<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: changing to trusted mode in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/changing-to-trusted-mode/m-p/3147969#M156936</link>
    <description>John,&lt;BR /&gt;&lt;BR /&gt;From what I know, converting to a trusted system will enable password aging to a default setting (I think 90 day's). What you can do is 1 or 2 weeks before converting, send all users a message to change their password (max length 8 chars) and then convert the system. This will not avoid a password change for the users, but they will not be prompted to change their passwords all at once(after the tsconvert), because the password's will not be 90 day's old.&lt;BR /&gt;&lt;BR /&gt;regards,&lt;BR /&gt;&lt;BR /&gt;Peter</description>
    <pubDate>Thu, 18 Dec 2003 06:12:19 GMT</pubDate>
    <dc:creator>Hoefnix</dc:creator>
    <dc:date>2003-12-18T06:12:19Z</dc:date>
    <item>
      <title>changing to trusted mode</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/changing-to-trusted-mode/m-p/3147968#M156935</link>
      <description>I have several 10.10 and 10.20 servers in non trusted mode. I intend to use SAM to covvert to trusted mode. I believe that once trusted all the users are going to be prompted to forced to change there password. This will cause me the biggest headache imaginable. &lt;BR /&gt;&lt;BR /&gt;how can i avoid this happening ?&lt;BR /&gt;&lt;BR /&gt;I will also be patching first and have seen on different threads different suggested patches so which are the right ones ?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;:-) John.</description>
      <pubDate>Thu, 18 Dec 2003 05:50:29 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/changing-to-trusted-mode/m-p/3147968#M156935</guid>
      <dc:creator>J_115</dc:creator>
      <dc:date>2003-12-18T05:50:29Z</dc:date>
    </item>
    <item>
      <title>Re: changing to trusted mode</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/changing-to-trusted-mode/m-p/3147969#M156936</link>
      <description>John,&lt;BR /&gt;&lt;BR /&gt;From what I know, converting to a trusted system will enable password aging to a default setting (I think 90 day's). What you can do is 1 or 2 weeks before converting, send all users a message to change their password (max length 8 chars) and then convert the system. This will not avoid a password change for the users, but they will not be prompted to change their passwords all at once(after the tsconvert), because the password's will not be 90 day's old.&lt;BR /&gt;&lt;BR /&gt;regards,&lt;BR /&gt;&lt;BR /&gt;Peter</description>
      <pubDate>Thu, 18 Dec 2003 06:12:19 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/changing-to-trusted-mode/m-p/3147969#M156936</guid>
      <dc:creator>Hoefnix</dc:creator>
      <dc:date>2003-12-18T06:12:19Z</dc:date>
    </item>
    <item>
      <title>Re: changing to trusted mode</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/changing-to-trusted-mode/m-p/3147970#M156937</link>
      <description>The Trusted conversion process will invalidate all user passwords. However, you can run modprpw (an undocumented command in the obsolete 10.xx systems) to fix all the entries to start password aging at today's date and enable the current passwords. The man page for modprpw is located at &lt;A href="http://docs.hp.com" target="_blank"&gt;http://docs.hp.com&lt;/A&gt; and it is used:&lt;BR /&gt; &lt;BR /&gt;/usr/lbin/modprpw -V&lt;BR /&gt; &lt;BR /&gt;Be sure to get copies of man [ages for modprpw and getprpw. Your man page for authcap is also useful.</description>
      <pubDate>Thu, 18 Dec 2003 08:38:17 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/changing-to-trusted-mode/m-p/3147970#M156937</guid>
      <dc:creator>Bill Hassell</dc:creator>
      <dc:date>2003-12-18T08:38:17Z</dc:date>
    </item>
    <item>
      <title>Re: changing to trusted mode</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/changing-to-trusted-mode/m-p/3147971#M156938</link>
      <description>John,&lt;BR /&gt;&lt;BR /&gt;I have installed a fresh copy of 10.20 on a workstation created 2 new users. I have changed system to trusted mode using SAM. I have not applied any patches yet&lt;BR /&gt;&lt;BR /&gt;now the system is trusted I have telnet session to system and login as both the new users and have not been asked by the system to change the password.&lt;BR /&gt;&lt;BR /&gt;Could the changing of the password be related to having password aging in place before a conversion to trusted mode.&lt;BR /&gt;&lt;BR /&gt;Bill will probably be able to clarify this&lt;BR /&gt;&lt;BR /&gt;John Carr :-)</description>
      <pubDate>Thu, 18 Dec 2003 08:51:47 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/changing-to-trusted-mode/m-p/3147971#M156938</guid>
      <dc:creator>John Carr_2</dc:creator>
      <dc:date>2003-12-18T08:51:47Z</dc:date>
    </item>
    <item>
      <title>Re: changing to trusted mode</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/changing-to-trusted-mode/m-p/3147972#M156939</link>
      <description>/usr/lbin/modprpw -V&lt;BR /&gt;&lt;BR /&gt;to avoid password expiry.</description>
      <pubDate>Thu, 18 Dec 2003 08:55:00 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/changing-to-trusted-mode/m-p/3147972#M156939</guid>
      <dc:creator>RAC_1</dc:creator>
      <dc:date>2003-12-18T08:55:00Z</dc:date>
    </item>
    <item>
      <title>Re: changing to trusted mode</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/changing-to-trusted-mode/m-p/3147973#M156940</link>
      <description>Hi John,&lt;BR /&gt;&lt;BR /&gt;See my post in this thread for 10.20 patches: &lt;A href="http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=287767" target="_blank"&gt;http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=287767&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Patches can be superceded, so it's possible that you've seen some older threads that mention older versions of these patches.  10.20 is now an obsolete OS, so patching for it isn't going to change (with the possible exception of security issues.)&lt;BR /&gt;&lt;BR /&gt;regards,&lt;BR /&gt;&lt;BR /&gt;Darren.</description>
      <pubDate>Thu, 18 Dec 2003 10:08:17 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/changing-to-trusted-mode/m-p/3147973#M156940</guid>
      <dc:creator>Darren Prior</dc:creator>
      <dc:date>2003-12-18T10:08:17Z</dc:date>
    </item>
    <item>
      <title>Re: changing to trusted mode</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/changing-to-trusted-mode/m-p/3147974#M156941</link>
      <description>I tried converting a 10.20 system using SAM to Trusted with 2 users, one with a password expiration setup and one without. After conversion, both accounts were still active. However, SAM uses modprdef after conversion which is not true if you use the tsconvert command. And for the user with pw expiration set, converting either direction maintained the current setting. /usr/bin/modprpw -V fixes all passwords in the Trusted system (leave a root window open).&lt;BR /&gt; &lt;BR /&gt;You can freely convert and un-convert using /usr/lbin/tsconvert (-r to revert back, -c to convert to Trusted). The only issue is with password length. If users on an untrusted system are ttyping in more than 8 characters for a password, on the untrusted system, characters 9+ were simply ignored. But on a Trusted system, every character in the password answer will be used to match the current password. Similarly, if a user chooses a 9+ character password while the system is Trusted and then the system is converted back to un-trusted, the user can still type the extra characters as they will be ignored again.</description>
      <pubDate>Thu, 18 Dec 2003 10:09:55 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/changing-to-trusted-mode/m-p/3147974#M156941</guid>
      <dc:creator>Bill Hassell</dc:creator>
      <dc:date>2003-12-18T10:09:55Z</dc:date>
    </item>
    <item>
      <title>Re: changing to trusted mode</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/changing-to-trusted-mode/m-p/3147975#M156942</link>
      <description>I have just tested again and if i entrust using tsconvert the user is prompted to change password. If I entrust using SAM the user is NOT requested to change password.&lt;BR /&gt;&lt;BR /&gt;have trusted with tsconvert and run command modprpw -V and the user was not prompted to change password.&lt;BR /&gt;&lt;BR /&gt;Bill was spot on&lt;BR /&gt;John</description>
      <pubDate>Thu, 18 Dec 2003 12:05:15 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/changing-to-trusted-mode/m-p/3147975#M156942</guid>
      <dc:creator>John Carr_2</dc:creator>
      <dc:date>2003-12-18T12:05:15Z</dc:date>
    </item>
  </channel>
</rss>

