<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SAM Password Administration in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/sam-password-administration/m-p/3592710#M231609</link>
    <description>I want to automatically notify users to change thier passwords periodically and force them to use a "strong" password (i.e.-Gnomes05!). Is this possible with SAM or is there another software package I can install to do this?</description>
    <pubDate>Fri, 29 Jul 2005 07:50:03 GMT</pubDate>
    <dc:creator>Mike Waibel</dc:creator>
    <dc:date>2005-07-29T07:50:03Z</dc:date>
    <item>
      <title>SAM Password Administration</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/sam-password-administration/m-p/3592710#M231609</link>
      <description>I want to automatically notify users to change thier passwords periodically and force them to use a "strong" password (i.e.-Gnomes05!). Is this possible with SAM or is there another software package I can install to do this?</description>
      <pubDate>Fri, 29 Jul 2005 07:50:03 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/sam-password-administration/m-p/3592710#M231609</guid>
      <dc:creator>Mike Waibel</dc:creator>
      <dc:date>2005-07-29T07:50:03Z</dc:date>
    </item>
    <item>
      <title>Re: SAM Password Administration</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/sam-password-administration/m-p/3592711#M231610</link>
      <description>Mike,&lt;BR /&gt;&lt;BR /&gt;Take a look at "man security".  Be aware, however, that many of the more advanced features of /etc/default/security require your system to be trusted.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Pete</description>
      <pubDate>Fri, 29 Jul 2005 07:51:36 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/sam-password-administration/m-p/3592711#M231610</guid>
      <dc:creator>Pete Randall</dc:creator>
      <dc:date>2005-07-29T07:51:36Z</dc:date>
    </item>
    <item>
      <title>Re: SAM Password Administration</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/sam-password-administration/m-p/3592712#M231611</link>
      <description>As Pete stated,the features you are looking for are availble in trusted mode.You can easily convert to trusted mode via SAM.</description>
      <pubDate>Fri, 29 Jul 2005 07:54:11 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/sam-password-administration/m-p/3592712#M231611</guid>
      <dc:creator>DCE</dc:creator>
      <dc:date>2005-07-29T07:54:11Z</dc:date>
    </item>
    <item>
      <title>Re: SAM Password Administration</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/sam-password-administration/m-p/3592713#M231612</link>
      <description>Thanks!!</description>
      <pubDate>Fri, 29 Jul 2005 08:00:14 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/sam-password-administration/m-p/3592713#M231612</guid>
      <dc:creator>Mike Waibel</dc:creator>
      <dc:date>2005-07-29T08:00:14Z</dc:date>
    </item>
    <item>
      <title>Re: SAM Password Administration</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/sam-password-administration/m-p/3592714#M231613</link>
      <description>What are the pitfalls of going to a trusted system? What problems might I encounter?</description>
      <pubDate>Fri, 29 Jul 2005 08:02:37 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/sam-password-administration/m-p/3592714#M231613</guid>
      <dc:creator>Mike Waibel</dc:creator>
      <dc:date>2005-07-29T08:02:37Z</dc:date>
    </item>
    <item>
      <title>Re: SAM Password Administration</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/sam-password-administration/m-p/3592715#M231614</link>
      <description>One common pitfall is the deactivation of the root account!  The default failed login attempts is three, and for some reason or other, a sysadmin will lock the root account.&lt;BR /&gt;&lt;BR /&gt;Two ways to get reactivate the account&lt;BR /&gt;If there is a root window open run the command modprpw -k root to reactivate it&lt;BR /&gt;or&lt;BR /&gt;log in from the console as root &lt;BR /&gt;&lt;BR /&gt;Another "issue" may be the status of little used accounts.  An account may be disabled from lack of use (a good thing from a security point of view, but bad from the user point of view)&lt;BR /&gt;&lt;BR /&gt;I have converted several systems to trusted, and have not encountered any other issues.  There is an added bonus to going to trusted - it eliminates an audit point, if your system is is ever audited for security.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 29 Jul 2005 08:13:47 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/sam-password-administration/m-p/3592715#M231614</guid>
      <dc:creator>DCE</dc:creator>
      <dc:date>2005-07-29T08:13:47Z</dc:date>
    </item>
    <item>
      <title>Re: SAM Password Administration</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/sam-password-administration/m-p/3592716#M231615</link>
      <description>If I do have problems, can I just switch back? Does switching to and from a trusted system require any reboot or disruption?</description>
      <pubDate>Fri, 29 Jul 2005 08:17:23 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/sam-password-administration/m-p/3592716#M231615</guid>
      <dc:creator>Mike Waibel</dc:creator>
      <dc:date>2005-07-29T08:17:23Z</dc:date>
    </item>
    <item>
      <title>Re: SAM Password Administration</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/sam-password-administration/m-p/3592717#M231616</link>
      <description>Switching back is simple - I believe the command tsconvert -r</description>
      <pubDate>Fri, 29 Jul 2005 08:32:29 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/sam-password-administration/m-p/3592717#M231616</guid>
      <dc:creator>DCE</dc:creator>
      <dc:date>2005-07-29T08:32:29Z</dc:date>
    </item>
    <item>
      <title>Re: SAM Password Administration</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/sam-password-administration/m-p/3592718#M231617</link>
      <description>I forgot to mention - no reboot required and no interuptions</description>
      <pubDate>Fri, 29 Jul 2005 08:36:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/sam-password-administration/m-p/3592718#M231617</guid>
      <dc:creator>DCE</dc:creator>
      <dc:date>2005-07-29T08:36:21Z</dc:date>
    </item>
    <item>
      <title>Re: SAM Password Administration</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/sam-password-administration/m-p/3592719#M231618</link>
      <description>/etc/default/security does not exist on my system. What's up??</description>
      <pubDate>Fri, 29 Jul 2005 08:44:36 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/sam-password-administration/m-p/3592719#M231618</guid>
      <dc:creator>Mike Waibel</dc:creator>
      <dc:date>2005-07-29T08:44:36Z</dc:date>
    </item>
    <item>
      <title>Re: SAM Password Administration</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/sam-password-administration/m-p/3592720#M231619</link>
      <description>Not sure why, but the following thread should prove helpful&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=833100" target="_blank"&gt;http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=833100&lt;/A&gt;</description>
      <pubDate>Fri, 29 Jul 2005 09:08:55 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/sam-password-administration/m-p/3592720#M231619</guid>
      <dc:creator>DCE</dc:creator>
      <dc:date>2005-07-29T09:08:55Z</dc:date>
    </item>
    <item>
      <title>Re: SAM Password Administration</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/sam-password-administration/m-p/3592721#M231620</link>
      <description>Thanks for the tip, but still don't know for sure when and how the /etc/default/security file is created.</description>
      <pubDate>Fri, 29 Jul 2005 09:53:23 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/sam-password-administration/m-p/3592721#M231620</guid>
      <dc:creator>Mike Waibel</dc:creator>
      <dc:date>2005-07-29T09:53:23Z</dc:date>
    </item>
    <item>
      <title>Re: SAM Password Administration</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/sam-password-administration/m-p/3592722#M231621</link>
      <description>Mike,&lt;BR /&gt;&lt;BR /&gt;The file does not exist by default and must be created manually.  The man page will show you format of the entries.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Pete</description>
      <pubDate>Fri, 29 Jul 2005 09:56:43 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/sam-password-administration/m-p/3592722#M231621</guid>
      <dc:creator>Pete Randall</dc:creator>
      <dc:date>2005-07-29T09:56:43Z</dc:date>
    </item>
    <item>
      <title>Re: SAM Password Administration</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/sam-password-administration/m-p/3592723#M231622</link>
      <description>Did you convert your system to a trusted system yet ? If yes and you do not have the file, just go ahead and create it with these lines in it:&lt;BR /&gt;&lt;BR /&gt;ABORT_LOGIN_ON_MISSING_HOMEDIR=1&lt;BR /&gt;MIN_PASSWORD_LENGTH=8&lt;BR /&gt;NOLOGIN=1&lt;BR /&gt;PASSWORD_HISTORY_DEPTH=8&lt;BR /&gt;PASSWORD_MIN_UPPER_CASE_CHARS=1&lt;BR /&gt;PASSWORD_MIN_LOWER_CASE_CHARS=1&lt;BR /&gt;PASSWORD_MIN_DIGIT_CHARS=1&lt;BR /&gt;PASSWORD_MIN_SPECIAL_CHARS=1&lt;BR /&gt;&lt;BR /&gt;with permissions of 444 It is not a magical file.</description>
      <pubDate>Fri, 29 Jul 2005 09:57:45 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/sam-password-administration/m-p/3592723#M231622</guid>
      <dc:creator>Mel Burslan</dc:creator>
      <dc:date>2005-07-29T09:57:45Z</dc:date>
    </item>
    <item>
      <title>Re: SAM Password Administration</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/sam-password-administration/m-p/3592724#M231623</link>
      <description>Does SAM write to this file once I have changed to a trusted system and created the file?</description>
      <pubDate>Fri, 29 Jul 2005 09:58:48 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/sam-password-administration/m-p/3592724#M231623</guid>
      <dc:creator>Mike Waibel</dc:creator>
      <dc:date>2005-07-29T09:58:48Z</dc:date>
    </item>
    <item>
      <title>Re: SAM Password Administration</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/sam-password-administration/m-p/3592725#M231624</link>
      <description>I never modified this file by sam but I am sure one or more of these parameters in the file are modifiable by sam, in which case it may write on it. But again this is an assumption. I create this file upon completion of a turted system conversion while I am building a new system. An usually it stays the same for the life of the system unless we get a new request from security team to deploy/chnge a setting, in which case, modification of the file and pushing it out to the other servers from a central location is how I do it.</description>
      <pubDate>Fri, 29 Jul 2005 10:02:14 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/sam-password-administration/m-p/3592725#M231624</guid>
      <dc:creator>Mel Burslan</dc:creator>
      <dc:date>2005-07-29T10:02:14Z</dc:date>
    </item>
    <item>
      <title>Re: SAM Password Administration</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/sam-password-administration/m-p/3592726#M231625</link>
      <description>Looks like you might need a patch - PHCO_33215&lt;BR /&gt;might not hurt to have PHCO_27694 and PHCO_27781</description>
      <pubDate>Fri, 29 Jul 2005 10:06:16 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/sam-password-administration/m-p/3592726#M231625</guid>
      <dc:creator>DCE</dc:creator>
      <dc:date>2005-07-29T10:06:16Z</dc:date>
    </item>
    <item>
      <title>Re: SAM Password Administration</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/sam-password-administration/m-p/3592727#M231626</link>
      <description>It would not be a bad idea to do a maketaperecovery before doing all this :).&lt;BR /&gt;Also do a /usr/lbin/gerprpw account  on your accounts and make sure no one esspecially root is locked out, at least if they are not supposed to be.  If its all 0s on the lockout=000000  you are good.  1s mean its locked.&lt;BR /&gt;/usr/lbin/modprpw -k will unlock the account&lt;BR /&gt;/usr/lbin/modprpw -v will reset the time to expire for an account.  Make sure your time to expire accounts is set to what you want.  getprpw will show you allot of information about your accounts that you may want to know as an admin.  Trusted is the way to go not only because it offers more features, but that it is more secure too.&lt;BR /&gt;&lt;BR /&gt;Good Luck.</description>
      <pubDate>Fri, 29 Jul 2005 10:10:43 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/sam-password-administration/m-p/3592727#M231626</guid>
      <dc:creator>generic_1</dc:creator>
      <dc:date>2005-07-29T10:10:43Z</dc:date>
    </item>
    <item>
      <title>Re: SAM Password Administration</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/sam-password-administration/m-p/3592728#M231627</link>
      <description>I am a bit confused. Does SAM allow me to assign different password security options on a per user basis on a trusted system?&lt;BR /&gt;&lt;BR /&gt;And what about the /etc/default/security file.&lt;BR /&gt;Does this apply to all users or does SAM override this?? Does this file exist for each user??</description>
      <pubDate>Mon, 01 Aug 2005 12:56:26 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/sam-password-administration/m-p/3592728#M231627</guid>
      <dc:creator>Mike Waibel</dc:creator>
      <dc:date>2005-08-01T12:56:26Z</dc:date>
    </item>
    <item>
      <title>Re: SAM Password Administration</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/sam-password-administration/m-p/3592729#M231628</link>
      <description>I am a bit confused. Does SAM allow me to assign different password security options on a per user basis on a trusted system?&lt;BR /&gt;&lt;BR /&gt;Yes&lt;BR /&gt;&lt;BR /&gt;And what about the /etc/default/security file.&lt;BR /&gt;Does this apply to all users or does SAM override this?? Does this file exist for each user??&lt;BR /&gt;&lt;BR /&gt;System file that contains default security settings is for all users - settings that are customized are stored in the TCB and override defaults in /etc/default/security</description>
      <pubDate>Mon, 01 Aug 2005 13:58:03 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/sam-password-administration/m-p/3592729#M231628</guid>
      <dc:creator>DCE</dc:creator>
      <dc:date>2005-08-01T13:58:03Z</dc:date>
    </item>
  </channel>
</rss>

