<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Shadow Password Usage/Install - Issues? in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/shadow-password-usage-install-issues/m-p/4858146#M395897</link>
    <description>here's an update related to Database vendors: informix and oracle related to HP's Shadow Product on HPUX 11.11&lt;BR /&gt;&lt;BR /&gt;After installing Shadow, the Informix database access users can not login.  (The users come in via tcp clients and informix database authenticates via normal unix system login using /etc/password file.)&lt;BR /&gt;&lt;BR /&gt;The Informix versions used are: 7.31 and 9.30.&lt;BR /&gt;&lt;BR /&gt;The fix is simple: take the encrypted password from /etc/shadow and copy it back into the database user's account in /etc/passwd.&lt;BR /&gt;&lt;BR /&gt;The other vendor: Oracle, apparently has patches to use Shadow.&lt;BR /&gt;</description>
    <pubDate>Fri, 03 Sep 2004 10:38:20 GMT</pubDate>
    <dc:creator>D Block 2</dc:creator>
    <dc:date>2004-09-03T10:38:20Z</dc:date>
    <item>
      <title>Shadow Password Usage/Install - Issues?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/shadow-password-usage-install-issues/m-p/4858142#M395893</link>
      <description>Have you installed HP's package: Shadow Password ?&lt;BR /&gt;&lt;BR /&gt;Say, I'm really worried about the OS HPUX with RAC, in particular, 10g.. should I get the vendor Oracle's approval before I install on 11i Production using Rac 10g ?  I would hate to break production or wait for a patch from an outside vendor..&lt;BR /&gt;&lt;BR /&gt;Thx in adv..&lt;BR /&gt;&lt;BR /&gt;BTW,&lt;BR /&gt;&lt;BR /&gt;I've installed the package on two test systems, and no problems, but its not production environment running Rac 10g.&lt;BR /&gt;&lt;BR /&gt;see:&lt;BR /&gt;&lt;A href="http://www.software.hp.com/portal/swdepot/displayProductInfo.do?productNumber=ShadowPassword" target="_blank"&gt;http://www.software.hp.com/portal/swdepot/displayProductInfo.do?productNumber=ShadowPassword&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;also a thread under HP's Security Form:&lt;BR /&gt;&lt;A href="http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=590554" target="_blank"&gt;http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=590554&lt;/A&gt;</description>
      <pubDate>Mon, 23 Aug 2004 21:06:28 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/shadow-password-usage-install-issues/m-p/4858142#M395893</guid>
      <dc:creator>D Block 2</dc:creator>
      <dc:date>2004-08-23T21:06:28Z</dc:date>
    </item>
    <item>
      <title>Re: Shadow Password Usage/Install - Issues?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/shadow-password-usage-install-issues/m-p/4858143#M395894</link>
      <description>Hi Tom,&lt;BR /&gt;&lt;BR /&gt;We don't take that intermediate step - we convert to full trusted. Every system - period.&lt;BR /&gt;Have *not* had a single problem to date.&lt;BR /&gt;That covers literally hundreds of systems.&lt;BR /&gt;So my advice to you would be - don't mess around with the relatively new shadow PW - do the right thing &amp;amp; go trusted.&lt;BR /&gt;It's *much* more secure.&lt;BR /&gt;&lt;BR /&gt;My $0.02,&lt;BR /&gt;Jeff</description>
      <pubDate>Mon, 23 Aug 2004 21:12:24 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/shadow-password-usage-install-issues/m-p/4858143#M395894</guid>
      <dc:creator>Jeff Schussele</dc:creator>
      <dc:date>2004-08-23T21:12:24Z</dc:date>
    </item>
    <item>
      <title>Re: Shadow Password Usage/Install - Issues?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/shadow-password-usage-install-issues/m-p/4858144#M395895</link>
      <description>Hi Tom,&lt;BR /&gt;&lt;BR /&gt;I personally haven't played with shadow password support, but one thing I've heard that is different from Trusted Systems is that Shadow Password support will be integrated into NIS in a coming release, where as I've heard of no plans to integrate NIS with Trusted Systems.&lt;BR /&gt;&lt;BR /&gt;Even if NIS is not used in your shop, my point is to get you thinking not only in terms of security, but of integration with your name server and authentication mechanisms.  If you choose a security model, either Shadow or Trusted, be sure to understand the implications of integrating support for those security models with whatever authentication back-end name service you plan to use in your environment.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;&lt;BR /&gt;Dave</description>
      <pubDate>Mon, 23 Aug 2004 21:47:32 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/shadow-password-usage-install-issues/m-p/4858144#M395895</guid>
      <dc:creator>Dave Olker</dc:creator>
      <dc:date>2004-08-23T21:47:32Z</dc:date>
    </item>
    <item>
      <title>Re: Shadow Password Usage/Install - Issues?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/shadow-password-usage-install-issues/m-p/4858145#M395896</link>
      <description>We only have a problem with one vendor.  Robelle's Qedit product has issues with Shadow passwords.  The vendor is aware of the problem and is currently working on a fix.</description>
      <pubDate>Tue, 24 Aug 2004 08:10:03 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/shadow-password-usage-install-issues/m-p/4858145#M395896</guid>
      <dc:creator>Gary L. Paveza, Jr.</dc:creator>
      <dc:date>2004-08-24T08:10:03Z</dc:date>
    </item>
    <item>
      <title>Re: Shadow Password Usage/Install - Issues?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/shadow-password-usage-install-issues/m-p/4858146#M395897</link>
      <description>here's an update related to Database vendors: informix and oracle related to HP's Shadow Product on HPUX 11.11&lt;BR /&gt;&lt;BR /&gt;After installing Shadow, the Informix database access users can not login.  (The users come in via tcp clients and informix database authenticates via normal unix system login using /etc/password file.)&lt;BR /&gt;&lt;BR /&gt;The Informix versions used are: 7.31 and 9.30.&lt;BR /&gt;&lt;BR /&gt;The fix is simple: take the encrypted password from /etc/shadow and copy it back into the database user's account in /etc/passwd.&lt;BR /&gt;&lt;BR /&gt;The other vendor: Oracle, apparently has patches to use Shadow.&lt;BR /&gt;</description>
      <pubDate>Fri, 03 Sep 2004 10:38:20 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/shadow-password-usage-install-issues/m-p/4858146#M395897</guid>
      <dc:creator>D Block 2</dc:creator>
      <dc:date>2004-09-03T10:38:20Z</dc:date>
    </item>
    <item>
      <title>Re: Shadow Password Usage/Install - Issues?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/shadow-password-usage-install-issues/m-p/4858147#M395898</link>
      <description>Hi (again) Tom,&lt;BR /&gt;&lt;BR /&gt;Well that "fix" kind of negates the purpose of Shadow PW because the "standard" /etc/passwd is world readable whereas the shadow is not.&lt;BR /&gt;The purpose being that a "normal" user can't grab a copy of the passwd file, take it off system &amp;amp; run crack or John the Ripper against it.&lt;BR /&gt;Personally I've never seen Informix have a problem with the TCB (Trusted Computing Base) structure that a trusted system uses.&lt;BR /&gt;You might talk to Informix about using the authentication method on the HP version that they use on Sun because all Sun system utilize the shadow PW principle.&lt;BR /&gt;&lt;BR /&gt;My $0.02,&lt;BR /&gt;Jeff</description>
      <pubDate>Fri, 03 Sep 2004 11:25:29 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/shadow-password-usage-install-issues/m-p/4858147#M395898</guid>
      <dc:creator>Jeff Schussele</dc:creator>
      <dc:date>2004-09-03T11:25:29Z</dc:date>
    </item>
    <item>
      <title>Re: Shadow Password Usage/Install - Issues?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/shadow-password-usage-install-issues/m-p/4858148#M395899</link>
      <description>Does a "trusted" HPUX system have a file called: /etc/shadow ?</description>
      <pubDate>Tue, 07 Sep 2004 07:25:43 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/shadow-password-usage-install-issues/m-p/4858148#M395899</guid>
      <dc:creator>D Block 2</dc:creator>
      <dc:date>2004-09-07T07:25:43Z</dc:date>
    </item>
    <item>
      <title>Re: Shadow Password Usage/Install - Issues?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/shadow-password-usage-install-issues/m-p/4858149#M395900</link>
      <description>I decided to learn on my own:&lt;BR /&gt;&lt;BR /&gt;- turned on Trusted via SAM and here's the difference when looking at file from /.&lt;BR /&gt;&lt;BR /&gt;diff# diff /tmp/nontrusted /tmp/trusted&lt;BR /&gt;1264a1265&lt;BR /&gt;&amp;gt; /tmp/trusted&lt;BR /&gt;58015a58017&lt;BR /&gt;&amp;gt; /var/spool/sockets/pwgr/client4708&lt;BR /&gt;58017d58018&lt;BR /&gt;&amp;lt; /var/spool/sockets/pwgr/client4412&lt;BR /&gt;58018a58020&lt;BR /&gt;&amp;gt; /var/spool/sockets/pwgr/client4567&lt;BR /&gt;58053a58056,58057&lt;BR /&gt;&amp;gt; /var/spool/cron/.ataids&lt;BR /&gt;&amp;gt; /var/spool/cron/.cronaids&lt;BR /&gt;58377d58380&lt;BR /&gt;&amp;lt; /var/sam/ann.dion&lt;BR /&gt;58378a58382,58383&lt;BR /&gt;&amp;gt; /var/sam/sam_tm_work&lt;BR /&gt;&amp;gt; /var/sam/ann.dion&lt;BR /&gt;59496a59502,59506&lt;BR /&gt;&amp;gt; /.secure&lt;BR /&gt;&amp;gt; /.secure/etc&lt;BR /&gt;&amp;gt; /.secure/etc/audnames&lt;BR /&gt;&amp;gt; /.secure/etc/audfile1&lt;BR /&gt;&amp;gt; /.secure/etc/audfile2&lt;BR /&gt;59512a59523,59594&lt;BR /&gt;&amp;gt; /tcb&lt;BR /&gt;&amp;gt; /tcb/files&lt;BR /&gt;&amp;gt; /tcb/files/auth&lt;BR /&gt;&amp;gt; /tcb/files/auth/system&lt;BR /&gt;&amp;gt; /tcb/files/auth/system/default&lt;BR /&gt;&amp;gt; /tcb/files/auth/system/maxaid&lt;BR /&gt;&amp;gt; /tcb/files/auth/a&lt;BR /&gt;&amp;gt; /tcb/files/auth/a/adm&lt;BR /&gt;&amp;gt; /tcb/files/auth/b&lt;BR /&gt;&amp;gt; /tcb/files/auth/b/bin&lt;BR /&gt;&amp;gt; /tcb/files/auth/c&lt;BR /&gt;&amp;gt; /tcb/files/auth/d&lt;BR /&gt;&amp;gt; /tcb/files/auth/d/daemon&lt;BR /&gt;&amp;gt; /tcb/files/auth/e&lt;BR /&gt;&amp;gt; /tcb/files/auth/f&lt;BR /&gt;&amp;gt; /tcb/files/auth/g&lt;BR /&gt;&amp;gt; /tcb/files/auth/h&lt;BR /&gt;&amp;gt; /tcb/files/auth/h/hpdb&lt;BR /&gt;&amp;gt; /tcb/files/auth/i&lt;BR /&gt;&amp;gt; /tcb/files/auth/j&lt;BR /&gt;&amp;gt; /tcb/files/auth/k&lt;BR /&gt;&amp;gt; /tcb/files/auth/l&lt;BR /&gt;&amp;gt; /tcb/files/auth/l/lp&lt;BR /&gt;&amp;gt; /tcb/files/auth/m&lt;BR /&gt;&amp;gt; /tcb/files/auth/n&lt;BR /&gt;&amp;gt; /tcb/files/auth/n/nuucp&lt;BR /&gt;&amp;gt; /tcb/files/auth/o&lt;BR /&gt;&amp;gt; /tcb/files/auth/p&lt;BR /&gt;&amp;gt; /tcb/files/auth/q&lt;BR /&gt;&amp;gt; /tcb/files/auth/r&lt;BR /&gt;&amp;gt; /tcb/files/auth/r/root&lt;BR /&gt;&amp;gt; /tcb/files/auth/s&lt;BR /&gt;&amp;gt; /tcb/files/auth/s/sys&lt;BR /&gt;&amp;gt; /tcb/files/auth/s/smbnull&lt;BR /&gt;&amp;gt; /tcb/files/auth/t&lt;BR /&gt;&amp;gt; /tcb/files/auth/u&lt;BR /&gt;&amp;gt; /tcb/files/auth/u/uucp&lt;BR /&gt;&amp;gt; /tcb/files/auth/v&lt;BR /&gt;&amp;gt; /tcb/files/auth/w&lt;BR /&gt;&amp;gt; /tcb/files/auth/w/www&lt;BR /&gt;&amp;gt; /tcb/files/auth/w/webadmin&lt;BR /&gt;&amp;gt; /tcb/files/auth/x&lt;BR /&gt;&amp;gt; /tcb/files/auth/y&lt;BR /&gt;&amp;gt; /tcb/files/auth/z&lt;BR /&gt;&amp;gt; /tcb/files/auth/A&lt;BR /&gt;&amp;gt; /tcb/files/auth/B&lt;BR /&gt;&amp;gt; /tcb/files/auth/C&lt;BR /&gt;&amp;gt; /tcb/files/auth/D&lt;BR /&gt;&amp;gt; /tcb/files/auth/E&lt;BR /&gt;&amp;gt; /tcb/files/auth/F&lt;BR /&gt;&amp;gt; /tcb/files/auth/G&lt;BR /&gt;&amp;gt; /tcb/files/auth/H&lt;BR /&gt;&amp;gt; /tcb/files/auth/I&lt;BR /&gt;&amp;gt; /tcb/files/auth/J&lt;BR /&gt;&amp;gt; /tcb/files/auth/K&lt;BR /&gt;&amp;gt; /tcb/files/auth/L&lt;BR /&gt;&amp;gt; /tcb/files/auth/M&lt;BR /&gt;&amp;gt; /tcb/files/auth/N&lt;BR /&gt;&amp;gt; /tcb/files/auth/O&lt;BR /&gt;&amp;gt; /tcb/files/auth/P&lt;BR /&gt;&amp;gt; /tcb/files/auth/Q&lt;BR /&gt;&amp;gt; /tcb/files/auth/R&lt;BR /&gt;&amp;gt; /tcb/files/auth/S&lt;BR /&gt;&amp;gt; /tcb/files/auth/T&lt;BR /&gt;&amp;gt; /tcb/files/auth/U&lt;BR /&gt;&amp;gt; /tcb/files/auth/V&lt;BR /&gt;&amp;gt; /tcb/files/auth/W&lt;BR /&gt;&amp;gt; /tcb/files/auth/X&lt;BR /&gt;&amp;gt; /tcb/files/auth/Y&lt;BR /&gt;&amp;gt; /tcb/files/auth/Z&lt;BR /&gt;&amp;gt; /tcb/files/ttys&lt;BR /&gt;&amp;gt; /tcb/files/devassign&lt;BR /&gt;#&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;I'll have to say, linux rules in this situation.  that TCB does not have: /etc/shadow file!&lt;BR /&gt;&lt;BR /&gt;closed.</description>
      <pubDate>Tue, 07 Sep 2004 20:01:05 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/shadow-password-usage-install-issues/m-p/4858149#M395900</guid>
      <dc:creator>D Block 2</dc:creator>
      <dc:date>2004-09-07T20:01:05Z</dc:date>
    </item>
    <item>
      <title>Re: Shadow Password Usage/Install - Issues?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/shadow-password-usage-install-issues/m-p/4858150#M395901</link>
      <description>fubar</description>
      <pubDate>Tue, 07 Sep 2004 20:01:55 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/shadow-password-usage-install-issues/m-p/4858150#M395901</guid>
      <dc:creator>D Block 2</dc:creator>
      <dc:date>2004-09-07T20:01:55Z</dc:date>
    </item>
  </channel>
</rss>

