<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic security Containment RBAC in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/security-containment-rbac/m-p/4584542#M374221</link>
    <description>&lt;BR /&gt;Hello, &lt;BR /&gt;&lt;BR /&gt;I am not able to guess what this error means in the rbacdbchk. It only appears with an rbacdbchk, but not with one of the options alone (-r, -a, -u, -c, -R, -x), and it is not showed when -vvv is used (I can see all the checking around the DBs is done but the error is not there)&lt;BR /&gt;&lt;BR /&gt;# rbacdbchk&lt;BR /&gt;[Invalid Authorization in role_auth DB. Auth with operation='hpux.*' and object='*' does not exist in the auths DB]&lt;BR /&gt;Administrator:(hpux.*, *)&lt;BR /&gt;&lt;BR /&gt;In other environment this is working, being the user_role, roles, role_auth, cmd_priv and auths files the same.&lt;BR /&gt;&lt;BR /&gt;Any help or clue will be welcomed, thank you in advance&lt;BR /&gt;&lt;BR /&gt;#rbacdbchk -vvv&lt;BR /&gt;&lt;BR /&gt;### Checking database /etc/rbac/roles&lt;BR /&gt;Checking field values in line: 'Administrator: Sample role shipped with system; assigned all auths by default' &lt;BR /&gt;...(and some more)&lt;BR /&gt;&lt;BR /&gt;### Checking database /etc/rbac/auths&lt;BR /&gt;Checking field values in line: '(hpux.*,*):' &lt;BR /&gt;Checking field values in line: '(hpux.admin.boot.config,*):' &lt;BR /&gt;Checking field values in line: '(hpux.admin.boot.make,*):' &lt;BR /&gt;Checking field values in line: '(hpux.admin.boot.remove,*):' &lt;BR /&gt;Checking field values in line: '(hpux.admin.kernel.config,*):' &lt;BR /&gt;Checking field values in line: '(hpux.admin.kernel.crash.save,*):'&lt;BR /&gt;...</description>
    <pubDate>Tue, 16 Feb 2010 10:10:00 GMT</pubDate>
    <dc:creator>Antonio Egea</dc:creator>
    <dc:date>2010-02-16T10:10:00Z</dc:date>
    <item>
      <title>security Containment RBAC</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-containment-rbac/m-p/4584542#M374221</link>
      <description>&lt;BR /&gt;Hello, &lt;BR /&gt;&lt;BR /&gt;I am not able to guess what this error means in the rbacdbchk. It only appears with an rbacdbchk, but not with one of the options alone (-r, -a, -u, -c, -R, -x), and it is not showed when -vvv is used (I can see all the checking around the DBs is done but the error is not there)&lt;BR /&gt;&lt;BR /&gt;# rbacdbchk&lt;BR /&gt;[Invalid Authorization in role_auth DB. Auth with operation='hpux.*' and object='*' does not exist in the auths DB]&lt;BR /&gt;Administrator:(hpux.*, *)&lt;BR /&gt;&lt;BR /&gt;In other environment this is working, being the user_role, roles, role_auth, cmd_priv and auths files the same.&lt;BR /&gt;&lt;BR /&gt;Any help or clue will be welcomed, thank you in advance&lt;BR /&gt;&lt;BR /&gt;#rbacdbchk -vvv&lt;BR /&gt;&lt;BR /&gt;### Checking database /etc/rbac/roles&lt;BR /&gt;Checking field values in line: 'Administrator: Sample role shipped with system; assigned all auths by default' &lt;BR /&gt;...(and some more)&lt;BR /&gt;&lt;BR /&gt;### Checking database /etc/rbac/auths&lt;BR /&gt;Checking field values in line: '(hpux.*,*):' &lt;BR /&gt;Checking field values in line: '(hpux.admin.boot.config,*):' &lt;BR /&gt;Checking field values in line: '(hpux.admin.boot.make,*):' &lt;BR /&gt;Checking field values in line: '(hpux.admin.boot.remove,*):' &lt;BR /&gt;Checking field values in line: '(hpux.admin.kernel.config,*):' &lt;BR /&gt;Checking field values in line: '(hpux.admin.kernel.crash.save,*):'&lt;BR /&gt;...</description>
      <pubDate>Tue, 16 Feb 2010 10:10:00 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-containment-rbac/m-p/4584542#M374221</guid>
      <dc:creator>Antonio Egea</dc:creator>
      <dc:date>2010-02-16T10:10:00Z</dc:date>
    </item>
    <item>
      <title>Re: security Containment RBAC</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-containment-rbac/m-p/4584543#M374222</link>
      <description>Hi,&lt;BR /&gt;I'm not very familiar with rbac, but normally as I understand the messages says that in the file /etc/rbac/role_auth you have a value &lt;BR /&gt;Administrator:  (hpux.*, *) that is not matching the auths file. But the auths file are always like (hpux.*,*):&lt;BR /&gt;So maybe there is a typo error on the /etc/rbac/role_auth that you can not see while the rbacdbck can check it.&lt;BR /&gt;Copy this line from another good server could help you?&lt;BR /&gt;HTH</description>
      <pubDate>Tue, 16 Feb 2010 10:41:12 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-containment-rbac/m-p/4584543#M374222</guid>
      <dc:creator>smatador</dc:creator>
      <dc:date>2010-02-16T10:41:12Z</dc:date>
    </item>
    <item>
      <title>Re: security Containment RBAC</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-containment-rbac/m-p/4584544#M374223</link>
      <description>We thought about that, but the copied all the files from the working server to the failing one and it the same error is appearing...&lt;BR /&gt;&lt;BR /&gt;They are having some issues with Ignite and maybe that's the problem but I am not sure</description>
      <pubDate>Tue, 16 Feb 2010 13:17:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-containment-rbac/m-p/4584544#M374223</guid>
      <dc:creator>Antonio Egea</dc:creator>
      <dc:date>2010-02-16T13:17:41Z</dc:date>
    </item>
    <item>
      <title>Re: security Containment RBAC</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-containment-rbac/m-p/4584545#M374224</link>
      <description>Hi Antonio&lt;BR /&gt;&lt;BR /&gt;&amp;gt;We thought about that, but the copied all the files from the working server to the failing one and it the same error is appearing...&lt;BR /&gt;&lt;BR /&gt;That's mean, the db is ok. So I suppose the problem is on the rbacdbchk command.&lt;BR /&gt;You write about ignite issue. What's the problem? Do you have restore this box?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Do you have check about library of rbackdbchk&lt;BR /&gt;ldd /usr/sbin/rbacdbchk&lt;BR /&gt;and compare  ll &lt;LIBFILE&gt; with another good one.&lt;BR /&gt;You could also check about patches like&lt;BR /&gt;PHCO_40362&lt;BR /&gt;&lt;BR /&gt;HTH&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/LIBFILE&gt;</description>
      <pubDate>Tue, 16 Feb 2010 14:05:14 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-containment-rbac/m-p/4584545#M374224</guid>
      <dc:creator>smatador</dc:creator>
      <dc:date>2010-02-16T14:05:14Z</dc:date>
    </item>
    <item>
      <title>Re: security Containment RBAC</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/security-containment-rbac/m-p/4584546#M374225</link>
      <description>We are investigating the corruption problem. From a tusc looks like it is opening the /etc/rbac/auths several times with different contents, I will try cksum</description>
      <pubDate>Wed, 17 Feb 2010 11:24:19 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/security-containment-rbac/m-p/4584546#M374225</guid>
      <dc:creator>Antonio Egea</dc:creator>
      <dc:date>2010-02-17T11:24:19Z</dc:date>
    </item>
  </channel>
</rss>

