<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: quick question about pwgr in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/quick-question-about-pwgr/m-p/4860116#M396304</link>
    <description>Hi Ken,&lt;BR /&gt;&lt;BR /&gt;Check this doc.&lt;BR /&gt;&lt;BR /&gt;Document description: How To Prevent Creation of Files in /var/spool/sockets/pwgr&lt;BR /&gt;Document id: KBRC00012276&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www1.itrc.hp.com/service/cki/docDisplay.do?docLocale=en_US&amp;amp;docId=200000068401720" target="_blank"&gt;http://www1.itrc.hp.com/service/cki/docDisplay.do?docLocale=en_US&amp;amp;docId=200000068401720&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;When the libc calls find this directory (/var/spool/sockets/pwgr) , they&lt;BR /&gt;will create the socket files in preparation for using the pwgrd server daemon, whether pwgrd is running or not.&lt;BR /&gt;&lt;BR /&gt;remove the directory pwgr from /var/spool/sockets. &lt;BR /&gt;&lt;BR /&gt;More detailed info in above link.&lt;BR /&gt;&lt;BR /&gt;Best regards,&lt;BR /&gt;Robert-Jan</description>
    <pubDate>Wed, 08 Sep 2004 16:12:07 GMT</pubDate>
    <dc:creator>Robert-Jan Goossens_1</dc:creator>
    <dc:date>2004-09-08T16:12:07Z</dc:date>
    <item>
      <title>quick question about pwgr</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/quick-question-about-pwgr/m-p/4860115#M396303</link>
      <description>Okay, I might already know the answer to this question, but want to run it by the experts first to confirm.&lt;BR /&gt;&lt;BR /&gt;To help secure our HPs, we have implemented several suggestions listed in the "How to create a Bastion Host" doc found all over the net, in it, it reads:&lt;BR /&gt;&lt;BR /&gt;pwgrd is a password and group caching daemon. Since we have a very small password and group file it is unnecessary. Also, a little detective work with lsof and tusc (Trace Unix System Calls) [12] shows us that it listens on a Unix domain socket for client requests, and we don't want to allow command channels like that to processes running as root, so we have additional incentive to disable it: &lt;BR /&gt;&lt;BR /&gt;Set the PWGR environment variable to 0 in /etc/rc.config.d/pwgr: &lt;BR /&gt;&lt;BR /&gt;PWGR=0&lt;BR /&gt;&lt;BR /&gt;We also remove stale sockets which will prevent unnecessary libc socket creation and requests to a nonexistent pwgrd listener: &lt;BR /&gt;  &lt;BR /&gt;# rm /var/spool/pwgr/* # really just need to remove status&lt;BR /&gt;# rm /var/spool/sockets/pwgr/*&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;which we did about a year ago...no problems..however, I have noticed that everytime a user logs on, a new socket is created in /var/spool/sockets/pwgr even though the daemon is not running.  why is this?  My thoughts are that possibly some other daemon creates the socket here for pwgr to use if needed, if that is the case, is there a way to turn that off as well? &lt;BR /&gt;</description>
      <pubDate>Wed, 08 Sep 2004 13:37:36 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/quick-question-about-pwgr/m-p/4860115#M396303</guid>
      <dc:creator>Ken Penland_1</dc:creator>
      <dc:date>2004-09-08T13:37:36Z</dc:date>
    </item>
    <item>
      <title>Re: quick question about pwgr</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/quick-question-about-pwgr/m-p/4860116#M396304</link>
      <description>Hi Ken,&lt;BR /&gt;&lt;BR /&gt;Check this doc.&lt;BR /&gt;&lt;BR /&gt;Document description: How To Prevent Creation of Files in /var/spool/sockets/pwgr&lt;BR /&gt;Document id: KBRC00012276&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www1.itrc.hp.com/service/cki/docDisplay.do?docLocale=en_US&amp;amp;docId=200000068401720" target="_blank"&gt;http://www1.itrc.hp.com/service/cki/docDisplay.do?docLocale=en_US&amp;amp;docId=200000068401720&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;When the libc calls find this directory (/var/spool/sockets/pwgr) , they&lt;BR /&gt;will create the socket files in preparation for using the pwgrd server daemon, whether pwgrd is running or not.&lt;BR /&gt;&lt;BR /&gt;remove the directory pwgr from /var/spool/sockets. &lt;BR /&gt;&lt;BR /&gt;More detailed info in above link.&lt;BR /&gt;&lt;BR /&gt;Best regards,&lt;BR /&gt;Robert-Jan</description>
      <pubDate>Wed, 08 Sep 2004 16:12:07 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/quick-question-about-pwgr/m-p/4860116#M396304</guid>
      <dc:creator>Robert-Jan Goossens_1</dc:creator>
      <dc:date>2004-09-08T16:12:07Z</dc:date>
    </item>
    <item>
      <title>Re: quick question about pwgr</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/quick-question-about-pwgr/m-p/4860117#M396305</link>
      <description>perfect, that is what I was suspecting, thanks for the confirmation!</description>
      <pubDate>Thu, 09 Sep 2004 07:27:12 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/quick-question-about-pwgr/m-p/4860117#M396305</guid>
      <dc:creator>Ken Penland_1</dc:creator>
      <dc:date>2004-09-09T07:27:12Z</dc:date>
    </item>
  </channel>
</rss>

