<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Set PASSWORD within the users .profile in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/set-password-within-the-users-profile/m-p/3265621#M177712</link>
    <description>Hi Patrick,&lt;BR /&gt;We have user similar like and we set his policy such that pasword never expires.&lt;BR /&gt;I don't see any harm in that. In case you want to keep on modifiying the password let the administrator spare somtime doing that once in 15 days.&lt;BR /&gt;</description>
    <pubDate>Mon, 03 May 2004 08:22:50 GMT</pubDate>
    <dc:creator>Bharat Katkar</dc:creator>
    <dc:date>2004-05-03T08:22:50Z</dc:date>
    <item>
      <title>Set PASSWORD within the users .profile</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/set-password-within-the-users-profile/m-p/3265617#M177708</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;I am facing an unique situation. I have a user who uses a thin client application software namely Oracle Financial Analyser to access the Oracle Database for reporting purposes. This thin client needs an OS user to be available for this purpose. Initially what i did is to restrict all telnet access for this user and only allow ftp access. this i have achieved by assigning a "/usr/bin/false" shell to this user. &lt;BR /&gt;&lt;BR /&gt;Now the problem is, what happens when the user's OS level password expires, which is set to 30 days. Since the user does not have any telnet access, he cannot change/choose another password. &lt;BR /&gt;&lt;BR /&gt;Suppose i give the user telnet access and then edit his .profile file to include only the command for password changing and then exit. This is an idea i had. &lt;BR /&gt;&lt;BR /&gt;Please give me any/all suggestion on how to go about achieving this. To sum it up the user needs to be able to change his OS login password every 30 days, in order to access the Oracle Financial Analyser apps. And i need to keep it secure. Don't want the user to have any shell access.&lt;BR /&gt;&lt;BR /&gt;Need all the ideas, scripts etc that i can get to achieve this. Thanks to everyone in advance.&lt;BR /&gt;&lt;BR /&gt;Many thanks &amp;amp; Regards,&lt;BR /&gt;&lt;BR /&gt;Patrick</description>
      <pubDate>Mon, 03 May 2004 07:58:54 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/set-password-within-the-users-profile/m-p/3265617#M177708</guid>
      <dc:creator>patrick coutinho</dc:creator>
      <dc:date>2004-05-03T07:58:54Z</dc:date>
    </item>
    <item>
      <title>Re: Set PASSWORD within the users .profile</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/set-password-within-the-users-profile/m-p/3265618#M177709</link>
      <description>Do u really wants his password to be expired ?. Why don't u change the policy ?&lt;BR /&gt;&lt;BR /&gt;Kaps</description>
      <pubDate>Mon, 03 May 2004 08:06:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/set-password-within-the-users-profile/m-p/3265618#M177709</guid>
      <dc:creator>KapilRaj</dc:creator>
      <dc:date>2004-05-03T08:06:21Z</dc:date>
    </item>
    <item>
      <title>Re: Set PASSWORD within the users .profile</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/set-password-within-the-users-profile/m-p/3265619#M177710</link>
      <description>If you use his .profile to make passwd and exit, and if he can do ftp, he can replace his own .profile...&lt;BR /&gt;&lt;BR /&gt;You should maybe add /usr/bin/passwd as a valid shell in /etc/shells and give him this shell. As long as he has a valid shell he can ftp, but when he makes telnet, it launches passwd then exit.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;&lt;BR /&gt;Fred&lt;BR /&gt;</description>
      <pubDate>Mon, 03 May 2004 08:10:36 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/set-password-within-the-users-profile/m-p/3265619#M177710</guid>
      <dc:creator>Fred Ruffet</dc:creator>
      <dc:date>2004-05-03T08:10:36Z</dc:date>
    </item>
    <item>
      <title>Re: Set PASSWORD within the users .profile</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/set-password-within-the-users-profile/m-p/3265620#M177711</link>
      <description>Patrick,&lt;BR /&gt;&lt;BR /&gt;I disable the user, only when they call I enable it for the periode they need.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Robert-Jan</description>
      <pubDate>Mon, 03 May 2004 08:11:43 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/set-password-within-the-users-profile/m-p/3265620#M177711</guid>
      <dc:creator>Robert-Jan Goossens</dc:creator>
      <dc:date>2004-05-03T08:11:43Z</dc:date>
    </item>
    <item>
      <title>Re: Set PASSWORD within the users .profile</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/set-password-within-the-users-profile/m-p/3265621#M177712</link>
      <description>Hi Patrick,&lt;BR /&gt;We have user similar like and we set his policy such that pasword never expires.&lt;BR /&gt;I don't see any harm in that. In case you want to keep on modifiying the password let the administrator spare somtime doing that once in 15 days.&lt;BR /&gt;</description>
      <pubDate>Mon, 03 May 2004 08:22:50 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/set-password-within-the-users-profile/m-p/3265621#M177712</guid>
      <dc:creator>Bharat Katkar</dc:creator>
      <dc:date>2004-05-03T08:22:50Z</dc:date>
    </item>
    <item>
      <title>Re: Set PASSWORD within the users .profile</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/set-password-within-the-users-profile/m-p/3265622#M177713</link>
      <description>Give the user sudo access to change the password only for that account and have them login in though a regular account through ssh of their own to do it :).  That would save you some headache, but not the user.</description>
      <pubDate>Mon, 03 May 2004 21:31:40 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/set-password-within-the-users-profile/m-p/3265622#M177713</guid>
      <dc:creator>generic_1</dc:creator>
      <dc:date>2004-05-03T21:31:40Z</dc:date>
    </item>
    <item>
      <title>Re: Set PASSWORD within the users .profile</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/set-password-within-the-users-profile/m-p/3265623#M177714</link>
      <description>hello patrick,&lt;BR /&gt;&lt;BR /&gt;         The best option would be to make the password's never expire. You can intervene as administrator if the passwords nedd be changed.To set a non-expiring password do as follows.&lt;BR /&gt;&lt;BR /&gt;    For non-expiring password the time frame for max days(-x) should be less than time frame meant for min days(-n).for exammple if the user is "tom"&lt;BR /&gt;&lt;BR /&gt;     Then,&lt;BR /&gt; #passwd -x 1 -n 2 tom&lt;BR /&gt;&lt;BR /&gt;I hope this solves the issue,&lt;BR /&gt;&lt;BR /&gt;regard's&lt;BR /&gt;senthil</description>
      <pubDate>Tue, 04 May 2004 00:13:57 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/set-password-within-the-users-profile/m-p/3265623#M177714</guid>
      <dc:creator>Senthil Kumar .A_1</dc:creator>
      <dc:date>2004-05-04T00:13:57Z</dc:date>
    </item>
    <item>
      <title>Re: Set PASSWORD within the users .profile</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/set-password-within-the-users-profile/m-p/3265624#M177715</link>
      <description>Just an added word on senthil's advice:&lt;BR /&gt;&lt;BR /&gt;the value of 'x' must be 0, while 'n' can be anything greater than '0', in order to prevent the user from changing the passwd, at least on my untrusted systems.&lt;BR /&gt;&lt;BR /&gt;As an aside: if root changes the passwd (ie: 'passwd &lt;USERID&gt;') then 'passwd -x 0 -n 1 &lt;USERID&gt;' must be run again afterward.  The passwd cmd by itself will remove the passwd aging bits, in this (x &amp;lt; n) combination.  Again this is on my untrusted systems.&lt;BR /&gt;&lt;BR /&gt;Looking at this has solved the puzzle of disappearing 'root only passwd changes' on my systems.  If I am missing a patch or something, I don't know.&lt;/USERID&gt;&lt;/USERID&gt;</description>
      <pubDate>Tue, 04 May 2004 07:43:58 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/set-password-within-the-users-profile/m-p/3265624#M177715</guid>
      <dc:creator>Robert True</dc:creator>
      <dc:date>2004-05-04T07:43:58Z</dc:date>
    </item>
    <item>
      <title>Re: Set PASSWORD within the users .profile</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/set-password-within-the-users-profile/m-p/3265625#M177716</link>
      <description>Thanks everyone. My problem was resolved with Fred's advice. I have used the shell /usr/bin/passwd and now the user can only change his password on login and then exits. Thanks Fred, and thanks everyone else who have contributed with their valuable advice. Points assigned. Sorry for the delay.&lt;BR /&gt;&lt;BR /&gt;One question, as Fred put it, if a user has ftp access only, he can still ftp a .profile file of his own creation to his directory and then get full privileges. That's true is it not ? Any ideas on how to address this security issue.&lt;BR /&gt;&lt;BR /&gt;Thanks &amp;amp; Rgds&lt;BR /&gt;&lt;BR /&gt;Pat</description>
      <pubDate>Sat, 08 May 2004 02:56:38 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/set-password-within-the-users-profile/m-p/3265625#M177716</guid>
      <dc:creator>patrick coutinho</dc:creator>
      <dc:date>2004-05-08T02:56:38Z</dc:date>
    </item>
  </channel>
</rss>

