Thanks to Yoav Flam for the tip. 
Here's how I got out of the mess, which was that local extended profile
files had been created on all five machines of my cluster, giving
me five different password files when I only wanted one protected
password file served by NIS.
1)  Add  "auth=local,yp" to svc.conf
(on all machines)
2)  use convuser -d  to delete the extraneous local profiles.  This
will temporarily leave all users unable to login.
3)  Go into dxaccounts and modify each account, and the proper
NIS profile will be created.
There is undoubtedly a way to do this with edauth but I didn't figure it out.
But the second part of my question still stands... I have to 
do this all over again because I still have to do a total clean install
of the OS on my NIS server.  What is the way to do it right
in the first place so all the NIS extended profiles get made automatically...
even better, is there a way to save the existing authentication database
and reinstall it?
Steve Timm
Received on Mon Apr 19 1999 - 15:59:16 NZST