<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: su-ing problems for root user when trusted is enabled in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/su-ing-problems-for-root-user-when-trusted-is-enabled/m-p/3738463#M255779</link>
    <description>arun(ars),&lt;BR /&gt;&lt;BR /&gt;previous reply is giving the same document of Bharat's one :). &lt;BR /&gt;&lt;BR /&gt;Anyway, credit has to go to bharat.&lt;BR /&gt;&lt;BR /&gt;--&lt;BR /&gt;Muthu&lt;BR /&gt;&lt;BR /&gt;PS: Assign 0 points</description>
    <pubDate>Fri, 24 Feb 2006 00:32:39 GMT</pubDate>
    <dc:creator>Muthukumar_5</dc:creator>
    <dc:date>2006-02-24T00:32:39Z</dc:date>
    <item>
      <title>su-ing problems for root user when trusted is enabled</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/su-ing-problems-for-root-user-when-trusted-is-enabled/m-p/3738452#M255768</link>
      <description>Guys,&lt;BR /&gt;&lt;BR /&gt; I have a problem when I turned on tcb on the machine it now prompt root user for a password, so when a root user tries to su to a normal user it prompts root user for a password, however when I turn off tcb then root user can su to any user without supplying a password.&lt;BR /&gt;&lt;BR /&gt;Any suggestions on how to resolve this problem???&lt;BR /&gt;&lt;BR /&gt;I have checked the root user id it is set to zero....&lt;BR /&gt;&lt;BR /&gt;thanks&lt;BR /&gt;Raf</description>
      <pubDate>Thu, 23 Feb 2006 19:22:31 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/su-ing-problems-for-root-user-when-trusted-is-enabled/m-p/3738452#M255768</guid>
      <dc:creator>Becke</dc:creator>
      <dc:date>2006-02-23T19:22:31Z</dc:date>
    </item>
    <item>
      <title>Re: su-ing problems for root user when trusted is enabled</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/su-ing-problems-for-root-user-when-trusted-is-enabled/m-p/3738453#M255769</link>
      <description>Hi Raf#,&lt;BR /&gt;&lt;BR /&gt;When you conver to tructed then the passwords are expired. There is a command pwconv that checks the passwd files and the &lt;BR /&gt;/tcb/files/auth directory and if they dont match moves only the entry's out of passwd to tcb directory. &lt;BR /&gt;&lt;BR /&gt;run the modprpw command to unexpire the passwords.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;IA&lt;BR /&gt;</description>
      <pubDate>Thu, 23 Feb 2006 19:43:14 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/su-ing-problems-for-root-user-when-trusted-is-enabled/m-p/3738453#M255769</guid>
      <dc:creator>Indira Aramandla</dc:creator>
      <dc:date>2006-02-23T19:43:14Z</dc:date>
    </item>
    <item>
      <title>Re: su-ing problems for root user when trusted is enabled</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/su-ing-problems-for-root-user-when-trusted-is-enabled/m-p/3738454#M255770</link>
      <description>&lt;BR /&gt; Thanks for your response mate, I'm running hp version 10.20 which doesn't have this command ie modprpw...????&lt;BR /&gt;&lt;BR /&gt; Raf</description>
      <pubDate>Thu, 23 Feb 2006 20:02:46 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/su-ing-problems-for-root-user-when-trusted-is-enabled/m-p/3738454#M255770</guid>
      <dc:creator>Becke</dc:creator>
      <dc:date>2006-02-23T20:02:46Z</dc:date>
    </item>
    <item>
      <title>Re: su-ing problems for root user when trusted is enabled</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/su-ing-problems-for-root-user-when-trusted-is-enabled/m-p/3738455#M255771</link>
      <description>&lt;BR /&gt; Hi Indira,&lt;BR /&gt;&lt;BR /&gt; Thank you so much for your help, modprpw resides in /usr/lbin and when I ran it with 'V' option it worked like a charm, I have just tested and i can su from root to any user without supplying a password...&lt;BR /&gt;&lt;BR /&gt;Let me perform another check and i will let you know, it looks good, if you don't hear from me then assume its all working..&lt;BR /&gt;&lt;BR /&gt;Thanks for your help&lt;BR /&gt;&lt;BR /&gt;Cheers,&lt;BR /&gt;Raf</description>
      <pubDate>Thu, 23 Feb 2006 20:13:06 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/su-ing-problems-for-root-user-when-trusted-is-enabled/m-p/3738455#M255771</guid>
      <dc:creator>Becke</dc:creator>
      <dc:date>2006-02-23T20:13:06Z</dc:date>
    </item>
    <item>
      <title>Re: su-ing problems for root user when trusted is enabled</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/su-ing-problems-for-root-user-when-trusted-is-enabled/m-p/3738456#M255772</link>
      <description>&lt;BR /&gt; Hi Indira,&lt;BR /&gt;&lt;BR /&gt; What is the correct procedure, I have all the user passwords which I want to use in the /tcb/files/auth directory but when I turnoff tcb I lost all the passwords and /etc/passwd file show * in the password field which means I think all the passwords are locked...&lt;BR /&gt;&lt;BR /&gt;I have run the modprpw V command and it recreates the /tcb/files/auth directory but it doesn't restore the same passwords or i'm not following the right procedure.&lt;BR /&gt;&lt;BR /&gt;Please let me know on how I can use user's same passwords and also it doesn't prompt root user for a password when a root user is su-ing to another user...&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;Raf</description>
      <pubDate>Thu, 23 Feb 2006 20:36:38 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/su-ing-problems-for-root-user-when-trusted-is-enabled/m-p/3738456#M255772</guid>
      <dc:creator>Becke</dc:creator>
      <dc:date>2006-02-23T20:36:38Z</dc:date>
    </item>
    <item>
      <title>Re: su-ing problems for root user when trusted is enabled</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/su-ing-problems-for-root-user-when-trusted-is-enabled/m-p/3738457#M255773</link>
      <description>Hi Raf, &lt;BR /&gt;&lt;BR /&gt;This guide should be useful to manage trusted systems. &lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://docs.hp.com/en/B2355-90950/ch08s08.html" target="_blank"&gt;http://docs.hp.com/en/B2355-90950/ch08s08.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;-Arun</description>
      <pubDate>Thu, 23 Feb 2006 21:47:05 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/su-ing-problems-for-root-user-when-trusted-is-enabled/m-p/3738457#M255773</guid>
      <dc:creator>Arunvijai_4</dc:creator>
      <dc:date>2006-02-23T21:47:05Z</dc:date>
    </item>
    <item>
      <title>Re: su-ing problems for root user when trusted is enabled</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/su-ing-problems-for-root-user-when-trusted-is-enabled/m-p/3738458#M255774</link>
      <description>&lt;BR /&gt; Thanks Arun,&lt;BR /&gt;&lt;BR /&gt; All the user's passwords are in /tcb/files/auth directory and if I turn off the trusted on the machine it should by default restore all the passwords into the /etc/passwd file but it doesn't do that when I turn off the 'tcb'.&lt;BR /&gt;&lt;BR /&gt;The main problem is that when tcb is enabled i can't su to a normal user without supplying a password as it prompts root user to supply normal user's password, and when I disable the trusted, root can su to any user without supplying a password. But the problem is when you disable trusted i can get root su working but all the user's password were lost...any idea???i'm also reading tcb documents on the net</description>
      <pubDate>Thu, 23 Feb 2006 21:54:49 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/su-ing-problems-for-root-user-when-trusted-is-enabled/m-p/3738458#M255774</guid>
      <dc:creator>Becke</dc:creator>
      <dc:date>2006-02-23T21:54:49Z</dc:date>
    </item>
    <item>
      <title>Re: su-ing problems for root user when trusted is enabled</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/su-ing-problems-for-root-user-when-trusted-is-enabled/m-p/3738459#M255775</link>
      <description>Hi Raf, &lt;BR /&gt;&lt;BR /&gt;You may need to check these threads, &lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=963444" target="_blank"&gt;http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=963444&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=119194" target="_blank"&gt;http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=119194&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;-Arun</description>
      <pubDate>Thu, 23 Feb 2006 23:01:32 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/su-ing-problems-for-root-user-when-trusted-is-enabled/m-p/3738459#M255775</guid>
      <dc:creator>Arunvijai_4</dc:creator>
      <dc:date>2006-02-23T23:01:32Z</dc:date>
    </item>
    <item>
      <title>Re: su-ing problems for root user when trusted is enabled</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/su-ing-problems-for-root-user-when-trusted-is-enabled/m-p/3738460#M255776</link>
      <description>Are you using DCE environment. So that is asking password for root user. Try as,&lt;BR /&gt;&lt;BR /&gt;# su -d &lt;DCE name=""&gt;&lt;BR /&gt;&lt;BR /&gt;It will not ask password now. See su man page with DCE string search.&lt;BR /&gt;&lt;BR /&gt;--&lt;BR /&gt;Muthu&lt;/DCE&gt;</description>
      <pubDate>Fri, 24 Feb 2006 00:24:37 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/su-ing-problems-for-root-user-when-trusted-is-enabled/m-p/3738460#M255776</guid>
      <dc:creator>Muthukumar_5</dc:creator>
      <dc:date>2006-02-24T00:24:37Z</dc:date>
    </item>
    <item>
      <title>Re: su-ing problems for root user when trusted is enabled</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/su-ing-problems-for-root-user-when-trusted-is-enabled/m-p/3738461#M255777</link>
      <description>For converting to trusted or reverting back use Bharat's document which is in,&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=655039" target="_blank"&gt;http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=655039&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;--&lt;BR /&gt;Muthu</description>
      <pubDate>Fri, 24 Feb 2006 00:27:18 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/su-ing-problems-for-root-user-when-trusted-is-enabled/m-p/3738461#M255777</guid>
      <dc:creator>Muthukumar_5</dc:creator>
      <dc:date>2006-02-24T00:27:18Z</dc:date>
    </item>
    <item>
      <title>Re: su-ing problems for root user when trusted is enabled</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/su-ing-problems-for-root-user-when-trusted-is-enabled/m-p/3738462#M255778</link>
      <description>Hi Raf, &lt;BR /&gt;&lt;BR /&gt;Here is the doc attached here. &lt;BR /&gt;&lt;BR /&gt;_Arun</description>
      <pubDate>Fri, 24 Feb 2006 00:29:00 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/su-ing-problems-for-root-user-when-trusted-is-enabled/m-p/3738462#M255778</guid>
      <dc:creator>Arunvijai_4</dc:creator>
      <dc:date>2006-02-24T00:29:00Z</dc:date>
    </item>
    <item>
      <title>Re: su-ing problems for root user when trusted is enabled</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/su-ing-problems-for-root-user-when-trusted-is-enabled/m-p/3738463#M255779</link>
      <description>arun(ars),&lt;BR /&gt;&lt;BR /&gt;previous reply is giving the same document of Bharat's one :). &lt;BR /&gt;&lt;BR /&gt;Anyway, credit has to go to bharat.&lt;BR /&gt;&lt;BR /&gt;--&lt;BR /&gt;Muthu&lt;BR /&gt;&lt;BR /&gt;PS: Assign 0 points</description>
      <pubDate>Fri, 24 Feb 2006 00:32:39 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/su-ing-problems-for-root-user-when-trusted-is-enabled/m-p/3738463#M255779</guid>
      <dc:creator>Muthukumar_5</dc:creator>
      <dc:date>2006-02-24T00:32:39Z</dc:date>
    </item>
    <item>
      <title>Re: su-ing problems for root user when trusted is enabled</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/su-ing-problems-for-root-user-when-trusted-is-enabled/m-p/3738464#M255780</link>
      <description>&lt;BR /&gt; Thanks Arun, Muthu and Bhrat for your detailed info and prompt responses guys.&lt;BR /&gt;&lt;BR /&gt;I apologise for the late response as I wasn't at work, I was actually at the vendor site performing the Disaster recovery exercise for HP-UX.&lt;BR /&gt;&lt;BR /&gt; I don't have access to the DR machine anymore as it is at vendor's site, however I have temporarily disabled trusted on the DR machine and everything worked fine.&lt;BR /&gt;&lt;BR /&gt; Next time when I will be performing DR I will use your documents and information to resolve this problem.&lt;BR /&gt;&lt;BR /&gt; Its great to see that we have an excellent team here guys, I have now assigned points...&lt;BR /&gt;&lt;BR /&gt;Many Regards,&lt;BR /&gt;Raf</description>
      <pubDate>Sun, 26 Feb 2006 17:52:20 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/su-ing-problems-for-root-user-when-trusted-is-enabled/m-p/3738464#M255780</guid>
      <dc:creator>Becke</dc:creator>
      <dc:date>2006-02-26T17:52:20Z</dc:date>
    </item>
    <item>
      <title>Re: su-ing problems for root user when trusted is enabled</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/su-ing-problems-for-root-user-when-trusted-is-enabled/m-p/3738465#M255781</link>
      <description>We probably assumed that when you said you turned off tcb, you meant to say that you ran the tsconvert command. You cannot turn off the Trusted System environment by removing the /tcb directory (or any other method except using tsconvert). The tsconvert is a 'backend' command which means it is not documented and designed only to be used by SAM. But it can be called directly with -u and -c which un-trusts and trusts respectively. NOTE: tsconvert always expires all passwords when converting to Trusted, which is why (without using SAM) you must run modprpw (another backend command) to reset the expiration time for all users.&lt;BR /&gt; &lt;BR /&gt;Now after conversion to Trusted, there are a couple of possible messages for failed logins. One is that the password has expired (see the above comment about modprpw) and the other says the user is not logging in correctly, probably due to the wrong password. If the user tries too many times, the user ID will be disabled (which is not the same as expired). Even though the user is sure of the password, if the password is longer than 8 characters, it will not work in the Trusted system. The reason is that an untrusted "throws away" all characters after 8 no matter how many the user types. So only the first 8 are significant. But a Trusted system honors all password characters. So in a Trusted system, users should only type up to 8 characters for their OLD password. Once they login, they can change their password to a longer one and it will be honored. &lt;BR /&gt; &lt;BR /&gt;And as you might expect, if users change to a longer password, conv erting back to untrusted means their password will never work and a new one must be created by the root user.</description>
      <pubDate>Sun, 26 Feb 2006 21:12:52 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/su-ing-problems-for-root-user-when-trusted-is-enabled/m-p/3738465#M255781</guid>
      <dc:creator>Bill Hassell</dc:creator>
      <dc:date>2006-02-26T21:12:52Z</dc:date>
    </item>
    <item>
      <title>Re: su-ing problems for root user when trusted is enabled</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/su-ing-problems-for-root-user-when-trusted-is-enabled/m-p/3738466#M255782</link>
      <description>&lt;BR /&gt; Thanks for your elaboration Bill, I have certainly got the better understanding now. And no I haven't deleted /tcb directory, I have used sam to unconvert the system which disables the trusted.&lt;BR /&gt;&lt;BR /&gt; The problem occurs while cloning the HP prod machine onto the DR machine. I had to restore all users password manually into /tcb/files/auth directory on the test machine, but before doing the above I had enabled trusted using sam.&lt;BR /&gt;&lt;BR /&gt;Users were able to login using their existing passwords after I restored the /tcb/files/auth directory from prod to test machine, but as a admin user I couldn't su from root's account to other users account without supplying the password, as su-ing from root to normal user prompted for a password, where it shouldn't prompt for a password, and I just wanted to sort this out, however I was also performing the AIX DR and AIX is my expertise, I was unable to resolve this problem as I was stuck with other things, so finally I decided to untrust the system which has allowed me to su to other people's account, but I had to reset user's password who were performing the application test on the DR machine. &lt;BR /&gt;&lt;BR /&gt;Your and everyone else's information will certainly help me next time when I will perform the DR exercise.&lt;BR /&gt;&lt;BR /&gt; Cheers,&lt;BR /&gt; Raf</description>
      <pubDate>Sun, 26 Feb 2006 22:28:01 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/su-ing-problems-for-root-user-when-trusted-is-enabled/m-p/3738466#M255782</guid>
      <dc:creator>Becke</dc:creator>
      <dc:date>2006-02-26T22:28:01Z</dc:date>
    </item>
    <item>
      <title>Re: su-ing problems for root user when trusted is enabled</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/su-ing-problems-for-root-user-when-trusted-is-enabled/m-p/3738467#M255783</link>
      <description>Note that /tcb does not stand by itself as a directory structure -- it requires a matching /etc/passwd file, and for completeness, /etc/default/security and /etc/group should also be ported. The connections between /etc/passwd and /tcb include the user name and the user ID number. Rules for both untrusted and Trusted system are contained in the security file (if it exists).</description>
      <pubDate>Sun, 26 Feb 2006 23:13:29 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/su-ing-problems-for-root-user-when-trusted-is-enabled/m-p/3738467#M255783</guid>
      <dc:creator>Bill Hassell</dc:creator>
      <dc:date>2006-02-26T23:13:29Z</dc:date>
    </item>
    <item>
      <title>Re: su-ing problems for root user when trusted is enabled</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/su-ing-problems-for-root-user-when-trusted-is-enabled/m-p/3738468#M255784</link>
      <description>&lt;BR /&gt; Hi Bill,&lt;BR /&gt; &lt;BR /&gt; Your comments does make sense, so next time when I will restore the /tcb/files/auth directory I will make sure that I restore /etc/passwd file as well, mind you /etc/passwd file has an * entry in the password field in prod machine, so you say that restoring /etc/passwd from prod to test would help even if it doesn't contain any passwords entries for users, and also I don't have security file in /etc/default directory in prod.&lt;BR /&gt;&lt;BR /&gt; Next DR test would be a good learning exercise.&lt;BR /&gt;&lt;BR /&gt; Thanks&lt;BR /&gt; Raf</description>
      <pubDate>Sun, 26 Feb 2006 23:31:20 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/su-ing-problems-for-root-user-when-trusted-is-enabled/m-p/3738468#M255784</guid>
      <dc:creator>Becke</dc:creator>
      <dc:date>2006-02-26T23:31:20Z</dc:date>
    </item>
    <item>
      <title>Re: su-ing problems for root user when trusted is enabled</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/su-ing-problems-for-root-user-when-trusted-is-enabled/m-p/3738469#M255785</link>
      <description>That is correct. The password fields are * on a Trusted system but the /tcb passwords are not useful unless the matching /etc/passwd file is also restored. The security file, while optional, should be created aqs you develop your security procedures. Use the command:&lt;BR /&gt; &lt;BR /&gt;man security</description>
      <pubDate>Mon, 27 Feb 2006 09:17:49 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/su-ing-problems-for-root-user-when-trusted-is-enabled/m-p/3738469#M255785</guid>
      <dc:creator>Bill Hassell</dc:creator>
      <dc:date>2006-02-27T09:17:49Z</dc:date>
    </item>
  </channel>
</rss>

