwordinformation154 to 155
.....keys and148
.....locking passwords157
.....NIS+ environment and147
.....nispasswd command and140, 144
......nistbladm command vs.149
......nsswitch.conf file and145 to 146
......other domains and148
......permissions and147 to 148
......-r option146
......root password change causesproblem332
......security issues59
......unlocking passwords158
......user cannot change password340
......user cannot log in after passwordchange313 to 314, 340
......yppasswd command and145
passwd file
......adding passwd table contents416
......credential-related information85, 324
......defaults file168 to 171
............MAXWEEKS setting170
............MINWEEKS setting170
............nsswitch.conf file and168
............PASSLENGTH setting169, 171
............principles169
............WARNWEEKS setting170
......NIS+ password and login passwordin330
passwd map, credential-relatedinformation85, 324
passwd table
......adding contents to/etc/passwdfile416
......changing password information20
......columns415
......credential-related information85, 324
......described45, 414
......shadow column415
............nistbladm command and149 to 152, 164 to 165
......User ID 0332
passwd.byname NIS map11
passwd.byuid NIS map11
password expired message139 to 140
password will expire message140, 162
passwords144 to 172
.....See also security
.....aging158 to 168
............aging vs. expiration164
............calculating dates152 to 153
............date of last change150
............described158 to 159
............expiration date for passwordprivilege151 to 152, 164 to 166
............forcing users to changepasswords159
............maximum days beforechanging150 to 151, 160, 170
............maximum days betweenlogins151, 166 to 167
............MAXWEEKS setting170
............minimum days beforechanging150, 161, 170
............MINWEEKS setting170
............nobody class and147
............operations affected159
............PASSLENGTH setting169, 171
............passwd file defaults168 to 171
............setting criteria for multipleusers168
............turning off aging163
............turning off privilegeexpiration166
............warning of required change151, 162 to 163, 170
............WARNWEEKS setting170
............world class and147
.....bad choices143
.....changing156 to 157
............another's password156
............choosing passwords142 to 143
............failures142, 171
............forcing users to changepasswords159
............maximum unsuccessfulattempts171
............root password141, 157
............your password140 to 142, 156
.....commands69
......displaying information154 to 155
......dummy password for creatingcredential information93 to 95
......failure limits171 to 172
......locking passwords157
......logging in
............See also logging in
............maximum login time period172
............process138
............troubleshooting139 to 140
......minimum length171
......nispasswd command144
......nistbladm command148 to 153
............calculating number of days152 to 153
......nsswitch.conf filerequirements144
......passwd command145 to 148
......passwd table414 to 416
......related commands154
......requirements142 to 143
......Solaris access54
......specifying criteria and defaults168 to 172
......troubleshooting
............forgotten password339
............"login incorrect" message139, 157, 166, 321
............NIS+ password and loginpassword in/etc/passwd file330
............password change failures142
............password locked, expired, orterminated139 to 140, 322
............"password [problems]"messages321
............root password change causesproblem332
............Secure RPC password differentfrom login password76, 82 to 83, 99 to 100, 330 to 331
............Sorry: less thanN dayssince the last changemessage141, 161
............Too many failures - trylater message139, 142, 172
............Too many tries; try againlater message139, 142
............user cannot changepassword340
............user cannot log in after passwordchange313 to 314, 340
............You may not change thispassword message141
............Your password has beenexpired for too longmessage160
............Your password has expiredmessage139 to 140
............Your password will expiremessage140, 162
.....unlocking passwords158
.....using138 to 143
.....yppasswd command145
paths
.....NIS_PATH variable43 to 44, 333
.....search paths for NIS+ tables48 to 50
.....table paths and performance44, 333
performance problems332 to 336
.....checkpointing in progress333
.....large NIS+ database logs (slowstartup)334
.....nis_cachemgr missing335
.....NIS_PATH variable too complex44, 333
.....niscat causesServer busymessage336
.....recursive groups334
.....startup slow334, 335
.....symptoms332 to 333
.....table paths333
.....too many replicas334
periods,See dots (.)
"permission denied" message322
.....during login attempt140
....../etc/.rootkey file preexisting331
......nobody authorization class82 to 83
......user cannot login after passwordchange313
......user cannot remote log in to remotedomain340
......user login same as machinename320
permissions
......See also access rights; authorization;security
......changing283
......checking282 to 283, 319
......network wide groups411
......passwd command and147 to 148
......Solaris
............file and directory matrix55
............NIS+ objects matrix56
......troubleshooting318 to 321
............credentials missing orcorrupted319, 327 to 328
............"insufficient permission"message318, 321, 331
............no permission319
............"no permission" messages(FNS)344
............"permission denied"message313, 320, 322, 331
............server running at security level0319
............symptoms318
............user login same as machinename319 to 320
pinging replica servers199 to 200
pipe symbol (|) as regular expressionsymbol220
plus sign (+)
......access rights operator121, 122
......nsswitch.conf compatibility with+/- syntax235, 242 to 243
......regular expression symbol220
Possible loop detected innamespace message310
pound sign (#)
.....nsswitch.conf file comments238
.....shell promptsxxxii
prefix of Secure RPC netnames80
principals (NIS+)
.....authorization classes63 to 67, 110
.....authorization process
............login phase75, 76 to 77
............preparation phase75, 76
............request phase76, 77 to 79
.....changing keys
............chkey command100 to 102
............nonroot server keys105
............root keys from anothermachine104
............root keys from root102
............root replica keys from thereplica104 to 105
.....creating credential information91 to 96
............dummy password example93 to 95
............other domain example95
............overview92
............user principals example93
............workstation example96
.....defined30
.....described58
.....fully qualified names42
.....naming syntax91
.....Secure RPC netnames vs.42
.....testing for group membership182
printer context type
.....administration
............using files302
............using NIS302
............using NIS+303 to 304
.....creation264
printers
.....context administration
............using files302
............using NIS302
............using NIS+303 to 304
.....context creation264
printing references used for binding273, 274
private keys
......See also keys; public keys
......authentication process77 to 79
......changing
............chkey command100 to 102
............nonroot server keys105
............root keys from anothermachine104
............root keys from root102
............root replica keys from thereplica104 to 105
......commands69
......creating DES credentials81 to 82
......creation bynisaddcred89
......logging out and security76 to 77
......NIS map11
......passwd command and148
......re-encrypting existing key100, 101
......Secure RPC password different fromlogin password76, 82 to 83, 99 to 100
......where information is stored84
problems,See troubleshooting (FNS);troubleshooting (NIS+)
processes
......checking size337
......insufficient338
prompts, defaultxxxii
protocols table
......columns416
......described46, 416
protocols, NIS maps11
protocols.byname NIS map11
protocols.bynumber NIS map11
public keys
......See also keys; private keys
......authentication process77 to 79
......cached public keys problems83 to 84
......changing326 to 327
............chkey command100 to 102
............nonroot server keys105
............root keys from anothermachine104
............root keys from root102
............root replica keys from thereplica104 to 105
.....checking directories for publickeys88
.....commands69
.....creating DES credentials81 to 82
.....creation bynisaddcred89
.....generating76, 325
.....NIS map11
.....propagating directory objects intoclient files326
.....propagating to directory objects325
.....updating20, 105 to 107, 324 to 327
............examples107
............nisupdkeys commandarguments106
............nisupdkeys commandoverview105 to 106
............updating IP addresses107
.....where information is stored84 to 85, 323
publickey.byname NIS map11

Q

queries (NIS+) hang after changing hostname336 to 337
question mark (?) as regular expressionsymbol220
quitting,See stopping
quotation marks (") in fully qualifiednames42

R

-R
.....nisls option185
.....nistbladm option215
-r
.....fnbind option273
.....fncheck option279, 280
.....fncreate option258
.....fncreate_fs(1M) option294
.....keylogin option100
.....nisaddcred option97
......nisaddent option226, 227
......nisclient option245 to 246
......nisdefault option124, 125
......nisgrpadm option177, 181
......nisinit option195, 196
......nistbladm option214
......passwd option146
r access rights,See read access rights
RAM, insufficient337
random (DES) key77, 81
read access rights
......See also access rights
......described67 to 68, 110
......levels and116
......syntax122
recursive directory listing185
recursive group members174, 175
recursive group nonmembers175
re-encrypting existing private key100, 101
references
......binding composite names to273 to 275
......NIS+ root reference285 to 286
......printing references used forbinding273, 274
regular expressions220
remote logins
......netgroup table411 to 413
......user cannot remote log in to remotedomain340
remote mounts, netgroup table411 to 413
removing
......See also destroy access rights
......access rights
............columns132
............objects or entries129
......attributes or values277
......cannot deleteorg_dir orgroups_dir311
......clearing
............directory cache197
............keys106
.....composite names fromnamespace275 to 276
.....credential information97 to 98
.....credentials88
.....destroying named objects276
.....directories190 to 191
.....disassociating replicas fromdirectories191
.....forcing removal without properpermissions191, 192
.....group members177, 181
.....groups177, 179
.....NIS+245 to 250
............from client machine245 to 246
............from server246 to 248
.....NIS+ directories and replicas fromnamespace19
.....NIS+ namespace248 to 250
.....NIS+ objects from namespace19
.....NIS+ table entries
............multiple entries215
............single entry214
.....nondirectory objects191 to 192
renaming bindings275
replacing attributes or values278
replica servers
.....See also servers
.....adding to domain326
.....adding to existing directory187, 189 to 190
.....changing keys
............nonroot servers105
............root replica keys from thereplica104 to 105
.....defined9, 12, 15
.....described28
.....disassociating from directories191
.....displaying time of last update198, 199
.....down or out of service309
.....lagging or out of sync316
.....performance issues334
.....pinging199 to 200
.....removing from namespace19
.....resynchronization30
......update failure341 to 342
......updating process28 to 30
replica_update error messages341 to 342
replicating FNS service256
requirements
......FNS in NIS+254
......passwords142 to 143
resource problems337 to 338
......insufficient disk space310, 338
......insufficient memory337
......insufficient processes338
......symptoms337
resource requirements254
resynchronization of replica servers30
return switch action option235, 236
rlogin command
......password aging and159
......user cannot remote log in to remotedomain340
root
......changing keys
............from another machine104
............from root102
............root replica from the replica104 to 105
......changing passwords141, 157
......NIS+ namespace vs. UNIX filesystem23
......reference for NIS+285 to 286
......security issues57, 60
......UID62
root directory, namespace24
root master server
......defined28
......initializing195, 196
root password
......change causes problem332
......passwd table and414
......Solaris security55
root_replica_update: updatefailed message342
.rootkey file
.....changing machine to differentdomain329
.....preexisting331
.....removing
............when removing NIS+ fromclient246
............when removing NIS+namespace248
RPC error messages350
RPC table
.....columns416
.....described46, 416
.....example417
rpc.bynumber NIS map11
rpc.nisd command
.....masterrpc.nisd daemon died334 to 335
.....multiple parent processes311 to 312
.....options193
............-B193, 194, 312, 337
............-M334
.....overview192 to 193
....."server not responding"message334
.....slow startup334
.....starting the NIS+ daemon192 to 194
............DNS-forwarding NIS-compatibledaemon193, 194
............NIS-compatible daemon193 to 194
rpc.nisd_resolv daemon,rpc.nisdwith-B option and312, 337
rpc.nispasswdd daemon, passwordfailure limits171 to 172
RPCs, NIS map11
running,See starting

S

-s
.....fnattr option278
.....fnbind option273
.....fncheck option279
.....fncreate option258
.....nisdefault option124, 125
......nismkdir option187, 189
......nisrmdir option191
......nisupdkeys option106
......passwd option154 to 155
S column type210
-S,rpc.nisd option193
search criteria fornsswitch.conffile235
......defaults236 to 237
search paths for NIS+ tables48 to 50
searching for NIS+ table entries19
......first column 229221
......multiple columns222
......particular column222
......regular expressions220
secret keys,See private keys
Secure RPC
......credential/authorization process59
......netname
............creation bynisaddcred89
............DES credentials80
............syntax90
......NIS maps11
......NIS+ principal names vs.42
......password different from loginpassword76, 330 to 331
......Solaris security55
......Youname do not have Secure RPCcredentials errormessage319
security53 to 69
......See also access rights; credentials;passwords; permissions
......administrative rights and68
......authentication
............credential/authenticationprocess74 to 79
............defined12, 17
............DES credentials60 to 61
............described56
............process56 to 57
............Solaris Secure RPC gate55
......authorization
............defined12, 17
............described56, 63
............NIS+ authorization classes63 to 67, 110
............passwd commandrequirements148
............process57
.....default values, setting125 to 127
.....described12, 16 to 17
.....levels
............described58 to 59
............password commands and59
............servers running at level 0319
............setting for NIS+ daemon193
.....NIS vs. NIS+13
.....NIS+
............access rights67 to 68
............administrator68
............authorization classes63 to 67, 110
............commands69
............credentials andauthentication59 to 62
............NIS vs. NIS+13
............overview56 to 58
............password commands59
............principals58
............security levels58 to 59
.....NIS-compatibility mode issues18, 55
.....Solaris53 to 56
.....specifying nondefault securityvalues127 to 128
.....troubleshooting321 to 332
............cached public keys problems83 to 84
............credential informationoutdated322 to 327
............credentials corrupted327 to 328
............domain change for machine329
............domain name changed329
............/etc/.rootkey filepreexisting331
............keyserv failure328
............"login incorrect" message139, 157, 166, 321
............machine previously was NIS+client329
............NIS+ password and loginpassword in/etc/passwd file330
............no entry in cred table329
............password locked, expired, orterminated322
............root password change causesproblem332
............Secure RPC password differentfrom login password76, 82 to 83, 99 to 100, 330 to 331
............server running at security level0319
............symptoms321
Security exception on LOCALsystem message318, 320
sendmail program, mail aliasestable411
Server busy. Try again message30, 336
"server not responding" message334
servers
......access rights, granting to tables119 to 120
......changing keys
............nonroot servers105
............root keys from anothermachine104
............root keys from root102
............root replica keys from thereplica104 to 105
......clients as36 to 37
......clients vs.27
......client-server computing4
......disassociating from directories190 to 191
......displaying time of last update198, 199
....../etc/.rootkey file preexisting331
......home domain36 to 37
......initializing NIS+ servers19
......master servers
............defined9, 12
............listing directory contentsfrom185
............listing table entries from216, 221
............NIS9
............NIS+12, 15
............replicas and28
............root master server28, 195, 196
.....NFS file servers292 to 293
.....NIS map11
.....NIS+
............connection to domains27
............ctx_dir directory256
............directories22, 255
............overview27 to 28
............requirements for FNS254
.....NIS-compatibility mode18
.....removing NIS+246 to 248
.....replicas
............adding to domain326
............adding to existing directory187, 189 to 190
............changing root replica keys fromthe replica104 to 105
............defined9, 12, 15
............described28
............disassociating fromdirectories191
............down or out of service309
............lagging or out of sync316
............performance issues334
............pinging199 to 200
............removing from namespace19
............resynchronization30
............update failure341 to 342
............updating process28 to 30
.....security level 0319
.....Server busy. Try againmessage336
....."server not responding"message334
.....slow performance after NIS+installation335
.....update implementation28 to 30
.....updating NIS+ tables52
service context type263
services
......context creation263
......context ownership263
services table46, 417
services.byname NIS map11
setenv command126 to 127
setting up FNS
......FNS namespace setup255 to 256
......NIS+ service setup254 to 255
......replicating FNS service256
......resource requirements254
severity threshold for error reporting349
shared directory cache,See directory cache
shells
......changingNIS_DEFAULTS values126 to 127
......default promptsxxxii
......netgroup table411 to 413
simple names37
single host context, creating260
single user context, creating262
site context type265
sites
......context creation265
......context ownership265
slash (/)
......double slashes in organizationnames283
......trailing, in organization names284
......in UNIX filenames23
slave servers,See replica servers
slow performance,See performanceproblems
Solaris17, 18
......group table409 to 410
......security53 to 56
............dialup gate54
............file and directory permissionsmatrix55
............login gate55
............NIS+ objects permissionsmatrix56
............root gate55
............schema of gates and filters54
............Secure RPC gate55
Solstice System Management Tools,creating credentialinformation86
Sorry: less thanN days since the lastchange message141, 161
spaces, column separators for NIS+tables404
starting
.....NIS+ cache manager18, 197
.....NIS+ daemon192 to 194
............DNS-forwarding NIS-compatibledaemon193, 194
............NIS-compatible daemon193 to 194
stopping
.....cache manager197
.....NIS+ daemon194
storage requirements for FNS onNIS+254
storing credential information84 to 85, 322 to 324
su command and security57
subnetting
.....name service advantages4 to 8
.....network masks table413
suborganizations
.....fnlist does not list345
.....listing usingnisls345
SUCCESS switch status message235, 236
.....default response237
superusers
.....See also root password
.....default promptsxxxii
switch, the,See name service switch
symbolic links
.....creating19, 223
.....following by NIS+ commands222
syslog.conf file, severity threshold forerror reporting349
system hang problems332 to 337
......masterrpc.nisd daemon died334 to 335
......NIS+ queries hang after changinghost name336 to 337
......NIS_PATH variable too complex333
......symptoms332 to 333
system resource problems337 to 338
......insufficient disk space338
......insufficient memory337
......insufficient processes338
......symptoms337
system tables (NIS+)
......See also NIS+ tables
......creating50 to 51
......described16, 45 to 46

T

-t
......fncheck option279
......fncreate option258, 345
......nisaddent option229, 231
......nisdefault option124, 203
......nisgrpadm option177, 182
......nislog option201
table level
......access rights
............create rights116
............described113
............destroy rights117
............example114 to 115
............modify rights117
............read rights116
............syntax123
............types and objects actedupon116
......authorization classes and66
tables (/etc),nsswitch.confspecification of sources404
tables (NIS+)45 to 52, 403 to 418
......See also column level; entry level;nistbladm command; tablelevel;specific tables
......access rights113 to 117
............how servers grant rights119 to 120
.....adding entries211 to 213
.....adding information from/etc files orNIS maps18
.....administration207 to 231
.....alternate sources of information233 to 234
.....changing entries213 to 214
.....changing time-to-live for entries203, 205
.....clients and31
.....column requirements209
.....column separators404
.....column types210
.....creating
............unpopulated tables19, 50 to 51
............usingfncreate command257
............usingnistbladmcommand209 to 210
.....creating links223
.....displaying contents18
.....dumping table information to afile231
...../etc files corresponding to404
.....expanding directories into NIS+domain225
.....expanding directories into NIS-compatible domain225
.....fully qualified names40 to 41
.....indexed names41
.....input file format requirements404
.....listing object properties217 to 218
.....listing table contents217
.....loading information226 to 231
............loading from NIS maps227, 229 to 231
............loading from text files227, 228 to 229
............methods of populating tables51 to 52
............replacing, merging, orappending226
.....NIS maps and matching tables229 to 230
.....nisaddent command226 to 231
......niscat command216 to 218
......nisgrep command219 to 222
......nisln command222 to 223
......nismatch command219 to 222
......nissetup command224 to 225
......nistbladm command208 to 216
......nsswitch.conf specification ofsources404
......paths333
......preconfigured tables16, 45 to 46
......removing211
......removing entries
............multiple entries215
............single entry214
......searching for entries19
............first column 229221
............multiple columns222
............particular column222
............regular expressions220
......setting up50 to 52
......structure45 to 50
............columns and entries47 to 48
............search paths48 to 50
......system tables16, 45 to 46
............creating50 to 51
......updating process52
tabs as column separators for NIS+tables404
telnet command and passwordaging159
template files fornsswitch.conf
......default template241
......described233 to 234
......examples240 to 241
......overview239
terminated password322
terminating,See stopping
time stamps
......authentication process77 to 79, 81 to 82
......transaction log29
time-to-live (TTL)
......changing field values19
......changing for objects204 to 205
......changing for table entries203, 205
.....described33, 203 to 204
.....displaying values203
timezone table46, 418
/tmp files and disk space problemsand338
Too many failures - try latermessage
.....during login139
.....during password change142, 172
Too many tries; try again latermessage
.....during login139
.....during password change142
trans.log file, caution againstrenaming22
transaction logs (NIS+)
.....cannot truncate310
.....corrupted311 to 312
.....described29
.....displaying contents201 to 202
.....replica updating process28 to 30
troubleshooting (FNS)284, 343 to 348
.....See also error messages
.....contexts
............cannot be removed bycreator346
............checking naminginconsistencies279 to 280
............debugging creation258
............host-related contexts cannot becreated345
............initial context cannot beobtained343
............initial context containsnothing343
............user-related contexts cannot becreated345
.....fndestroy/fnunbind does notreturn "operationfailed"347 to 348
.....fnlist does not listsuborganizations345
....."name in use" messages346 to 347
....."no permission" messages344
troubleshooting (NIS+)307 to 348
......See also error messages
......miscellaneous problems341 to 342
............checking if NIS+ is running341
............replica update failure341 to 342
......namespace administrationproblems308 to 311
............cannot add user to group309
............cannot deleteorg_dir orgroups_dir311