<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Trusted Mode Root Lockout in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/trusted-mode-root-lockout/m-p/3326346#M188380</link>
    <description>Hi Randy,&lt;BR /&gt;&lt;BR /&gt;You can change the values for root either as RAC suggested, or via SAM.  It's also worth looking at the output of /usr/lbin/getprpw root regularly to see attempted login times and ttys to give you a clue as to what's going on.&lt;BR /&gt;&lt;BR /&gt;Which logs do you suspect are filling up?  If your system is configured such that / can fill up with logs then it's possible that this is the cause.  However, in this instance I believe that root is only locked out because there's no way of writing logs when you attempt to login, rather than being locked out within the /tcb area.&lt;BR /&gt;&lt;BR /&gt;regards,&lt;BR /&gt;&lt;BR /&gt;Darren.</description>
    <pubDate>Thu, 08 Jul 2004 08:25:07 GMT</pubDate>
    <dc:creator>Darren Prior</dc:creator>
    <dc:date>2004-07-08T08:25:07Z</dc:date>
    <item>
      <title>Trusted Mode Root Lockout</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/trusted-mode-root-lockout/m-p/3326342#M188376</link>
      <description>Is there a way to force trusted mode to NOT lockout the root account?  &lt;BR /&gt;&lt;BR /&gt;We have not identified exactly why the root account is getting locked out but we think it is do to logs filling up.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 08 Jul 2004 07:19:24 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/trusted-mode-root-lockout/m-p/3326342#M188376</guid>
      <dc:creator>Randy Gelineau</dc:creator>
      <dc:date>2004-07-08T07:19:24Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted Mode Root Lockout</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/trusted-mode-root-lockout/m-p/3326343#M188377</link>
      <description>On trusted system, three unsuccessfuly logins attempts will lock the account. This is controlled by umaxlntr.&lt;BR /&gt;&lt;BR /&gt;/usr/lbin/getprdef -m umaxlntr&lt;BR /&gt;/usr/lbin/modprdef -m umaxlntr=5&lt;BR /&gt;&lt;BR /&gt;Now 5 unsuccessfult logins attempts will lock the account&lt;BR /&gt;&lt;BR /&gt;Anil</description>
      <pubDate>Thu, 08 Jul 2004 07:27:08 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/trusted-mode-root-lockout/m-p/3326343#M188377</guid>
      <dc:creator>RAC_1</dc:creator>
      <dc:date>2004-07-08T07:27:08Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted Mode Root Lockout</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/trusted-mode-root-lockout/m-p/3326344#M188378</link>
      <description>HI,&lt;BR /&gt;Have a look at the doc attached.&lt;BR /&gt;Hope that helps.&lt;BR /&gt;Regards,</description>
      <pubDate>Thu, 08 Jul 2004 07:46:54 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/trusted-mode-root-lockout/m-p/3326344#M188378</guid>
      <dc:creator>Bharat Katkar</dc:creator>
      <dc:date>2004-07-08T07:46:54Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted Mode Root Lockout</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/trusted-mode-root-lockout/m-p/3326345#M188379</link>
      <description>root will not be able to get into the machine to run any commands if its account is locked.  &lt;BR /&gt;&lt;BR /&gt;I would rather not boot into single user mode to unlock it.  This is the situation we are trying to avoid.</description>
      <pubDate>Thu, 08 Jul 2004 07:59:17 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/trusted-mode-root-lockout/m-p/3326345#M188379</guid>
      <dc:creator>Randy Gelineau</dc:creator>
      <dc:date>2004-07-08T07:59:17Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted Mode Root Lockout</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/trusted-mode-root-lockout/m-p/3326346#M188380</link>
      <description>Hi Randy,&lt;BR /&gt;&lt;BR /&gt;You can change the values for root either as RAC suggested, or via SAM.  It's also worth looking at the output of /usr/lbin/getprpw root regularly to see attempted login times and ttys to give you a clue as to what's going on.&lt;BR /&gt;&lt;BR /&gt;Which logs do you suspect are filling up?  If your system is configured such that / can fill up with logs then it's possible that this is the cause.  However, in this instance I believe that root is only locked out because there's no way of writing logs when you attempt to login, rather than being locked out within the /tcb area.&lt;BR /&gt;&lt;BR /&gt;regards,&lt;BR /&gt;&lt;BR /&gt;Darren.</description>
      <pubDate>Thu, 08 Jul 2004 08:25:07 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/trusted-mode-root-lockout/m-p/3326346#M188380</guid>
      <dc:creator>Darren Prior</dc:creator>
      <dc:date>2004-07-08T08:25:07Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted Mode Root Lockout</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/trusted-mode-root-lockout/m-p/3326347#M188381</link>
      <description>You can log in through console.&lt;BR /&gt;&lt;BR /&gt;Anil</description>
      <pubDate>Thu, 08 Jul 2004 08:33:53 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/trusted-mode-root-lockout/m-p/3326347#M188381</guid>
      <dc:creator>RAC_1</dc:creator>
      <dc:date>2004-07-08T08:33:53Z</dc:date>
    </item>
    <item>
      <title>Re: Trusted Mode Root Lockout</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/trusted-mode-root-lockout/m-p/3326348#M188382</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;If the root account is locked, it will allow you to login from the console and you can enable the account by running "modprpw -k root".&lt;BR /&gt;&lt;BR /&gt;If you do not want your root account locked, then turn off (make it 99) maximum number of unsuccessful attempts as previously mentioned. If you are planning to do so, then make sure you have /etc/securetty file so that no one will be able to login from other than console. Have a mechanism to notify you after certain number (say 10) of successive unsuccesful attempts so you can keep an eye on malicious attempts.&lt;BR /&gt;&lt;BR /&gt;To find out why root account is getting locked, look at your 'lastb' and the 'unsuccessful su - root' entries in /var/adm/sulog. &lt;BR /&gt;&lt;BR /&gt;-Sri</description>
      <pubDate>Thu, 08 Jul 2004 08:38:52 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/trusted-mode-root-lockout/m-p/3326348#M188382</guid>
      <dc:creator>Sridhar Bhaskarla</dc:creator>
      <dc:date>2004-07-08T08:38:52Z</dc:date>
    </item>
  </channel>
</rss>

