With this update, you can now use the scap-client-modules-winbind (available via the modulename=winbind configuration option of the nsswitch.conf(5) file in the NSS database) module to configure the scap-client-modules-winbind module in the NSS domain. The scap-client-modules-winbind module supports authentication to Windows servers. This module is not enabled by default, but can be enabled in the nsswitch.conf(5) file.
As a result of the above changes, the following modules have been updated:
modulename=winbind configuration in the nsswitch.conf(5) file.
/etc/security/winbind.conf now contains the following parameter:
The current OpenVZ Linux guests use the Linux kernel in the default mode. A mode flag was added to the kernel to support the security model of the Red Hat Virtualization software (RHV). The mode flag is not set by default and must be set by the host via an interface configuration file. A new interface configuration file is provided to set the mode flag.
When a daemon starts, a service file is created at the end of the /etc/init.d/ directory. If the service file exists, the daemon must use it because it is created with the preferred parameters of the daemon. When a service file does not exist, the daemon must use the default parameters. The “” location is the location of a directory.
An update to the Secure File Transfer Protocol (SFTP) server adds an option to the authentication mechanism to disable the use of SSH Public Keys. When this option is enabled, the server uses a challenge-response method to authenticate a user.
The serial parameter in the /etc/ssh/sshd_config file indicates the maximum number of concurrent connections that the SSH server will make to accept incoming connections. This feature can prevent denial of service attacks, which is especially important if the computer is a web server.
When the Radius client is used for authentication, a parameter is added to the radiusd server's configuration file. It is used to control which directory to use when the radiusd server attempts to find RADIUS clients. This parameter should be set to the path of the directory that contains a directory of RADIUS clients.
The --grub-install CLI option is used to install, configure, and remove a GRUB configuration file. This option cannot be used if you have already installed a GRUB bootloader on the system, for example, during a system update. 827ec27edc