Computer and Network/Account and Project
/home/admin/2016/ 00_ms1_create_pwDBs.sh 10_create_accdata.sh 20_create_homedir.sh 30_create_project.sh 40_ms1_vncpasswd.sh common.inc config.inc siteinfo.inc gen_one_passwd do_account_test
ms1 1s as1 ss1 (LDAP アカウント登録 / ホームやプロジェクトの作成) gw (パスワードファイルに登録 / ホームの作成)
aste-xxx{admin}: cd /home/admin/2016 aste-ms1{admin}: cd /home/admin/2016
aste-ms1{admin}: ./00_ms1_create_pwDBs.sh
=>
pw/pwdb_crypt_2016.csv
pw/pwdb_secret_2016.csv
pw/pwdb_secret_2016_vnc.csv
pw/lock aste-ms1{admin}: rm pw/pwdb_lock ; ./00_ms1_create_pwDBs.sh aste-ms1{root}# mv pwdb_secret_2016.csv /home/admin/secret/
aste-ms1{root}# mv pwdb_secret_2016_vnc.csv /home/admin/secret/
aste-ms1{root}# chown root /home/admin/secret
aste-ms1{root}# chmod 700 /home/admin/secret aste-ms1{admin}: cd /home/admin
aste-ms1{admin}: rsync -auvzH 2016 aste-xxx:/home/admin/ aste-xxx{admin}: cd /home/admin/2016
aste-xxx{admin}: ./10_create_accdata.sh
=>
xxx.out/ldapvi.add
xxx.out/useradd.run aste-gw{admin}: cd /home/admin/2016/mx3.out
aste-gw{admin}: su
password: xxxxxxxx (root になります)
aste-gw{root}# ./useradd.run
=> /home/acc000 ... /home/acc099 aste-srv{admin}: /usr/bin/ldapvi -h ldaps://localhost/ -b dc=aste,dc=naoj -D cn=root,dc=aste,dc=naoj
ms1, 1s, as1, ss1 gw
aste-srv{admin}: cd /home/admin/2016
aste-srv{admin}: su
password: xxxxxxxx (root になります)
aste-srv{root}# ./20_create_homedir.shms1, 1s, as1, ss1
aste-obstab{admin}: cd /home/admin/2016
aste-obstab{admin}: su
password: xxxxxxxx (root になります)
aste-obstab{root}# ./30_create_project.shms1, 1s, as1, ss1
aste-ms1{admin}: cd /home/admin/2016
aste-ms1{admin}: su
password: xxxxxxxx (root になる)
aste-ms1{root}# ./40_ms1_vncpasswd.sh
=> /home/[user]/.vnc/vncpasswd aste-mx3{admin}: cd /home/admin/2016
aste-mx3{admin}: su
password: xxxxxxxx (root になる)
aste-mx3{root}# ./50_mx3_vnc_xinetd.sh
=>
mx3.out/aste-gdm.conf
mx3.out/services.add
mx3.out/xinetd-aste.d/
aste-vnc-5900 ... aste-vnc-5999 aste-mx1{root}# passwd asterobs
Changing password for user asterobs.
New password: xxxxxxxx
Retype new password: xxxxxxxx
passwd: all authentication tokens updated successfully.
aste-mx1{root}# /usr/bin/vncpasswd /etc/vncpasswd
Password: yyyyyyyy
Verify: yyyyyyyy
aste-mx1{root}# /bin/chown root.astctl /etc/vncpasswd
aste-mx1{root}# /bin/chmod 440 /etc/vncpasswd aste-mx1{root}# ls -l /etc/vncpasswd
-r--r----- 1 root astctl 8 Apr 6 05:45 /etc/vncpasswda16000 - ms1 mx1 mx3 1x 1s ax1 as1 ss1 a16099 - ms1 mx1 mx3 1x 1s ax1 as1 ss1
a16000 - ms1 mx1 mx3 1x 1s ax1 as1 ss1 a16099 - ms1 mx1 mx3 1x 1s ax1 as1 ss1
a16000 - ms1 mx1 mx3 1x 1s ax1 as1 ss1
a16000 - mx1 mx3 ax1 1x asteobs - mx1
a16000 - ms1 mx1 mx3 ax1 as1 1x 1s ss1
pw ログイン可能 - ?
sftp 不可 ("Request for subsystem 'sftp' failed on channel 0") - ? pw ログイン不可 ("Permission denied (publickey,gssapi-keyex,gssapi-with-mic).") - ?
pubkey ログイン可 - ?
sftp 不可 ("Request for subsystem 'sftp' failed on channel 0") - ?ssh コマンドで到達不可 (ssh -v や telnet 22 で確認) - ?
/etc/security/access.conf の設定必要
pw ログイン不可 (pubkey 設置なしで "Permission denied (publickey,gssapi-keyex,gssapi-with-mic).") - ok15
sshd122.conf 許可で pubkey ログイン可 - ok
sshd122.conf 不許可で pubkey ログイン不可 ("Connection closed by 133.40.7.130") - ?
sftp アクセス不可 ("subsystem request failed on channel 0") - ?ls -ld /home/acc???
acc000@gw -> a16000-VNC on mx3 接続後の画面で a16000 としてログインできること
acc000@gw -> VNC on mx1 接続後の画面で asterobs としてログインできること
ms1 as1
未完
/etc/security/sshd122.conf
/etc/xinetd-aste.d/ 情報削除