<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Trusted Systems in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/trusted-systems/m-p/3106345#M147882</link>
    <description>I see. You'll have to modify the script to query the system defaults with getprdef, then if getprpw returns -1, replace the -1 with the default value. This will then show the correct value for any user who is using the default. If getprpw doesn't return -1, then the default has been overridden by the user specific value, and no replacement will be necessary.&lt;BR /&gt;&lt;BR /&gt;The man pages I attached in the previous post will explain how to use getprdef.&lt;BR /&gt;&lt;BR /&gt;HTH.</description>
    <pubDate>Thu, 30 Oct 2003 10:52:07 GMT</pubDate>
    <dc:creator>Brian Bergstrand</dc:creator>
    <dc:date>2003-10-30T10:52:07Z</dc:date>
    <item>
      <title>Trusted Systems</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/trusted-systems/m-p/3106336#M147873</link>
      <description>I'm running HP-UX 11.11 as a Trusted System and I am experiencing the following problem:&lt;BR /&gt;&lt;BR /&gt;I set my default security policies through SAM for password minimum time (7 days) and password expiration warning (30 days), but when I run getprpw against accounts they report -1 for both settings.  When I use modprpw I can change the values. &lt;BR /&gt;&lt;BR /&gt;Am I missing something?&lt;BR /&gt;</description>
      <pubDate>Thu, 30 Oct 2003 08:47:07 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/trusted-systems/m-p/3106336#M147873</guid>
      <dc:creator>Troy E. Miles</dc:creator>
      <dc:date>2003-10-30T08:47:07Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted Systems</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/trusted-systems/m-p/3106337#M147874</link>
      <description>The system defaults are stored in a separate system file, not in each users file. The -1 represents the default, which is referenced from the system file. You can use modprpw to override the default for any specific user.&lt;BR /&gt;&lt;BR /&gt;HTH.</description>
      <pubDate>Thu, 30 Oct 2003 08:50:19 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/trusted-systems/m-p/3106337#M147874</guid>
      <dc:creator>Brian Bergstrand</dc:creator>
      <dc:date>2003-10-30T08:50:19Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted Systems</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/trusted-systems/m-p/3106338#M147875</link>
      <description>The system file is:&lt;BR /&gt;&lt;BR /&gt;/tcb/files/auth/system&lt;BR /&gt;&lt;BR /&gt;Forgot to mention that.&lt;BR /&gt;&lt;BR /&gt;You can use getprdef and modprdef to view/modify these settings (or SAM).</description>
      <pubDate>Thu, 30 Oct 2003 08:54:27 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/trusted-systems/m-p/3106338#M147875</guid>
      <dc:creator>Brian Bergstrand</dc:creator>
      <dc:date>2003-10-30T08:54:27Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted Systems</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/trusted-systems/m-p/3106339#M147876</link>
      <description>Brian,&lt;BR /&gt;&lt;BR /&gt;I don't think they are syncing.  I set defaults through SAM, but they are not propagating to users and user accounts are set to use defaults, but that's not happening.</description>
      <pubDate>Thu, 30 Oct 2003 10:03:50 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/trusted-systems/m-p/3106339#M147876</guid>
      <dc:creator>Troy E. Miles</dc:creator>
      <dc:date>2003-10-30T10:03:50Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted Systems</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/trusted-systems/m-p/3106340#M147877</link>
      <description>Troy,&lt;BR /&gt;  Can you cut&amp;amp;paste the commands from /var/sam/log/samlog which sam has executed.&lt;BR /&gt;&lt;BR /&gt;  May be that can shed some light on this.&lt;BR /&gt;&lt;BR /&gt;HTH,&lt;BR /&gt;Umapathy</description>
      <pubDate>Thu, 30 Oct 2003 10:10:03 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/trusted-systems/m-p/3106340#M147877</guid>
      <dc:creator>Umapathy S</dc:creator>
      <dc:date>2003-10-30T10:10:03Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted Systems</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/trusted-systems/m-p/3106341#M147878</link>
      <description>The defaults don't "propogate", you will never see default values in a specific user's profile using the the *prpw commands. You will always see the default placeholder of -1. SAM does the same thing I belive. The only time you will see a value in a specific user's profile is if you override the defaults for that user. Even though you can't see them for each user, the system will enforce the defaults.&lt;BR /&gt;&lt;BR /&gt;Maybe I'm not understanding your problem though.&lt;BR /&gt;&lt;BR /&gt;HTH.</description>
      <pubDate>Thu, 30 Oct 2003 10:19:06 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/trusted-systems/m-p/3106341#M147878</guid>
      <dc:creator>Brian Bergstrand</dc:creator>
      <dc:date>2003-10-30T10:19:06Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted Systems</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/trusted-systems/m-p/3106342#M147879</link>
      <description>Brian,&lt;BR /&gt;&lt;BR /&gt;I understand you'll never see them in a user's profile, but when I run getprpw against a user's account it returns the -1 placeholder.  Other than running modprpw on the individual accounts, how am I to affect a global change.</description>
      <pubDate>Thu, 30 Oct 2003 10:23:09 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/trusted-systems/m-p/3106342#M147879</guid>
      <dc:creator>Troy E. Miles</dc:creator>
      <dc:date>2003-10-30T10:23:09Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted Systems</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/trusted-systems/m-p/3106343#M147880</link>
      <description>You set the global defaults with modprdef or with SAM -&amp;gt; Auditing and Security -&amp;gt; System Security Policies. These are the only ways to modify the globals, going through SAM -&amp;gt; Users or using modprpw only modifies a single user. (BTW, SAM uses modprdef to do the actual work).&lt;BR /&gt;&lt;BR /&gt;I've attached the man pages for the *prpw and the *prdef commands too.&lt;BR /&gt;&lt;BR /&gt;HTH.</description>
      <pubDate>Thu, 30 Oct 2003 10:33:29 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/trusted-systems/m-p/3106343#M147880</guid>
      <dc:creator>Brian Bergstrand</dc:creator>
      <dc:date>2003-10-30T10:33:29Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted Systems</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/trusted-systems/m-p/3106344#M147881</link>
      <description>Brian,&lt;BR /&gt;&lt;BR /&gt;Thanks for the help.  I didn't digest all of your response properly.  The problem I have is my company runs a security check script that uses getprpw.  Since, getprpw returns the placeholder (-1) and not the system default setting, the script returns an error saying password aging is not properly configured.&lt;BR /&gt;&lt;BR /&gt;I'll have to pass this information on to them.&lt;BR /&gt;&lt;BR /&gt;Thanks again.</description>
      <pubDate>Thu, 30 Oct 2003 10:39:00 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/trusted-systems/m-p/3106344#M147881</guid>
      <dc:creator>Troy E. Miles</dc:creator>
      <dc:date>2003-10-30T10:39:00Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted Systems</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/trusted-systems/m-p/3106345#M147882</link>
      <description>I see. You'll have to modify the script to query the system defaults with getprdef, then if getprpw returns -1, replace the -1 with the default value. This will then show the correct value for any user who is using the default. If getprpw doesn't return -1, then the default has been overridden by the user specific value, and no replacement will be necessary.&lt;BR /&gt;&lt;BR /&gt;The man pages I attached in the previous post will explain how to use getprdef.&lt;BR /&gt;&lt;BR /&gt;HTH.</description>
      <pubDate>Thu, 30 Oct 2003 10:52:07 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/trusted-systems/m-p/3106345#M147882</guid>
      <dc:creator>Brian Bergstrand</dc:creator>
      <dc:date>2003-10-30T10:52:07Z</dc:date>
    </item>
  </channel>
</rss>

