<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Rename root in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/rename-root/m-p/3688271#M246641</link>
    <description>Great Replies. Just what I needed.&lt;BR /&gt;&lt;BR /&gt;Thanks a lot,&lt;BR /&gt;&lt;BR /&gt;Arthur</description>
    <pubDate>Fri, 09 Dec 2005 06:56:38 GMT</pubDate>
    <dc:creator>Arthur Luimes_2</dc:creator>
    <dc:date>2005-12-09T06:56:38Z</dc:date>
    <item>
      <title>Rename root</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/rename-root/m-p/3688266#M246636</link>
      <description>Dear Security Guru's,&lt;BR /&gt;&lt;BR /&gt;My manager has aked me if it is possible to rename the root user to something else, so that a hacker would have to guess both the name and it's password. &lt;BR /&gt;&lt;BR /&gt;How would I do this? &lt;BR /&gt;Is this actually a bad idea? Are there components of HP-UX 11.00 that depend on the name "root"?&lt;BR /&gt;&lt;BR /&gt;Thanks a lot,&lt;BR /&gt;&lt;BR /&gt;Arthur Luimes&lt;BR /&gt;</description>
      <pubDate>Fri, 09 Dec 2005 06:27:00 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/rename-root/m-p/3688266#M246636</guid>
      <dc:creator>Arthur Luimes_2</dc:creator>
      <dc:date>2005-12-09T06:27:00Z</dc:date>
    </item>
    <item>
      <title>Re: Rename root</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/rename-root/m-p/3688267#M246637</link>
      <description>You can't rename root user as far as i know. Its not possible in any unix OS. Try to implement some other techniques like SSL, SSH, PAM kerberos, IDS to secure your server. &lt;BR /&gt;&lt;BR /&gt;-Arun</description>
      <pubDate>Fri, 09 Dec 2005 06:31:05 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/rename-root/m-p/3688267#M246637</guid>
      <dc:creator>Arunvijai_4</dc:creator>
      <dc:date>2005-12-09T06:31:05Z</dc:date>
    </item>
    <item>
      <title>Re: Rename root</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/rename-root/m-p/3688268#M246638</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Block direct root access to the system. Give permission to a group of users(System admin) to do an su - from their login access root. You can even implement sudoers .&lt;BR /&gt;&lt;BR /&gt;Install SSL, SSH, PAM kerberos, IDS as suggested by arun.&lt;BR /&gt;&lt;BR /&gt;There is no way you can rename the ultimate super user 'root'&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Sunil</description>
      <pubDate>Fri, 09 Dec 2005 06:39:07 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/rename-root/m-p/3688268#M246638</guid>
      <dc:creator>Sยภเl Kย๓คг</dc:creator>
      <dc:date>2005-12-09T06:39:07Z</dc:date>
    </item>
    <item>
      <title>Re: Rename root</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/rename-root/m-p/3688269#M246639</link>
      <description>&lt;BR /&gt;Dear Arthur,&lt;BR /&gt;&lt;BR /&gt;You cannot rename root user in any HPUX, lot may dependencys are present in the system.&lt;BR /&gt;&lt;BR /&gt;With Regards,&lt;BR /&gt;&lt;BR /&gt;Siva.</description>
      <pubDate>Fri, 09 Dec 2005 06:54:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/rename-root/m-p/3688269#M246639</guid>
      <dc:creator>Sivakumar TS</dc:creator>
      <dc:date>2005-12-09T06:54:21Z</dc:date>
    </item>
    <item>
      <title>Re: Rename root</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/rename-root/m-p/3688270#M246640</link>
      <description>Hi Arthur,&lt;BR /&gt;&lt;BR /&gt;Block direct root access to the system. Give permission to a group of users(System admin) to do an su - from their login access root. as suggested above.&lt;BR /&gt;Set the login try on 3 times so after 3 badlogins you have to enable root paaswd trough the console.&lt;BR /&gt;&lt;BR /&gt;One otherway is to make a user with uid 0.&lt;BR /&gt;and after that diable the root account with /usr/lbin/modprpw -k root.&lt;BR /&gt;This is not what i should do but it is an option.&lt;BR /&gt;&lt;BR /&gt;grtz. Mark&lt;BR /&gt;</description>
      <pubDate>Fri, 09 Dec 2005 06:56:15 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/rename-root/m-p/3688270#M246640</guid>
      <dc:creator>Mark Nieuwboer</dc:creator>
      <dc:date>2005-12-09T06:56:15Z</dc:date>
    </item>
    <item>
      <title>Re: Rename root</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/rename-root/m-p/3688271#M246641</link>
      <description>Great Replies. Just what I needed.&lt;BR /&gt;&lt;BR /&gt;Thanks a lot,&lt;BR /&gt;&lt;BR /&gt;Arthur</description>
      <pubDate>Fri, 09 Dec 2005 06:56:38 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/rename-root/m-p/3688271#M246641</guid>
      <dc:creator>Arthur Luimes_2</dc:creator>
      <dc:date>2005-12-09T06:56:38Z</dc:date>
    </item>
    <item>
      <title>Re: Rename root</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/rename-root/m-p/3688272#M246642</link>
      <description>Search ITRC for locking root account and more security related information. It is a great place to look into. &lt;BR /&gt;&lt;BR /&gt;-Arun</description>
      <pubDate>Fri, 09 Dec 2005 07:03:38 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/rename-root/m-p/3688272#M246642</guid>
      <dc:creator>Arunvijai_4</dc:creator>
      <dc:date>2005-12-09T07:03:38Z</dc:date>
    </item>
    <item>
      <title>Re: Rename root</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/rename-root/m-p/3688273#M246643</link>
      <description>You can indeed rename root as long as the system is not Trusted. Just edit the /etc/passwd file. But as others have mentioned, portions of HP-UX and other applications may depend on "root" and of course, 100% of sysadmin documentation will use the name root when referring to the superuser.&lt;BR /&gt; &lt;BR /&gt;The very first step in protecting your system is to REPLACE the text in /etc/issue with a non-descriptive message. The typical text is the output of uname -a and that is TOO MUCH information!! It contains the hardware model and the version of HP-UX, far too much information to be shown *before* you login. Instead, just put the name (or nickname if the network name implies HP-UX) of the computer and nothing else. &lt;BR /&gt; &lt;BR /&gt;Then you immdediately convert to a Trusted system. At that point, the root password cannot be guessed without locking out the root user for non-console logins. Note that the lastb command will reveal when and from which IP address a root attack was launched. And to address your manager's concerns, just create an empty /etc/securetty:&lt;BR /&gt; &lt;BR /&gt;cat /dev/null &amp;gt; /etc/securetty&lt;BR /&gt; &lt;BR /&gt;Now, *NO ONE* can login as root except at the real console. To gain root access remotely (telnet, ssh, etc) use su (which logs each access) or better yet, install and configure sudo.&lt;BR /&gt; &lt;BR /&gt;The above will address your manager's concerns. But for truly important systems, you need to download and run Bastille to harden all the security on each system. And get a copy of the HP-UX Security book by Chris Wong.</description>
      <pubDate>Fri, 09 Dec 2005 07:44:20 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/rename-root/m-p/3688273#M246643</guid>
      <dc:creator>Bill Hassell</dc:creator>
      <dc:date>2005-12-09T07:44:20Z</dc:date>
    </item>
  </channel>
</rss>

