<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Thrusted System in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/thrusted-system/m-p/3015910#M129502</link>
    <description>If I enable the login time an user, Can I make su to this user from other user? If I can, how I configure it?&lt;BR /&gt;&lt;BR /&gt;Thanks</description>
    <pubDate>Fri, 04 Jul 2003 17:16:29 GMT</pubDate>
    <dc:creator>Marcel Garcia Will</dc:creator>
    <dc:date>2003-07-04T17:16:29Z</dc:date>
    <item>
      <title>Thrusted System</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/thrusted-system/m-p/3015910#M129502</link>
      <description>If I enable the login time an user, Can I make su to this user from other user? If I can, how I configure it?&lt;BR /&gt;&lt;BR /&gt;Thanks</description>
      <pubDate>Fri, 04 Jul 2003 17:16:29 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/thrusted-system/m-p/3015910#M129502</guid>
      <dc:creator>Marcel Garcia Will</dc:creator>
      <dc:date>2003-07-04T17:16:29Z</dc:date>
    </item>
    <item>
      <title>Re: Thrusted System</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/thrusted-system/m-p/3015911#M129503</link>
      <description>The answer to your question is yes.&lt;BR /&gt;&lt;BR /&gt;su - username will give you the user along with the environment.  Take out the dash and you only get priviledges.&lt;BR /&gt;&lt;BR /&gt;Trusted System is done either by running Bastille Security Checker or by Going into sam Security(obvious from there) as root user.&lt;BR /&gt;&lt;BR /&gt;The only configuration after that is to make the audit logs manageable.  Too much logging and you just fill up filesystems.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Fri, 04 Jul 2003 18:49:31 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/thrusted-system/m-p/3015911#M129503</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2003-07-04T18:49:31Z</dc:date>
    </item>
    <item>
      <title>Re: Thrusted System</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/thrusted-system/m-p/3015912#M129504</link>
      <description>thanks SEP, but it cannot resolve my problems.&lt;BR /&gt;I??ve added a login time policy to an user.&lt;BR /&gt;If I want to make su - [user] from other user besides root, the su - [user] fails. su - [user] obey login time policy, like telnet?&lt;BR /&gt;&lt;BR /&gt;in time, I need to make su - [user].</description>
      <pubDate>Fri, 04 Jul 2003 19:05:57 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/thrusted-system/m-p/3015912#M129504</guid>
      <dc:creator>Marcel Garcia Will</dc:creator>
      <dc:date>2003-07-04T19:05:57Z</dc:date>
    </item>
    <item>
      <title>Re: Thrusted System</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/thrusted-system/m-p/3015913#M129505</link>
      <description>Greetings,&lt;BR /&gt;&lt;BR /&gt;I do not fully understand your problem.&lt;BR /&gt;&lt;BR /&gt;Here is what I understand.&lt;BR /&gt;&lt;BR /&gt;You limit logins based on time.&lt;BR /&gt;&lt;BR /&gt;Do you want to enable or disable su - logins.&lt;BR /&gt;&lt;BR /&gt;What is the error message you receive.&lt;BR /&gt;&lt;BR /&gt;Detail will help me understand.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Fri, 04 Jul 2003 20:06:23 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/thrusted-system/m-p/3015913#M129505</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2003-07-04T20:06:23Z</dc:date>
    </item>
    <item>
      <title>Re: Thrusted System</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/thrusted-system/m-p/3015914#M129506</link>
      <description>This is not the way this should work.&lt;BR /&gt;&lt;BR /&gt;The security policy can only be enforced if:&lt;BR /&gt;The user logs in &lt;LOGIN time="" recorded="" and="" monitored=""&gt;&lt;BR /&gt;If you su - xxxx you are changing the rules.&lt;BR /&gt;Each su session is recorded in syslog/sulog.&lt;BR /&gt;&lt;BR /&gt;Why do you wish to su anyway? Why can't the user use his/her own login ? There are ways that file permissions can be manipulated with groups and acls.&lt;BR /&gt;&lt;BR /&gt;Within the shell there is an idle timeout facility (TMOUT and autologout depending on the shell type)&lt;BR /&gt;&lt;BR /&gt;I am sure that you compile or change options with using the 'sudo' product where there is a timeout.&lt;/LOGIN&gt;</description>
      <pubDate>Fri, 04 Jul 2003 23:04:56 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/thrusted-system/m-p/3015914#M129506</guid>
      <dc:creator>Michael Tully</dc:creator>
      <dc:date>2003-07-04T23:04:56Z</dc:date>
    </item>
    <item>
      <title>Re: Thrusted System</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/thrusted-system/m-p/3015915#M129507</link>
      <description>I think Marcel wants to know whether it is possible to switch to a time-restricted account while outside of the 'allowed logon hours' of the target account.&lt;BR /&gt;&lt;BR /&gt;I guess not, since I assume this policy is checked at -every- logon, including su's.. hence, as a non-root user I don't think it will work. &lt;BR /&gt;&lt;BR /&gt;Best regards</description>
      <pubDate>Sat, 05 Jul 2003 14:34:45 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/thrusted-system/m-p/3015915#M129507</guid>
      <dc:creator>Wouter Jagers</dc:creator>
      <dc:date>2003-07-05T14:34:45Z</dc:date>
    </item>
  </channel>
</rss>

