<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: tsconvert options in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/tsconvert-options/m-p/3286166#M181209</link>
    <description>Hi Jeff,&lt;BR /&gt;&lt;BR /&gt;I suspect SAM's doing more than just running tsconvert -c.&lt;BR /&gt;&lt;BR /&gt;Why don't you let SAM do a conversion &amp;amp; then check the /var/sam/log/samlog to see just exactly what it did?&lt;BR /&gt;&lt;BR /&gt;My 2 cents,&lt;BR /&gt;Jeff</description>
    <pubDate>Tue, 25 May 2004 10:43:17 GMT</pubDate>
    <dc:creator>Jeff Schussele</dc:creator>
    <dc:date>2004-05-25T10:43:17Z</dc:date>
    <item>
      <title>tsconvert options</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/tsconvert-options/m-p/3286162#M181205</link>
      <description>I've looked around ITRC and newsgroups, but haven't seen the info. I know -r converts back to an untrusted system since that seems to get mentioned all the time as people try to convert back. What do the -c and -p options do?</description>
      <pubDate>Tue, 25 May 2004 10:05:12 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/tsconvert-options/m-p/3286162#M181205</guid>
      <dc:creator>Jeff_Traigle</dc:creator>
      <dc:date>2004-05-25T10:05:12Z</dc:date>
    </item>
    <item>
      <title>Re: tsconvert options</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/tsconvert-options/m-p/3286163#M181206</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Patch PHCO_17218 mentions doing a 'tsconvert -p':&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;PHCO_17218 cumulative fix for SAM convert/unconvert &lt;BR /&gt; If you are already in trusted mode when you install the&lt;BR /&gt; patch then execute "/usr/lbin/tsconvert -p"&lt;BR /&gt; to pick up any missing entries.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;JP&lt;BR /&gt;</description>
      <pubDate>Tue, 25 May 2004 10:16:34 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/tsconvert-options/m-p/3286163#M181206</guid>
      <dc:creator>John Poff</dc:creator>
      <dc:date>2004-05-25T10:16:34Z</dc:date>
    </item>
    <item>
      <title>Re: tsconvert options</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/tsconvert-options/m-p/3286164#M181207</link>
      <description>-c option is actually is used to convert TO a trusted system as far as I can remember but it has been a while since we are only doing the converts via SAM as suggested by hp for support considerations.</description>
      <pubDate>Tue, 25 May 2004 10:18:10 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/tsconvert-options/m-p/3286164#M181207</guid>
      <dc:creator>Mel Burslan</dc:creator>
      <dc:date>2004-05-25T10:18:10Z</dc:date>
    </item>
    <item>
      <title>Re: tsconvert options</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/tsconvert-options/m-p/3286165#M181208</link>
      <description>Ok. -c does seem to be "convert", which is the default action if no option is provided.&lt;BR /&gt;&lt;BR /&gt;Interesting though... I tried running tsconvert on a system and it didn't seem to work:&lt;BR /&gt;&lt;BR /&gt;omega# /usr/lbin/tsconvert -c&lt;BR /&gt;Creating secure password database...&lt;BR /&gt;Directories created.&lt;BR /&gt;Making default files.&lt;BR /&gt;System default file created...&lt;BR /&gt;Terminal default file created...&lt;BR /&gt;Device assignment file created...&lt;BR /&gt;Moving passwords...&lt;BR /&gt;Can't write protected database;&lt;BR /&gt;password file unchanged.</description>
      <pubDate>Tue, 25 May 2004 10:31:26 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/tsconvert-options/m-p/3286165#M181208</guid>
      <dc:creator>Jeff_Traigle</dc:creator>
      <dc:date>2004-05-25T10:31:26Z</dc:date>
    </item>
    <item>
      <title>Re: tsconvert options</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/tsconvert-options/m-p/3286166#M181209</link>
      <description>Hi Jeff,&lt;BR /&gt;&lt;BR /&gt;I suspect SAM's doing more than just running tsconvert -c.&lt;BR /&gt;&lt;BR /&gt;Why don't you let SAM do a conversion &amp;amp; then check the /var/sam/log/samlog to see just exactly what it did?&lt;BR /&gt;&lt;BR /&gt;My 2 cents,&lt;BR /&gt;Jeff</description>
      <pubDate>Tue, 25 May 2004 10:43:17 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/tsconvert-options/m-p/3286166#M181209</guid>
      <dc:creator>Jeff Schussele</dc:creator>
      <dc:date>2004-05-25T10:43:17Z</dc:date>
    </item>
    <item>
      <title>Re: tsconvert options</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/tsconvert-options/m-p/3286167#M181210</link>
      <description>I did. That's all it appears to do and it generates the same output without doing the conversion.</description>
      <pubDate>Tue, 25 May 2004 10:44:36 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/tsconvert-options/m-p/3286167#M181210</guid>
      <dc:creator>Jeff_Traigle</dc:creator>
      <dc:date>2004-05-25T10:44:36Z</dc:date>
    </item>
    <item>
      <title>Re: tsconvert options</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/tsconvert-options/m-p/3286168#M181211</link>
      <description>Jeff beat me to the same suggestion. I second his opinion. :)</description>
      <pubDate>Tue, 25 May 2004 10:45:13 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/tsconvert-options/m-p/3286168#M181211</guid>
      <dc:creator>Mel Burslan</dc:creator>
      <dc:date>2004-05-25T10:45:13Z</dc:date>
    </item>
    <item>
      <title>Re: tsconvert options</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/tsconvert-options/m-p/3286169#M181212</link>
      <description>The protected database gets written to /tcb/files/auth/*/*, so you might poke around that directory tree and see if everything looks ok.  Do you have another trusted system to compare it to?&lt;BR /&gt;&lt;BR /&gt;JP&lt;BR /&gt;</description>
      <pubDate>Tue, 25 May 2004 10:48:01 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/tsconvert-options/m-p/3286169#M181212</guid>
      <dc:creator>John Poff</dc:creator>
      <dc:date>2004-05-25T10:48:01Z</dc:date>
    </item>
    <item>
      <title>Re: tsconvert options</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/tsconvert-options/m-p/3286170#M181213</link>
      <description>No, I don't. Was just investigating it for the first time because of new audit requirements that systems in the building use shadow password.&lt;BR /&gt;&lt;BR /&gt;Here's the ownship of /. I can't trust this is the way it should be offhand because so many file permissions have been unwisely modified on these systems over the years before I showed up in January.&lt;BR /&gt;&lt;BR /&gt;omega# ls -ld /&lt;BR /&gt;drwxr-xr-x  21 root       root          8192 May 25 07:37 /&lt;BR /&gt;&lt;BR /&gt;Definitely no space problems at 20% used and 160MB free.</description>
      <pubDate>Tue, 25 May 2004 11:00:28 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/tsconvert-options/m-p/3286170#M181213</guid>
      <dc:creator>Jeff_Traigle</dc:creator>
      <dc:date>2004-05-25T11:00:28Z</dc:date>
    </item>
    <item>
      <title>Re: tsconvert options</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/tsconvert-options/m-p/3286171#M181214</link>
      <description>Check if there is already a /tcb directory or file. In an untrusted system, this will not exist. tsconvert will create the /tcb directory structure. However, as you mentioned, some sysadmins with Unix For Newbies books have been loose on the system and may have compromised a lot of security features. Check /etc/passwd (should be 644 or 444 owned by root) and /etc/group. Check the syntax in both files with pwck and grpck respectively. Check that /etc is 755 and I would run the following command just to look fo overall problems:&lt;BR /&gt; &lt;BR /&gt;find /etc /sbin /stand -perm -002 -exec ll {} \;&lt;BR /&gt; &lt;BR /&gt;which should produce no entries. If something shows up, the contents of the file or directory cannot be trusted.</description>
      <pubDate>Tue, 25 May 2004 11:15:23 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/tsconvert-options/m-p/3286171#M181214</guid>
      <dc:creator>Bill Hassell</dc:creator>
      <dc:date>2004-05-25T11:15:23Z</dc:date>
    </item>
    <item>
      <title>Re: tsconvert options</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/tsconvert-options/m-p/3286172#M181215</link>
      <description>Bingo! pwck revealed a bogus line with username usr/bin... looks like someone was hacking around with this passwd file at some point and messed up. Good list of things to check.</description>
      <pubDate>Tue, 25 May 2004 11:26:40 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/tsconvert-options/m-p/3286172#M181215</guid>
      <dc:creator>Jeff_Traigle</dc:creator>
      <dc:date>2004-05-25T11:26:40Z</dc:date>
    </item>
  </channel>
</rss>

