<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: user list in SAM in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/user-list-in-sam/m-p/3559819#M226276</link>
    <description>well, I have to disagree with "don't delete those users" comment here. Yeah, you do not go in and delete them all but if your server is not going to use some sort of web server or app server, you do not need www account. Heck even if you are going to run it but run it under a predefined user, you will not need this account. Another candidate for deletion is hpdb account. Even some hp engineers I talked to, does not remember what it used to be used for anymore. Most probably it was something related to hp's old database, allbase, but do you use it ? I sure don't. So, why do I need it as a sore point when I get SOX audited. &lt;BR /&gt;&lt;BR /&gt;So my suggestion is sysadm of each system needs to decide if they have any use for any of these accounts and delete the ones he/she needs on his/her own discretion.&lt;BR /&gt;&lt;BR /&gt;to see if a user has any files/directories associated by this username, run the command:&lt;BR /&gt;&lt;BR /&gt;find / -user $USERNAME &lt;BR /&gt;&lt;BR /&gt;(do it when your system has very low utilization, as this will hammer your disks pretty bad) &lt;BR /&gt;&lt;BR /&gt;and see if it lists anything. If it does, decide if these files are used for anything related to the purpose of this server. For instance, if you are going to run a very specific application on your server and you get an apache web server installed with user id www, do you really want it there, as a security threat ? &lt;BR /&gt;&lt;BR /&gt;This issue is more political than technical. So, every data center should make their own decisions about which of the default users they get handed upon a fresh system installation they want to delete and which ones to keep.&lt;BR /&gt;&lt;BR /&gt;Hope this helps.</description>
    <pubDate>Sat, 18 Jun 2005 13:37:13 GMT</pubDate>
    <dc:creator>Mel Burslan</dc:creator>
    <dc:date>2005-06-18T13:37:13Z</dc:date>
    <item>
      <title>user list in SAM</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/user-list-in-sam/m-p/3559815#M226272</link>
      <description>Hi all where can I find any doc related to the list of user in SAM, like who is the user, the function and the purpose to create esp default one. E.g bin,daemon,hpdb,lp,,nuucp,uucp,www and etc&lt;BR /&gt;&lt;BR /&gt;Thanks</description>
      <pubDate>Tue, 07 Jun 2005 20:18:03 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/user-list-in-sam/m-p/3559815#M226272</guid>
      <dc:creator>Fauziah Mahdan</dc:creator>
      <dc:date>2005-06-07T20:18:03Z</dc:date>
    </item>
    <item>
      <title>Re: user list in SAM</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/user-list-in-sam/m-p/3559816#M226273</link>
      <description>Hi Fauziah,&lt;BR /&gt;&lt;BR /&gt;These users are pseudo and special accounts that is used by subsystem.&lt;BR /&gt;&lt;BR /&gt;FROM MANAGING STANDARDS AND PASSWORDS&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://docs.hp.com/en/5990-8172/ch08s03.html#bjeieaae" target="_blank"&gt;http://docs.hp.com/en/5990-8172/ch08s03.html#bjeieaae&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;By tradition, the /etc/passwd file contains numerous â  pseudo-accountsâ   â   entries not associated with individual users and which do not have true interactive login shells.&lt;BR /&gt;&lt;BR /&gt;Some of these entries, such as date, who, sync, and tty, evolved strictly for user convenience, providing commands that could be executed without logging in. To tighten security, they have been eliminated in the distributed /etc/passwd so that these programs can be run only by a user who is logged in.&lt;BR /&gt;&lt;BR /&gt;Other such entries remain in /etc/passwd because they are owners of files. Programs with owners such as adm, bin, daemon, hpdb, lp, and uucp encompass entire subsystems, and represent a special case. Since they grant access to files they protect or use, these programs must be allowed to function as pseudo-accounts, with entries listed in /etc/passwd. The customary pseudo- and special accounts are shown in Figure 8-1, â  Pseudo- and Special System Accountsâ  .</description>
      <pubDate>Tue, 07 Jun 2005 21:09:54 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/user-list-in-sam/m-p/3559816#M226273</guid>
      <dc:creator>Paul_481</dc:creator>
      <dc:date>2005-06-07T21:09:54Z</dc:date>
    </item>
    <item>
      <title>Re: user list in SAM</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/user-list-in-sam/m-p/3559817#M226274</link>
      <description>hi,&lt;BR /&gt;&lt;BR /&gt;some threads on these users, just in case u r ask by auditor for the function of these users:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=142049" target="_blank"&gt;http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=142049&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=232066" target="_blank"&gt;http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=232066&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;also, do not delete them.&lt;BR /&gt;&lt;BR /&gt;regards.</description>
      <pubDate>Tue, 07 Jun 2005 21:32:16 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/user-list-in-sam/m-p/3559817#M226274</guid>
      <dc:creator>Joseph Loo</dc:creator>
      <dc:date>2005-06-07T21:32:16Z</dc:date>
    </item>
    <item>
      <title>Re: user list in SAM</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/user-list-in-sam/m-p/3559818#M226275</link>
      <description>hi Fauz...&lt;BR /&gt;&lt;BR /&gt;dont ever delete these users...&lt;BR /&gt;&lt;BR /&gt;as these are the default users of unix ...&lt;BR /&gt;&lt;BR /&gt;and users cannot login with any of these usernames ( root or rootequiv can login by changing the passwd).. ... so dont panic! &lt;BR /&gt;&lt;BR /&gt;Regards&lt;BR /&gt;&lt;BR /&gt;Vinod k</description>
      <pubDate>Sat, 18 Jun 2005 04:24:30 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/user-list-in-sam/m-p/3559818#M226275</guid>
      <dc:creator>vinod_25</dc:creator>
      <dc:date>2005-06-18T04:24:30Z</dc:date>
    </item>
    <item>
      <title>Re: user list in SAM</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/user-list-in-sam/m-p/3559819#M226276</link>
      <description>well, I have to disagree with "don't delete those users" comment here. Yeah, you do not go in and delete them all but if your server is not going to use some sort of web server or app server, you do not need www account. Heck even if you are going to run it but run it under a predefined user, you will not need this account. Another candidate for deletion is hpdb account. Even some hp engineers I talked to, does not remember what it used to be used for anymore. Most probably it was something related to hp's old database, allbase, but do you use it ? I sure don't. So, why do I need it as a sore point when I get SOX audited. &lt;BR /&gt;&lt;BR /&gt;So my suggestion is sysadm of each system needs to decide if they have any use for any of these accounts and delete the ones he/she needs on his/her own discretion.&lt;BR /&gt;&lt;BR /&gt;to see if a user has any files/directories associated by this username, run the command:&lt;BR /&gt;&lt;BR /&gt;find / -user $USERNAME &lt;BR /&gt;&lt;BR /&gt;(do it when your system has very low utilization, as this will hammer your disks pretty bad) &lt;BR /&gt;&lt;BR /&gt;and see if it lists anything. If it does, decide if these files are used for anything related to the purpose of this server. For instance, if you are going to run a very specific application on your server and you get an apache web server installed with user id www, do you really want it there, as a security threat ? &lt;BR /&gt;&lt;BR /&gt;This issue is more political than technical. So, every data center should make their own decisions about which of the default users they get handed upon a fresh system installation they want to delete and which ones to keep.&lt;BR /&gt;&lt;BR /&gt;Hope this helps.</description>
      <pubDate>Sat, 18 Jun 2005 13:37:13 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/user-list-in-sam/m-p/3559819#M226276</guid>
      <dc:creator>Mel Burslan</dc:creator>
      <dc:date>2005-06-18T13:37:13Z</dc:date>
    </item>
    <item>
      <title>Re: user list in SAM</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/user-list-in-sam/m-p/3559820#M226277</link>
      <description>Hi all,&lt;BR /&gt;thanks for the reply. Sorry late, I attend SNA1 course at HP education Centre Malaysia. Did ask the same question too. I am doing the doc of all my hp-ux servers that's why need the info.....will refer to the link...&lt;BR /&gt;&lt;BR /&gt;Thanks</description>
      <pubDate>Fri, 24 Jun 2005 22:00:09 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/user-list-in-sam/m-p/3559820#M226277</guid>
      <dc:creator>Fauziah Mahdan</dc:creator>
      <dc:date>2005-06-24T22:00:09Z</dc:date>
    </item>
  </channel>
</rss>

