<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic System Default Accounts in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/system-default-accounts/m-p/4067008#M306871</link>
    <description>&lt;!--!*#--&gt;This question concrens Run Control Scripts... IE: /sbin/rc* and /sbin/init.d scripts. &lt;BR /&gt;&lt;BR /&gt;Is it acceptable/secure for the user ADM to be listed as the file's GROUP owner?&lt;BR /&gt;&lt;BR /&gt;Is the user ADM considered a DEFAULT SYSTEM ACCOUNT similar to ROOT,SYS,BIN and OTHER?&lt;BR /&gt;&lt;BR /&gt;I don't believe I've ever seen a DEFAULT OS INSTALL where any of the "rc" scripts were owned (GROUP OWNED) by ADM.&lt;BR /&gt;&lt;BR /&gt;Anyone?&lt;BR /&gt;</description>
    <pubDate>Fri, 07 Sep 2007 07:46:00 GMT</pubDate>
    <dc:creator>john guardian</dc:creator>
    <dc:date>2007-09-07T07:46:00Z</dc:date>
    <item>
      <title>System Default Accounts</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/system-default-accounts/m-p/4067008#M306871</link>
      <description>&lt;!--!*#--&gt;This question concrens Run Control Scripts... IE: /sbin/rc* and /sbin/init.d scripts. &lt;BR /&gt;&lt;BR /&gt;Is it acceptable/secure for the user ADM to be listed as the file's GROUP owner?&lt;BR /&gt;&lt;BR /&gt;Is the user ADM considered a DEFAULT SYSTEM ACCOUNT similar to ROOT,SYS,BIN and OTHER?&lt;BR /&gt;&lt;BR /&gt;I don't believe I've ever seen a DEFAULT OS INSTALL where any of the "rc" scripts were owned (GROUP OWNED) by ADM.&lt;BR /&gt;&lt;BR /&gt;Anyone?&lt;BR /&gt;</description>
      <pubDate>Fri, 07 Sep 2007 07:46:00 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/system-default-accounts/m-p/4067008#M306871</guid>
      <dc:creator>john guardian</dc:creator>
      <dc:date>2007-09-07T07:46:00Z</dc:date>
    </item>
    <item>
      <title>Re: System Default Accounts</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/system-default-accounts/m-p/4067009#M306872</link>
      <description>Shalom,&lt;BR /&gt;&lt;BR /&gt;No, it is unacceptable to make the adm user user zero.&lt;BR /&gt;&lt;BR /&gt;It is fine to have a startup script that does an su - username -c command. That is a very normal practice.&lt;BR /&gt;&lt;BR /&gt;You should probably talk to the vendor and ask them why they did this.&lt;BR /&gt;&lt;BR /&gt;I'm guessing its just a sloppy Q&amp;amp;A situation. I know of no third party products other than Cyborg that require this level of privileges to start. You can bet I gave Cognos a lot of trouble over this.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Fri, 07 Sep 2007 07:51:33 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/system-default-accounts/m-p/4067009#M306872</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2007-09-07T07:51:33Z</dc:date>
    </item>
    <item>
      <title>Re: System Default Accounts</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/system-default-accounts/m-p/4067010#M306873</link>
      <description>&lt;!--!*#--&gt;Nope.  Me either.&lt;BR /&gt;&lt;BR /&gt;# ll /sbin/rc?.d |grep adm&lt;BR /&gt;lrwxr-xr-x   1 root       42              21 Mar 15  2004 K140webadmin -&amp;gt; /sbin/&lt;BR /&gt;init.d/webadmin&lt;BR /&gt;lrwxr-xr-x   1 root       root            22 Mar 15  2004 S206clean_adm -&amp;gt; /sbin&lt;BR /&gt;/init.d/clean_adm&lt;BR /&gt;lrwxr-xr-x   1 root       42              21 Mar 15  2004 S860webadmin -&amp;gt; /sbin/&lt;BR /&gt;init.d/webadmin&lt;BR /&gt;lrwxr-xr-x   1 bin        bin             29 Mar 15  2004 S996vradmind -&amp;gt; /sbin/&lt;BR /&gt;init.d/vras-vradmind.sh&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Pete</description>
      <pubDate>Fri, 07 Sep 2007 07:52:39 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/system-default-accounts/m-p/4067010#M306873</guid>
      <dc:creator>Pete Randall</dc:creator>
      <dc:date>2007-09-07T07:52:39Z</dc:date>
    </item>
    <item>
      <title>Re: System Default Accounts</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/system-default-accounts/m-p/4067011#M306874</link>
      <description>&lt;!--!*#--&gt;Actually, ADM hasn't been made user/uid zero. One or two of the script listings look something like :&lt;BR /&gt;&lt;BR /&gt;-r-xr-x-rx  root  adm  &amp;lt;script_name&amp;gt;&lt;BR /&gt;&lt;BR /&gt;So, ADM is simply listed as the GROUP OWNER of this script.&lt;BR /&gt;&lt;BR /&gt;I've never seen this and didn't think it was acceptable.&lt;BR /&gt;&lt;BR /&gt;So, once again, I still wonder whether ADM is considered a default system account?&lt;BR /&gt;</description>
      <pubDate>Fri, 07 Sep 2007 07:57:13 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/system-default-accounts/m-p/4067011#M306874</guid>
      <dc:creator>john guardian</dc:creator>
      <dc:date>2007-09-07T07:57:13Z</dc:date>
    </item>
    <item>
      <title>Re: System Default Accounts</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/system-default-accounts/m-p/4067012#M306875</link>
      <description>Hi John:&lt;BR /&gt;&lt;BR /&gt;&amp;gt; Is it acceptable/secure for the user ADM to be listed as the file's GROUP owner?&lt;BR /&gt;&lt;BR /&gt;This should be acceptable.  After all, it's the root user under which the startup/shutdown scripts actually execute.&lt;BR /&gt;&lt;BR /&gt;&amp;gt; Is the user ADM considered a DEFAULT SYSTEM ACCOUNT similar to ROOT,SYS,BIN and OTHER?&lt;BR /&gt;&lt;BR /&gt;Yes, 'adm' is one of the standard, default groups.  You will find this group associated with '/var/adm', for example.&lt;BR /&gt;&lt;BR /&gt;Generally the '/sbin/init.d' scripts are owned by 'bin' with 'bin' as their group, too.&lt;BR /&gt;&lt;BR /&gt;Regards!&lt;BR /&gt;&lt;BR /&gt;...JRF...&lt;BR /&gt;</description>
      <pubDate>Fri, 07 Sep 2007 08:01:12 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/system-default-accounts/m-p/4067012#M306875</guid>
      <dc:creator>James R. Ferguson</dc:creator>
      <dc:date>2007-09-07T08:01:12Z</dc:date>
    </item>
    <item>
      <title>Re: System Default Accounts</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/system-default-accounts/m-p/4067013#M306876</link>
      <description>ADM is one of the default **GROUPS** in /etc/groups as part of the OS install.&lt;BR /&gt;&lt;BR /&gt;The GROUP permission you are seeing has NOTHING to do with any of the users in /etc/passwd.  ADM is a valid default user as well, though the user and the group ADM are separate things.&lt;BR /&gt;&lt;BR /&gt;I don't know that having ADM as the group on some of the rc scripts is necessarily normal, but I don't think it is a disaster waiting to happen either.  All of the scripts run as root when the system is booting anyway so the owner and group don't necessarily matter much.&lt;BR /&gt;&lt;BR /&gt;If it makes you nervous, change it to match the other scripts.</description>
      <pubDate>Fri, 07 Sep 2007 08:04:47 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/system-default-accounts/m-p/4067013#M306876</guid>
      <dc:creator>Patrick Wallek</dc:creator>
      <dc:date>2007-09-07T08:04:47Z</dc:date>
    </item>
  </channel>
</rss>

