<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Duplicate root account. in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/duplicate-root-account/m-p/4603443#M376089</link>
    <description>If you don't want sudo, there is HP's RBAC:&lt;BR /&gt;&lt;A href="https://h20392.www2.hp.com/portal/swdepot/displayProductInfo.do?productNumber=AccessControl" target="_blank"&gt;https://h20392.www2.hp.com/portal/swdepot/displayProductInfo.do?productNumber=AccessControl&lt;/A&gt;</description>
    <pubDate>Fri, 19 Mar 2010 03:34:59 GMT</pubDate>
    <dc:creator>Dennis Handly</dc:creator>
    <dc:date>2010-03-19T03:34:59Z</dc:date>
    <item>
      <title>Duplicate root account.</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/duplicate-root-account/m-p/4603431#M376077</link>
      <description>Hello Guruz,&lt;BR /&gt;&lt;BR /&gt;I want to create a duplicate root account, but ter is a restriction for duplication of uid 0&lt;BR /&gt;&lt;BR /&gt;Then  I thought of installing sudo, but that option also not accepted.&lt;BR /&gt;&lt;BR /&gt;Just would like to know if any can advise, how can I get the root access for normal account.&lt;BR /&gt;&lt;BR /&gt;Note: points will be equally shared :)</description>
      <pubDate>Thu, 18 Mar 2010 15:45:53 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/duplicate-root-account/m-p/4603431#M376077</guid>
      <dc:creator>bullz</dc:creator>
      <dc:date>2010-03-18T15:45:53Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate root account.</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/duplicate-root-account/m-p/4603432#M376078</link>
      <description>It is not advised to have more than one UID 0 account.  That is a VERY BIG security hole.&lt;BR /&gt;&lt;BR /&gt;&amp;gt;&amp;gt;Then I thought of installing sudo, but that option also not accepted.&lt;BR /&gt;&lt;BR /&gt;Sudo is the best way to grant normal users root access.  Why was it not accepted?&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 18 Mar 2010 15:49:22 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/duplicate-root-account/m-p/4603432#M376078</guid>
      <dc:creator>Patrick Wallek</dc:creator>
      <dc:date>2010-03-18T15:49:22Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate root account.</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/duplicate-root-account/m-p/4603433#M376079</link>
      <description>Hi:&lt;BR /&gt;&lt;BR /&gt;Do *not* create duplicate uid=0 accounts.&lt;BR /&gt;&lt;BR /&gt;You can, and then if you forget (or your successor forgets) and does something (stupid) like this (where user 'bullz' has a uid=0):&lt;BR /&gt;&lt;BR /&gt;/* DO NOT DO THIS !!! */&lt;BR /&gt;&lt;BR /&gt;# find /path -user bullz -exec rm -rf {} +&lt;BR /&gt;&lt;BR /&gt;...then you just *removed* all of 'root's files and directories!&lt;BR /&gt;&lt;BR /&gt;Regards!&lt;BR /&gt;&lt;BR /&gt;...JRF...&lt;BR /&gt;</description>
      <pubDate>Thu, 18 Mar 2010 15:56:27 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/duplicate-root-account/m-p/4603433#M376079</guid>
      <dc:creator>James R. Ferguson</dc:creator>
      <dc:date>2010-03-18T15:56:27Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate root account.</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/duplicate-root-account/m-p/4603434#M376080</link>
      <description>Thanks for you view on this, any other s/w or tool availbe just like SUDO? i want this kind of setup on HP-UX / Linux and Solaris servers too :)&lt;BR /&gt;&lt;BR /&gt;waiting for good news.</description>
      <pubDate>Thu, 18 Mar 2010 16:03:13 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/duplicate-root-account/m-p/4603434#M376080</guid>
      <dc:creator>bullz</dc:creator>
      <dc:date>2010-03-18T16:03:13Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate root account.</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/duplicate-root-account/m-p/4603435#M376081</link>
      <description>Check the official sudo site:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.gratisoft.us/sudo/intro.html" target="_blank"&gt;http://www.gratisoft.us/sudo/intro.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;for installation requirements and supported environments.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Pete</description>
      <pubDate>Thu, 18 Mar 2010 16:26:33 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/duplicate-root-account/m-p/4603435#M376081</guid>
      <dc:creator>Pete Randall</dc:creator>
      <dc:date>2010-03-18T16:26:33Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate root account.</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/duplicate-root-account/m-p/4603436#M376082</link>
      <description>I suppose I could have just told you that its available for AIX, RedHat Linux, IRIX and Solaris but you really ought to try this new thing called Google.  Quite handy.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Pete</description>
      <pubDate>Thu, 18 Mar 2010 16:36:53 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/duplicate-root-account/m-p/4603436#M376082</guid>
      <dc:creator>Pete Randall</dc:creator>
      <dc:date>2010-03-18T16:36:53Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate root account.</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/duplicate-root-account/m-p/4603437#M376083</link>
      <description>Shalom,&lt;BR /&gt;&lt;BR /&gt;A few views:&lt;BR /&gt;&lt;BR /&gt;Now, Dana Corp. Only security department has the root password, no duplicate root accounts are permitted. We use etrust/seos to elevate the admin users to root privileges but what they can do is limited.&lt;BR /&gt;&lt;BR /&gt;Previous job, NDS Jerusalem. They chose to go the duplicate uid=0 root. The primary reason was to know who did what. I was rootp(prottever) rootv was my boss Victor, etc etc.&lt;BR /&gt;&lt;BR /&gt;Is it really a security hole to have multiple uid=0 accounts? Classical response which you already have is yes. But it was manageable since only qualified systems administrators had the password. Though password reset involved a meeting.&lt;BR /&gt;&lt;BR /&gt;Prior to that only systems administrator, my backup(a dba eeek!) and operations had root.&lt;BR /&gt;&lt;BR /&gt;I fought operators having root and proposed sudo and was overruled.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Thu, 18 Mar 2010 16:49:12 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/duplicate-root-account/m-p/4603437#M376083</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2010-03-18T16:49:12Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate root account.</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/duplicate-root-account/m-p/4603438#M376084</link>
      <description>&amp;gt;&amp;gt;&amp;gt;Thanks for you view on this, any other s/w or tool availbe just like SUDO? i want this kind of setup on HP-UX&amp;lt;&amp;lt;&amp;lt;&lt;BR /&gt;&lt;BR /&gt;"Power broker" software which is similar software like sudo for HP,&lt;BR /&gt;&lt;BR /&gt;Difference between Power broker &amp;amp; Sudo explained in below thread&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://forums11.itrc.hp.com/service/forums/questionanswer.do?threadId=956140" target="_blank"&gt;http://forums11.itrc.hp.com/service/forums/questionanswer.do?threadId=956140&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Hope for &amp;gt;&amp;gt; AX, RedHat Linux, IRIX and Solaris&amp;lt;&amp;lt; -&amp;gt; SUDO would best approach, if not better to ask "Google" any third party SW available&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://forums11.itrc.hp.com/service/forums/questionanswer.do?admit=109447626+1268935173924+28353475&amp;amp;threadId=1084893" target="_blank"&gt;http://forums11.itrc.hp.com/service/forums/questionanswer.do?admit=109447626+1268935173924+28353475&amp;amp;threadId=1084893&lt;/A&gt;</description>
      <pubDate>Thu, 18 Mar 2010 17:02:19 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/duplicate-root-account/m-p/4603438#M376084</guid>
      <dc:creator>Johnson Punniyalingam</dc:creator>
      <dc:date>2010-03-18T17:02:19Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate root account.</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/duplicate-root-account/m-p/4603439#M376085</link>
      <description>Another option to look at is called 'rootsh'. Works in conjunction with sudo and provides lots of logging. Can find on the net, there are HPUX binaries available as well.&lt;BR /&gt;&lt;BR /&gt;Can give you the best of both worlds. The logging of sudo to see who invoke a rootsh plus the logging of rootsh to provide you with the data you want plus the capabilities of a UID=0 user without duplicating.</description>
      <pubDate>Thu, 18 Mar 2010 17:22:24 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/duplicate-root-account/m-p/4603439#M376085</guid>
      <dc:creator>Rick Garland</dc:creator>
      <dc:date>2010-03-18T17:22:24Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate root account.</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/duplicate-root-account/m-p/4603440#M376086</link>
      <description>And BTW, rootsh will work on AIX, Solaris, Linux, HPUX, etc...&lt;BR /&gt;</description>
      <pubDate>Thu, 18 Mar 2010 17:31:48 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/duplicate-root-account/m-p/4603440#M376086</guid>
      <dc:creator>Rick Garland</dc:creator>
      <dc:date>2010-03-18T17:31:48Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate root account.</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/duplicate-root-account/m-p/4603441#M376087</link>
      <description>Take a look at man sudoers, there might be something to help you.</description>
      <pubDate>Thu, 18 Mar 2010 17:42:49 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/duplicate-root-account/m-p/4603441#M376087</guid>
      <dc:creator>Tingli</dc:creator>
      <dc:date>2010-03-18T17:42:49Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate root account.</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/duplicate-root-account/m-p/4603442#M376088</link>
      <description>Bullz,&lt;BR /&gt;&lt;BR /&gt;Yes, you can create duplicate root id, with -o option with useradd command.&lt;BR /&gt;#useradd -u 0 -o ..... -m /home/root1 root1&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://docs.hp.com/en/B2355-60105/useradd.1M.html" target="_blank"&gt;http://docs.hp.com/en/B2355-60105/useradd.1M.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;However it is wise to use sudo , and that way system will be secure and access can be delegated properly. &lt;BR /&gt;&lt;BR /&gt;There is another good software available ($$) for access control is powerbroker and can be used for wide range of unix systems including linux:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.beyondtrust.com/products/pbreviews.asp" target="_blank"&gt;http://www.beyondtrust.com/products/pbreviews.asp&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;HTH,&lt;BR /&gt;Raj.</description>
      <pubDate>Thu, 18 Mar 2010 18:33:59 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/duplicate-root-account/m-p/4603442#M376088</guid>
      <dc:creator>Raj D.</dc:creator>
      <dc:date>2010-03-18T18:33:59Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate root account.</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/duplicate-root-account/m-p/4603443#M376089</link>
      <description>If you don't want sudo, there is HP's RBAC:&lt;BR /&gt;&lt;A href="https://h20392.www2.hp.com/portal/swdepot/displayProductInfo.do?productNumber=AccessControl" target="_blank"&gt;https://h20392.www2.hp.com/portal/swdepot/displayProductInfo.do?productNumber=AccessControl&lt;/A&gt;</description>
      <pubDate>Fri, 19 Mar 2010 03:34:59 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/duplicate-root-account/m-p/4603443#M376089</guid>
      <dc:creator>Dennis Handly</dc:creator>
      <dc:date>2010-03-19T03:34:59Z</dc:date>
    </item>
    <item>
      <title>Re: Duplicate root account.</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/duplicate-root-account/m-p/4603444#M376090</link>
      <description>Folks,&lt;BR /&gt;&lt;BR /&gt;I really appreciate the replies which you all sent.&lt;BR /&gt;Still points need to be assigned for ROOTSH posts. I do that shortly.&lt;BR /&gt;&lt;BR /&gt;Major challenge here is, can I get a root access ( eventually I should login as root ) for normal user without below options.&lt;BR /&gt;&lt;BR /&gt;â ¢ There shouldnâ  t be any duplicate UID of 0 (zero)&lt;BR /&gt;â ¢ SUDO also strictly restricted for some reason&lt;BR /&gt;&lt;BR /&gt;I got an advice to install ROOTSH, but my question here is, will it work without SUDO?&lt;BR /&gt;Also, will it work on Linux, and solaris too?</description>
      <pubDate>Fri, 19 Mar 2010 09:30:26 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/duplicate-root-account/m-p/4603444#M376090</guid>
      <dc:creator>bullz</dc:creator>
      <dc:date>2010-03-19T09:30:26Z</dc:date>
    </item>
  </channel>
</rss>

