home
NEWS       BLOGS       FORUMS       NEWSLETTERS       RESEARCH       EVENTS       DIGITAL LIBRARY       CAREERS  
Network Computing Network Computing Powered by InformationWeek Business Technology Network

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers


netgroup(4) File Formats netgroup(4)
NAME
netgroup - list of network groups
DESCRIPTION
A netgroup defines a network-wide group of hosts and users.
Netgroups may be used to restrict access to shared NFS
filesystems and for restricting remote login and shell
access.
Network groups are stored in one of the Network Information
Services, either NIS or NIS+, not in a local file.
This manual page describes the format for a file that may be
used to supply input to the makedbm(1M) or nisaddent(1M)
programs that are use to build the NIS map or NIS+ table,
respectively.
Each line of the file defines the name and membership of
network group. The line should have the format:
groupname member ...
The items on a line may be separated by a combination of one
or more spaces or tabs.
The groupname is the name of the group being defined. This
is followed by a list of members of the group. Each member
is either another group name, all of whose members are to be
included in the group being defined, or a triple of the
form:
(hostname,username,domainname)
In each triple, any of the three fields hostname, username,
and domainname, can be empty. An empty field signifies a
"wildcard" matching any value in that field. Thus:
everything (,,this.domain)
defines a group named "everything" for the domain
"this.domain" to which every host and user belongs.
The domainname field refers to the domain in which the tri-
ple is valid, not the domain containing the host or user.
Netgroups can be used to control NFS mount access (see
share_nfs(1M)) and to control remote login and shell access
(see hosts.equiv(4)). They can also be used to control
local login access (see passwd(4), shadow(4), and "compat"
in nsswitch.conf(4)).
When used for these purposes, a host is considered a member
of a netgroup if the netgroup contains any triple in which
the hostname field matches the name of the host requesting
access and the domainname field matches the domain of the
host controlling access.
Similarly, a user is considered a member of a netgroup if
the netgroup contains any triple in which the username field
matches the name of the user requesting access and the
domainname field matches the domain of the host controlling
access.
Note that when netgroups are used to control NFS mount
access, access is granted depending only on whether the
requesting host is a member of the netgroup. Remote login
and shell access can be controlled both on the basis of host
and user membership in separate netgroups.
FILES
/etc/netgroup used by /var/yp/Makefile on NIS masters
to build the NIS netgroup map
Note that the netgroup information must always be stored in
a network information service, either NIS or NIS+. The local
file is only used to construct the netgroup NIS maps or NIS+
table; it is never consulted directly.
SEE ALSO
nis+(1), makedbm(1M), nisaddent(1M), share_nfs(1M),
innetgr(3N), hosts.equiv(4), nsswitch.conf(4), passwd(4),
shadow(4)
NOTES
Applications may make general membership tests using the
innetgr() function (see innetgr(3N)).
Because the "-" character will not match any specific user-
name or hostname, it is commonly used as a placeholder that
will match only wildcarded membership queries. So, for exam-
ple:
onlyhosts (host1,-,our.domain) (host2,-,our.domain)
onlyusers (-,john,our.domain) (-,linda,our.domain)
effectively define netgroups containing only hosts and only
users, respectively. Any other string that is guaranteed
not to be a legal username or hostname will also suffice for
this purpose.
When a machine with multiple interfaces and multiple names
is defined as a member of a netgroup, one must list all of
the names (see hosts(4)). A manageable way to do this is to
define a netgroup containing all of the machine names. For
example, for a host "gateway" that has names "gateway-
subnet1" and "gateway-subnet2" one may define the netgroup:
gateway (gateway-subnet1,,our.domain) (gateway-subnet2,,our.domain)
and use this netgroup gateway whenever the host is to be
included in another netgroup.
SunOS 5.4 Last change: 8 Aug 1993





Ready to take that job and shove it?

Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
Go beyond Google and get vertical. These specialized search sites will help you find the business information you need -- fast.

Ari Balogh was named to the post of chief technology officer as the companys for a "realignment" of employees.










InformationWeek U.S. IT Salary Survey 2008
Salaries for business technology professionals are falling. Here's what you need to know in order to make good hiring decisions and personal career choices. Download Today
 
ROLLING RIGHT ALONG
Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








TechSearch


Microsite of the Week


Powerful Information at Your Fingertips



InformationWeek Business Technology Network
InformationWeekInformationWeek 500InformationWeek 500 ConferenceInformationWeek AnalyticsInformationWeek CIO
InformationWeek EventsInformationWeek ReportsInformationWeek MagazinebMightyByte and SwitchDark Reading
Digital LibraryIntelligent EnterpriseInternet EvolutionNetwork ComputingNo Jitter
space
Techweb Events Network
InteropVoiceConWeb 2.0 ExpoWeb 2.0 SummitEnterprise 2.0 ConferenceMobile Business ExpoSoftware ConferenceCSI - Computer Security Institute
Black HatGTECEnergy CampMashup CampStartup Camp
space
Light Reading Communications Network
Light ReadingLight Reading EuropeUnstrungLight Reading's Cable Digital NewsConstantinopleInternet Evolution
Heavy ReadingLight Reading Live!Light Reading InsiderEthernet ExpoOptical ExpoTeleco TVTower Technology Summit
space
Financial Technology Network
Advanced TradingBank Systems & TechnologyInsurance & TechnologyWall Street & TechnologyAccelerating Wall StreetBank Systems & Technology Executive SummitBuyside Trading SummitInsurance & Technology Executive Summit
space
Microsoft Technology Network
MSDN MagazineTechNetThe Architecture Journal
space
App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
About Us  |  Contact Us  |  Site Map  |  Technology Marketing Solutions  |  Advertising Contacts  |   Briefing Centers
Copyright © 2008  United Business Media LLC  |  Privacy Statement  |  Terms of Service  |  Your California Privacy Rights