ypserv(1M)

ypserv, ypbind - NIS server and binder processes

As shipped in IRIX 6.5.19. Unchanged since IRIX 6.5.

NAME
     ypserv, ypbind - NIS server and binder processes

SYNOPSIS
     /usr/etc/ypserv [ -iv ] [ -t timeout ] [ -L logflags ]
     /usr/etc/ypbind [ -s ] [ -v ] [ -ypset | -ypsetme ] [ server ]

DESCRIPTION
     The network information service (NIS) provides a simple network lookup
     service consisting of databases and processes.  The databases are dbm(3B)
     files in a directory tree rooted at /var/yp.  These files are described
     in ypfiles(4).  The processes are /usr/etc/ypserv, the NIS database
     lookup server, and /usr/etc/ypbind, the NIS binder.  The programmatic
     interface to NIS is described in ypclnt(3N).  Administrative tools are
     described in yppush(1M) ypxfr(1M) yppoll(1M) ypwhich(1), and ypset(1M).
     Tools to see the contents of NIS maps are described in ypcat(1), and
     ypmatch(1).  Database generation and maintenance tools are described in
     ypinit(1M), ypmake(1M), and makedbm(1M).

     Both ypbind and ypserv are daemon processes typically activated at system
     startup time from /etc/init.d/network if the configuration flags ``yp''
     and ``ypserv'' are set on (see network(1M)).  The yp configuration state
     must be on for ypserv to be on.

     ypserv runs only on NIS server machines with a complete NIS database.
     ypbind runs on all machines using NIS, that is, both servers and clients.

     The ypserv daemon's primary function is to look up information in its
     local database of NIS maps.  The operations performed by ypserv are
     defined for the implementor by the NIS protocol specification, and for
     the programmer by the header file <rpcsvc/yp_prot.h>. Communication to
     and from ypserv is by means of RPC calls.  Lookup functions are described
     in ypclnt(3N), and are supplied as C-callable functions in
     /usr/lib/libsun.a.  There are four lookup functions, all of which are
     performed on a specified map within some NIS domain:  Match, Get_first,
     Get_next, and Get_all.  The Match operation takes a key, and returns the
     associated value.  The Get_first operation returns the first key-value
     pair from the map, and Get_next can be used to enumerate the remainder.
     Get_all ships the entire map to the requester as the response to a single
     RPC request.

     Two other functions supply information about the map, rather than map
     entries:  Get_order_number, and Get_master_name.  In fact, both order
     number and master name exist in the map as key-value pairs, but the
     server will not return either through the normal lookup functions.  (If
     you examine the map with makedbm(1M), however, they will be visible.)
     Other functions are used within the NIS subsystem itself, and are not of
     general interest to NIS clients.  They include Do_you_serve_this_domain?,
     Transfer_map, and Reinitialize_internal_state.

     The function of ypbind is to remember information that lets client
     processes on a single node communicate with some ypserv process.

     ypbind must run on every machine which has NIS client processes; ypserv
     may or may not be running on the same node, but must be running somewhere
     on the network or subnet.

     The information ypbind remembers is called a binding - the association of
     a domain name with the internet address of the NIS server, and the port
     on that host at which the ypserv process is listening for service
     requests.  The process of binding is driven by client requests.  As a
     request for an unbound domain comes in, the ypbind process broadcasts on
     the net trying to find a ypserv process that serves maps within that
     domain.  Since the binding is established by broadcasting, there must be
     at least one ypserv process on every net.  Once a domain is bound by a
     particular ypbind, that same binding is given to every client process on
     the node.  The ypbind process on the local node or a remote node may be
     queried for the binding of a particular domain by using the ypwhich(1)
     command.

     Bindings are verified before they are given out to a client process.  If
     ypbind is unable to speak to the ypserv process it is bound to, it marks
     the domain as unbound, tells the client process that the domain is
     unbound, and tries to bind the domain once again.  Requests received for
     an unbound domain will fail immediately.  In general, a bound domain is
     marked as unbound when the node running ypserv crashes or gets
     overloaded.  In such a case, ypbind will to bind any NIS server
     (typically one that is less-heavily loaded) available on the net.

     If ypbind is invoked with the hostname or IP address of an NIS server for
     the domain, the domain will be permanently bound to that server.  With
     this option, ypbind will not verify that the specified server is running,
     hence it will never unbind the domain and never broadcast for a new
     server.  (ypset(1M) can be used to change to a different server in case
     the original does fail.)

     ypbind also accepts requests to set its binding for a particular domain
     if enabled with the -ypset or -ypsetme options. The request is usually
     generated by the NIS subsystem itself.  ypset(1M) is a command to access
     the Set_domain facility.  It is for unsnarling messes. Note that the Set
     Domain procedure only accepts requests from processes running as root.

YPSERV OPTIONS
     The following options can be specified in /etc/config/ypserv.options:

     -f forklimit
          limits the number of processes ypserv can fork at any given time.
          (The default is 20.)

     -i   allows ypserv to resolve non-local host name and address lookups
          with the 4.3BSD Internet Domain Name System (DNS) server, named(1M).
          Positive and negative answers from the DNS server are cached - see
          the -t option to change the cache timeout.  Send SIGHUP to ypserv to
          flush its DNS query cache. This is useful when a named database is
          updated and ypserv has a stale answer.

     -L logflags
          specifies the type(s) of information to be logged in
          /var/yp/ypserv.log (see below), in addition to error messages.
          logflags is a comma-separated list of one or more of: dispatch (show
          request type and requester IP address), interdomain (show queries to
          DNS server), and querycache (show results from DNS query cache).

     -v   ``Verbose'' - display messages to stderr instead of the logfile.

     -t timeout
          sets the DNS query cache timeout interval to the specified value in
          seconds.  The default is 600 seconds.

YPBIND OPTIONS
     The following options can be specified in /etc/config/ypbind.options:

     -s   Secure.  When specified,  only  ypservers  bound  to  a reserved
          port  are  used.   This  allows  for a slight increase in security
          in completely controlled  environ- ments,   where  there  are  no
          computers  operated  by untrusted individuals. It offers no  real
          increase  in security.

     -v   Verbose. When specified, ypbind will log a message using syslog(3B)
          when it broadcasts domain requests, when it binds a domain after
          broadcasts, and when it executes successful Set_domain requests.

     -ypset
          ypset(1M) may be used to change the binding.  This option is very
          dangerous, and only should be used for debugging the network from a
          remote machine.

     -ypsetme
          ypset(1M) may be issued from this machine, security is based on IP
          address checking, which can be defeated on network where untrusted
          individuals may inject packets.  This option does not provide that
          much security.

     server
          The IP address or hostname of a permanent NIS server for the default
          domain.  This option is useful when there is no NIS server on the
          local network.  Note that although it is possible to set up a local
          network without any local NIS servers, this practice is not
          recommended.

FILES
     If the file /var/yp/ypserv.log exists when ypserv starts up, log
     information will be written to this file.

     /etc/config/ypserv.options
     /etc/config/ypbind.options

SEE ALSO
     named(1M), network(1M), ypcat(1), ypmatch(1), yppush(1M), ypwhich(1),
     ypxfr(1M), ypset(1M), ypclnt(3N), ypfiles(4), NIS protocol specification