AIX 不能创建 高权限ID 的 问题
2014-07-15 15:45
197 查看
今天碰到 问题了,帮用户创建 manage ID 的时候,碰到问题了。
结果发现是升级系统后的bug 下面说明一下解决方法:
There is a workaround you can use however. If a role is set up in RBAC
with enough authorization to run mkuser and set some of the account
characteristics, it will be enough to run smitty mkuser.
Here are the steps to set up a role for that and assign to a user
"testadm"
# mkrole
authorizations=aix.security.user.create.admin,aix.security.user.create.n
ormal mkuserauth
update the kernel security tables:
# setkst
Then assign that role to a user
# chuser roles=mkuserauth testadm
That user would be able to run smitty mkuser when they logged in and
switched into the role:
$ swrole mkuserauth
Those two authorizations will give them enough authority to run both
command line mkuser and smitty mkuser. They won't get ALL the
functionality, but the minimum they need until the problem can be fixed.
结果发现是升级系统后的bug 下面说明一下解决方法:
There is a workaround you can use however. If a role is set up in RBAC
with enough authorization to run mkuser and set some of the account
characteristics, it will be enough to run smitty mkuser.
Here are the steps to set up a role for that and assign to a user
"testadm"
# mkrole
authorizations=aix.security.user.create.admin,aix.security.user.create.n
ormal mkuserauth
update the kernel security tables:
# setkst
Then assign that role to a user
# chuser roles=mkuserauth testadm
That user would be able to run smitty mkuser when they logged in and
switched into the role:
$ swrole mkuserauth
Those two authorizations will give them enough authority to run both
command line mkuser and smitty mkuser. They won't get ALL the
functionality, but the minimum they need until the problem can be fixed.
相关文章推荐
- 15 Linux更改权限解决新建用户不能读写创建文件/文件夹的问题
- android问题:控件id不能在R.java里自动创建,导致在Activity中无法获取控件
- wpf 运行权限 解决不能写文件 创建文件夹问题
- Oracle存储过程动态创建临时表/存储过程执行权限问题--AUTHID CURRENT_USER
- 关于oracle11g数据库不能创建序列的报错问题----实现表id自增问题
- ASP.NET两个常见的异常-不能创建Mutex、NETWORK SERVICE没有Temporary ASP.NET Files写访问权限
- 解决“Automation 服务器不能创建对象”的问题!
- 关于布署asp.net程序时,不能创建虚拟目录的问题
- asp问题之"ActiveX部件不能创建对象 "(2006.7.28)
- DCOM权限问题.不能导出Excel
- automation服务器不能创建对象的问题
- Automation 服务器不能创建对象的问题的解决方案大全
- Automation服务器不能创建对象问题
- 关于MMC不能打开文件C:\Program Files\Microsoft SQL Server\80\Tools\Binn\SQL Server Enterprise Manager.MSC可能是由于文件不存在,不是一个MMC控制台,或者用后来的MMC版本创建。也可能你没有访问此文件的足够权限
- "automation服务器不能创建对象”的问题的解决方案总结大全
- 解决automation服务器不能创建对象问题
- VS偶然碰到的问题:automation服务器不能创建对象
- 解决automation服务器不能创建对象问题
- 打开页面时出现"Automation 服务器不能创建对象"问题的解决方法
- 一步一步SharePoint 2007之二十一:解决实现注册用户后,自动具备访问网站的权限的问题(3)——创建用户