<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: /etc/default/Security with Untrusted in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/etc-default-security-with-untrusted/m-p/3979102#M294124</link>
    <description>My memory was indeed faulty.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=1000150" target="_blank"&gt;http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=1000150&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;/etc/default/security should be fully functional on non-trusted systems.&lt;BR /&gt;&lt;BR /&gt;JRF confirms this. I confirm this in the previous thread.&lt;BR /&gt;&lt;BR /&gt;Apologies.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
    <pubDate>Wed, 11 Apr 2007 05:38:48 GMT</pubDate>
    <dc:creator>Steven E. Protter</dc:creator>
    <dc:date>2007-04-11T05:38:48Z</dc:date>
    <item>
      <title>/etc/default/Security with Untrusted</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/etc-default-security-with-untrusted/m-p/3979099#M294121</link>
      <description>kindly confirm one thing to me that Password restriction policies work only with trusted host. I installed the patch for that.&lt;BR /&gt;&lt;BR /&gt;I convert my system to trusted and password policies was enforced But i revert back to untrust then not a singly policy was working. (Although documentation says that min_passwd_length can work with untrusted system.).&lt;BR /&gt;I just want to get confirmation how can i use password policies with untrusted system.&lt;BR /&gt;&lt;BR /&gt;What changes occured in passwd file or effects after migration from trusted to untrust or trust to untrust.&lt;BR /&gt;&lt;BR /&gt;Any idea about these things.</description>
      <pubDate>Wed, 11 Apr 2007 05:27:23 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/etc-default-security-with-untrusted/m-p/3979099#M294121</guid>
      <dc:creator>zafar.rizvi</dc:creator>
      <dc:date>2007-04-11T05:27:23Z</dc:date>
    </item>
    <item>
      <title>Re: /etc/default/Security with Untrusted</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/etc-default-security-with-untrusted/m-p/3979100#M294122</link>
      <description>Shalom,&lt;BR /&gt;&lt;BR /&gt;Going from trusted to un-trusted migrates the password information back into the /etc/passwd file with the standard encryption mechanism.&lt;BR /&gt;&lt;BR /&gt;I'd like to see your documentation, because I recall (perhaps incorrectly) that /etc/default/security does not work unless the system is trusted.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Wed, 11 Apr 2007 05:36:14 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/etc-default-security-with-untrusted/m-p/3979100#M294122</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2007-04-11T05:36:14Z</dc:date>
    </item>
    <item>
      <title>Re: /etc/default/Security with Untrusted</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/etc-default-security-with-untrusted/m-p/3979101#M294123</link>
      <description>A review of the man pages for "security" will reveal that some of the features require that the system be trusted - but not all, so some of the features *should* work.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Pete</description>
      <pubDate>Wed, 11 Apr 2007 05:38:20 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/etc-default-security-with-untrusted/m-p/3979101#M294123</guid>
      <dc:creator>Pete Randall</dc:creator>
      <dc:date>2007-04-11T05:38:20Z</dc:date>
    </item>
    <item>
      <title>Re: /etc/default/Security with Untrusted</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/etc-default-security-with-untrusted/m-p/3979102#M294124</link>
      <description>My memory was indeed faulty.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=1000150" target="_blank"&gt;http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=1000150&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;/etc/default/security should be fully functional on non-trusted systems.&lt;BR /&gt;&lt;BR /&gt;JRF confirms this. I confirm this in the previous thread.&lt;BR /&gt;&lt;BR /&gt;Apologies.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Wed, 11 Apr 2007 05:38:48 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/etc-default-security-with-untrusted/m-p/3979102#M294124</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2007-04-11T05:38:48Z</dc:date>
    </item>
    <item>
      <title>Re: /etc/default/Security with Untrusted</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/etc-default-security-with-untrusted/m-p/3979103#M294125</link>
      <description>Dear All,&lt;BR /&gt;&lt;BR /&gt;I check it with trusted system all required configuration was working fine. When i convert back to  non trusted system and then try to change passwd of any user , it accept the 2 length password. I did't change any file parameters in /etc/default/security.&lt;BR /&gt;&lt;BR /&gt;I am using HP-UX version &lt;BR /&gt;HP Release B.11.11 and patch PHCO_27037 is installed as recomended for extra password parameters,&lt;BR /&gt;and this configuration parameters is in use in file.&lt;BR /&gt;MIN_PASSWORD_LENGTH=7&lt;BR /&gt;PASSWORD_HISTORY_DEPTH=3&lt;BR /&gt;PASSWORD_MIN_DIGIT_CHARS=1&lt;BR /&gt;PASSWORD_MIN_SPECIAL_CHARS=1&lt;BR /&gt;&lt;BR /&gt;kindly check and confirm what else i need to configure it with non trusted system.</description>
      <pubDate>Wed, 11 Apr 2007 06:01:50 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/etc-default-security-with-untrusted/m-p/3979103#M294125</guid>
      <dc:creator>zafar.rizvi</dc:creator>
      <dc:date>2007-04-11T06:01:50Z</dc:date>
    </item>
    <item>
      <title>Re: /etc/default/Security with Untrusted</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/etc-default-security-with-untrusted/m-p/3979104#M294126</link>
      <description>Let me clarify: /etc/default/security does work with an untrusted system. BUT almost *NONE* of the options in the man page are functional in a non-trusted system. The man page doesn't clearly identify the features but you can infer what will not work by the lack of a /tcb directory. The only place to for password controls on an untrusted system is the 4 characters trailing the encrypted password in the /etc/passwd file. That means you can control the time for password expiration, and the minimum time before a password can be changed. That's all. No more. Nada.&lt;BR /&gt; &lt;BR /&gt;So for your list:&lt;BR /&gt; &lt;BR /&gt;&amp;gt; MIN_PASSWORD_LENGTH=7&lt;BR /&gt; &lt;BR /&gt;This is a gray area. The man pages:&lt;BR /&gt; &lt;BR /&gt;security&lt;BR /&gt;passwd(1)&lt;BR /&gt;passwd(4)&lt;BR /&gt; &lt;BR /&gt;are not conclusive that this item in the security file has any effect. The maximum password size is ALWAYS 8 in a non-trusted system although extra characters beyond 8 are accepted without any error message.&lt;BR /&gt;&lt;BR /&gt;&amp;gt; PASSWORD_HISTORY_DEPTH=3&lt;BR /&gt;&amp;gt; PASSWORD_MIN_DIGIT_CHARS=1&lt;BR /&gt;&amp;gt; PASSWORD_MIN_SPECIAL_CHARS=1 &lt;BR /&gt; &lt;BR /&gt;These are silently ignored in a non-Trusted system. If you upgrade to 11.23 and implement the Security Extensions, then you can regain many of the security file features. See: &lt;A href="http://docs.hp.com/en/5991-8711" target="_blank"&gt;http://docs.hp.com/en/5991-8711&lt;/A&gt; Note also that Trusted mode is going away after 11.31. See: &lt;A href="http://h21007.www2.hp.com/dspp/tech/tech_TechDocumentDetailPage_IDX/1,1701,8231,00.html?jumpid=reg_R1002_USEN" target="_blank"&gt;http://h21007.www2.hp.com/dspp/tech/tech_TechDocumentDetailPage_IDX/1,1701,8231,00.html?jumpid=reg_R1002_USEN&lt;/A&gt;&lt;BR /&gt; &lt;BR /&gt;BTW: PHCO_27037 has a warning and has been superseded twice -- the current patch is PHCO_35250. However, it does not mention password length at all.&lt;BR /&gt; &lt;BR /&gt;The attached script will summarize your security settings.</description>
      <pubDate>Wed, 11 Apr 2007 07:26:23 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/etc-default-security-with-untrusted/m-p/3979104#M294126</guid>
      <dc:creator>Bill Hassell</dc:creator>
      <dc:date>2007-04-11T07:26:23Z</dc:date>
    </item>
  </channel>
</rss>

