[SUMMARY] DNS Lookups on X logins

From: Mr. Jolt Cola <msmith_at_quix.robins.af.mil>
Date: Tue, 10 Dec 1996 14:27:08 -0500 (GMT)

My original half-brained question was this:

> One of the features of enhanced security seems to be a lookup
> of IP address to the DNS before allowing a person to connect.
> I'm assuming this is because I have to make an entry in the
> /etc/auth/system/ttys for the system name. Is there any other
> way to not have to rely on the DNS? Putting the name in the
> hosts file does not help for this. Thanks, will summarize.

I finally dug it up from _X Window System Admin. Guide_

My problem was I forgot to update the /usr/lib/X11/xdm/Xaccess file
and add host names such as:

syst*.robins.af.mil

The new nodes were using new naming schemes (syst*) so and it had been
over a year since I was last in this file that I forgot it. :)
I'm surprised noone suggested this, or either it was too fundamental.

Also Marie-Claude Vialatte also told me how to put IP addresses in
the ttys and devassign file which works ONCE you fix the Xaccess
file above, and this may help others with different problems than mine. ;)

Quote from Marie-Claude (mc.vialatte_at_custsv.univ-bpclermont.fr):
---
I do not put the terminal names in the DNS.
I put some of them only in the /etc/hosts, and for the others, I put
only the IP address in the /etc/auth/system/ttys and /etc/auth/system/devassign
        /etc/auth/system/ttys
                193.54.50.89\:0:t_devname=193.54.50.89\:0:t_xdisplay:t_login_tim
eout#0:chkent:
        /etc/auth/system/devassign
                193.54.50.89\:0:v_devs=\:0,193.54.50.89\:0:v_type=xdisplay:chken
t:
and all works fine
---
Later,
	Melvin Smith
Received on Tue Dec 10 1996 - 20:46:00 NZDT

This archive was generated by hypermail 2.4.0 : Wed Nov 08 2023 - 11:53:47 NZDT