<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: restricted user in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/restricted-user/m-p/4355379#M345301</link>
    <description>Hi,&lt;BR /&gt;&lt;BR /&gt;just put /./after home directory,&lt;BR /&gt;&lt;BR /&gt;(e.i. user1:4ZCqrSQpm07fk:110:20::/pgapsoft/pegains/CRBT/./:/bin/sh&lt;BR /&gt;&lt;BR /&gt;user will not be able to move from home diectory.</description>
    <pubDate>Tue, 10 Feb 2009 13:01:23 GMT</pubDate>
    <dc:creator>Md. Farhan A Azam</dc:creator>
    <dc:date>2009-02-10T13:01:23Z</dc:date>
    <item>
      <title>restricted user</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/restricted-user/m-p/4355375#M345297</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;I would like to create a user with the following access rights:&lt;BR /&gt;&lt;BR /&gt;1. the user can't live outside his home directory structure&lt;BR /&gt;2. ordinary user can access his home directory structure&lt;BR /&gt;&lt;BR /&gt;Thanks in advance.&lt;BR /&gt;-Br&lt;BR /&gt;-Ahmad</description>
      <pubDate>Tue, 10 Feb 2009 08:09:25 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/restricted-user/m-p/4355375#M345297</guid>
      <dc:creator>Muhammad Ahmad</dc:creator>
      <dc:date>2009-02-10T08:09:25Z</dc:date>
    </item>
    <item>
      <title>Re: restricted user</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/restricted-user/m-p/4355376#M345298</link>
      <description>Shalom,&lt;BR /&gt;&lt;BR /&gt;Using the restricted shell (rsh) will accomplish this goal.&lt;BR /&gt;&lt;BR /&gt;You might also consider if you use ssh of setting this user up as a chroot user.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://docs.hp.com/en/5992-3387/ch05s06.html" target="_blank"&gt;http://docs.hp.com/en/5992-3387/ch05s06.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Tue, 10 Feb 2009 08:32:09 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/restricted-user/m-p/4355376#M345298</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2009-02-10T08:32:09Z</dc:date>
    </item>
    <item>
      <title>Re: restricted user</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/restricted-user/m-p/4355377#M345299</link>
      <description>Hi Muhammad,&lt;BR /&gt;&lt;BR /&gt;You need to configure the user with chroot environment. Configuring chroot manually needs lot of work. HP has provided a script to configure chroot simply.&lt;BR /&gt;&lt;BR /&gt;You need to use the script /opt/ssh/ssh_chroot_setup.sh. This script will create a user and configure that user with chroot environment.&lt;BR /&gt;&lt;BR /&gt;Also read /opt/ssh/README.hp . It will give you exact steps.</description>
      <pubDate>Tue, 10 Feb 2009 08:42:28 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/restricted-user/m-p/4355377#M345299</guid>
      <dc:creator>Ganesan R</dc:creator>
      <dc:date>2009-02-10T08:42:28Z</dc:date>
    </item>
    <item>
      <title>Re: restricted user</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/restricted-user/m-p/4355378#M345300</link>
      <description>If this is an ftp user you may want to look at the following links:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://newfdawg.com/SHP-FTP-anon.htm" target="_blank"&gt;http://newfdawg.com/SHP-FTP-anon.htm&lt;/A&gt; &lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://forums11.itrc.hp.com/service/forums/questionanswer.do?threadId=1264911" target="_blank"&gt;http://forums11.itrc.hp.com/service/forums/questionanswer.do?threadId=1264911&lt;/A&gt; &lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;amp;cc=us&amp;amp;" target="_blank"&gt;http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&amp;amp;cc=us&amp;amp;&lt;/A&gt;&lt;BR /&gt;;taskId=115&amp;amp;prodSeriesId=3215373&amp;amp;prodTypeId=18964&amp;amp;objectID=c01516983</description>
      <pubDate>Tue, 10 Feb 2009 09:18:07 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/restricted-user/m-p/4355378#M345300</guid>
      <dc:creator>bright image</dc:creator>
      <dc:date>2009-02-10T09:18:07Z</dc:date>
    </item>
    <item>
      <title>Re: restricted user</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/restricted-user/m-p/4355379#M345301</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;just put /./after home directory,&lt;BR /&gt;&lt;BR /&gt;(e.i. user1:4ZCqrSQpm07fk:110:20::/pgapsoft/pegains/CRBT/./:/bin/sh&lt;BR /&gt;&lt;BR /&gt;user will not be able to move from home diectory.</description>
      <pubDate>Tue, 10 Feb 2009 13:01:23 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/restricted-user/m-p/4355379#M345301</guid>
      <dc:creator>Md. Farhan A Azam</dc:creator>
      <dc:date>2009-02-10T13:01:23Z</dc:date>
    </item>
    <item>
      <title>Re: restricted user</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/restricted-user/m-p/4355380#M345302</link>
      <description>&amp;gt;Farhan: just put /./after home directory,&lt;BR /&gt;&lt;BR /&gt;I tried this and this doesn't restrict cd with sh/ksh.  Where did you here about it?</description>
      <pubDate>Tue, 10 Feb 2009 21:29:29 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/restricted-user/m-p/4355380#M345302</guid>
      <dc:creator>Dennis Handly</dc:creator>
      <dc:date>2009-02-10T21:29:29Z</dc:date>
    </item>
    <item>
      <title>Re: restricted user</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/restricted-user/m-p/4355381#M345303</link>
      <description>Hi All, &lt;BR /&gt;&lt;BR /&gt;Thanks for your time.&lt;BR /&gt;&lt;BR /&gt;Farhan, i agree with Deniss.&lt;BR /&gt;&lt;BR /&gt;Secondly, ftp restricted access is given to that user using "chroot" and it's running fine.&lt;BR /&gt;&lt;BR /&gt;but in this case, only root can access that restricted user's home directory, we need to remove that restriction, so that an ordinary user can also access his home directory sturcture. with in-effect of the existing ftp restricted access for the user.&lt;BR /&gt;&lt;BR /&gt;-Br&lt;BR /&gt;Ahmad</description>
      <pubDate>Wed, 11 Feb 2009 11:46:39 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/restricted-user/m-p/4355381#M345303</guid>
      <dc:creator>Muhammad Ahmad</dc:creator>
      <dc:date>2009-02-11T11:46:39Z</dc:date>
    </item>
    <item>
      <title>Re: restricted user</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/restricted-user/m-p/4355382#M345304</link>
      <description>Hi Muhammad,&lt;BR /&gt;&lt;BR /&gt;By default write permission will not be given to anyone other then the owner of the home directories. In this case only root and owner can have write access.&lt;BR /&gt;&lt;BR /&gt;If you want to give write access to others as well, use chmod command and give write access to others.&lt;BR /&gt;&lt;BR /&gt;If you are looking something else, clarify in details.</description>
      <pubDate>Wed, 11 Feb 2009 11:57:32 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/restricted-user/m-p/4355382#M345304</guid>
      <dc:creator>Ganesan R</dc:creator>
      <dc:date>2009-02-11T11:57:32Z</dc:date>
    </item>
    <item>
      <title>Re: restricted user</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/restricted-user/m-p/4355383#M345305</link>
      <description>Hi Dennis,&lt;BR /&gt;&lt;BR /&gt;Sorry for delay in response, i was out of office from last few weeks.&lt;BR /&gt;actually..this will work for FTP user..somehow it was posted....So sorry again.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Thanks Farhan</description>
      <pubDate>Tue, 17 Feb 2009 09:03:24 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/restricted-user/m-p/4355383#M345305</guid>
      <dc:creator>Md. Farhan A Azam</dc:creator>
      <dc:date>2009-02-17T09:03:24Z</dc:date>
    </item>
    <item>
      <title>Re: restricted user</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/restricted-user/m-p/4355384#M345306</link>
      <description>&amp;gt;Farhan: this will work for FTP user&lt;BR /&gt;&lt;BR /&gt;Yes, I later saw that for ftpaccess(4).</description>
      <pubDate>Tue, 17 Feb 2009 09:14:49 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/restricted-user/m-p/4355384#M345306</guid>
      <dc:creator>Dennis Handly</dc:creator>
      <dc:date>2009-02-17T09:14:49Z</dc:date>
    </item>
    <item>
      <title>Re: restricted user</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/restricted-user/m-p/4355385#M345307</link>
      <description>Hi Farhan/Dennis,&lt;BR /&gt;&lt;BR /&gt;but in this case, we can't restrict the access of that user on shell through telnet/ssh etc. &lt;BR /&gt;&lt;BR /&gt;-Br &lt;BR /&gt;Ahmad</description>
      <pubDate>Tue, 17 Feb 2009 11:49:04 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/restricted-user/m-p/4355385#M345307</guid>
      <dc:creator>Muhammad Ahmad</dc:creator>
      <dc:date>2009-02-17T11:49:04Z</dc:date>
    </item>
    <item>
      <title>Re: restricted user</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/restricted-user/m-p/4355386#M345308</link>
      <description>Hi Muhammad,&lt;BR /&gt;&lt;BR /&gt;If you want to restrict the telnet/ssh access then change the shell to /bin/false</description>
      <pubDate>Tue, 17 Feb 2009 13:01:28 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/restricted-user/m-p/4355386#M345308</guid>
      <dc:creator>Ganesan R</dc:creator>
      <dc:date>2009-02-17T13:01:28Z</dc:date>
    </item>
    <item>
      <title>Re: restricted user</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/restricted-user/m-p/4355387#M345309</link>
      <description>&amp;gt;Ganeshan R:If you want to restrict the telnet/ssh access then change the shell to /bin/false.&lt;BR /&gt;&lt;BR /&gt;In this scenario user will not be able to login in the server through telnet, as user will not get any shell. i think this will work for ftp.</description>
      <pubDate>Wed, 18 Feb 2009 04:39:18 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/restricted-user/m-p/4355387#M345309</guid>
      <dc:creator>Md. Farhan A Azam</dc:creator>
      <dc:date>2009-02-18T04:39:18Z</dc:date>
    </item>
    <item>
      <title>Re: restricted user</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/restricted-user/m-p/4355388#M345310</link>
      <description>Hi Ahmad,&lt;BR /&gt;&lt;BR /&gt;&amp;gt;&amp;gt;In this scenario user will not be able to login in the server through telnet, as user will not get any shell. i think this will work for ftp.&amp;lt;&amp;lt; &lt;BR /&gt;&lt;BR /&gt;yes , &lt;BR /&gt;&lt;BR /&gt;But you are looking for "user id" which should be resticted under its own working directory only.?&lt;BR /&gt;&lt;BR /&gt;Can please try below suggestion under (Development Server)&lt;BR /&gt;&lt;BR /&gt;Creat account :-  UserA&lt;BR /&gt;&lt;BR /&gt;Edit the /etc/passwd file. Append a "./" to the end of the initial working &lt;BR /&gt;&lt;BR /&gt;userA:cinUTe/NGII4.:505:125::/home/userA/./:/usr/bin/sh&lt;BR /&gt;&lt;BR /&gt;otherwise, You need look for resticted shell (or) jailroot&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;Johnson&lt;BR /&gt;</description>
      <pubDate>Wed, 18 Feb 2009 10:59:45 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/restricted-user/m-p/4355388#M345310</guid>
      <dc:creator>Johnson Punniyalingam</dc:creator>
      <dc:date>2009-02-18T10:59:45Z</dc:date>
    </item>
  </channel>
</rss>

