Go to main content

man pages section 8: System Administration Commands

Exit Print View

Updated: Thursday, June 13, 2019
 
 

rpc.rexd(8)

Name

rpc.rexd, rexd - RPC-based remote execution server

Synopsis

/usr/sbin/rpc.rexd [-s]

Description

rpc.rexd is the Oracle Sun RPC server for remote program execution. This daemon is started by inetd(8) whenever a remote execution request is made.

For non-interactive programs, the standard file descriptors are connected directly to TCP connections. Interactive programs involve pseudo-terminals, in a fashion that is similar to the login sessions provided by rlogin(1). This daemon may use NFS to mount file systems specified in the remote execution request.

There is a 10240 byte limit for arguments to be encoded and passed from the sending to the receiving system.

Options

The following option is supported:

–s

Secure. When specified, requests must have valid DES credentials. If the request does not have a DES credential it is rejected. The default publickey credential is rejected. Only newer on(1) commands send DES credentials.

If access is denied with an authentication error, you may have to set your publickey with the chkey(1) command.

Specifying the –s option without presenting secure credentials will result in an error message: Unix too weak auth (DesONly)!

Security

rpc.rexd uses pam(3PAM) for account and session management. The PAM configuration policy, configured in /etc/pam.conf or per-service files in /etc/pam.d/, specifies the modules to be used for rpc.rexd. Here is a partial pam.conf file with rpc.rexd entries for account and session management using the UNIX module:

rpc.rexd   account requisite       pam_roles.so.1
rpc.rexd   account required        pam_projects.so.1
rpc.rexd   account required        pam_unix_account.so.1

rpc.rexd      session required      pam_unix_session.so.1

The equivalent PAM configuration in /etc/pam.d/ would be the following entries in /etc/pam.d/rpc.rexd:

account requisite         pam_roles.so.1
account required                  pam_projects.so.1
account required                  pam_unix_account.so.1

session required                  pam_unix_session.so.1

If there are no entries for the rpc.rexd service in /etc/pam.conf and no /etc/pam.d/rpc.rexd file exists, then the entries for the “other” service in /etc/pam.conf will be used. If there are not any entries in /etc/pam.conf for the “other” service, then the entries in /etc/pam.d/other will be used. rpc.rexd uses the getpwuid() call to determine whether the given user is a legal user.

Files

/dev/ptsn

Pseudo-terminals used for interactive mode

/etc/passwd

Authorized users

/tmp_rex/rexd??????

Temporary mount points for remote file systems

Attributes

See attributes(7) for descriptions of the following attributes:

ATTRIBUTE TYPE
ATTRIBUTE VALUE
Availability
system/network/nis

See Also

chkey(1), on(1), rlogin(1), svcs(1), pam(3PAM), pam.conf(5), publickey(5), attributes(7), pam_authtok_check(7), pam_authtok_get(7), pam_authtok_store(7), pam_dhkeys(7), pam_passwd_auth(7), pam_unix_account(7), pam_unix_auth(7), pam_unix_session(7), smf(7), inetadm(8), inetd(8), svcadm(8)

Diagnostics

Diagnostic messages are normally printed on the console, and returned to the requestor.

Notes

Root cannot execute commands using rexd client programs such as on(1).

The rpc.rexd service is managed by the service management facility, smf(7), under the service identifier:

svc:/network/rpc/rex:default

Administrative actions on this service, such as enabling, disabling, or requesting restart, can be performed using svcadm(8). Responsibility for initiating and restarting this service is delegated to inetd(8). Use inetadm(8) to make configuration changes and to view configuration information for this service. The service's status can be queried using the svcs(1) command.