<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I force users to su to a non-root account? in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/how-do-i-force-users-to-su-to-a-non-root-account/m-p/2625050#M39640</link>
    <description>Try making their shell /usr/bin/su - userid.&lt;BR /&gt;&lt;BR /&gt;Good Luck,&lt;BR /&gt;C</description>
    <pubDate>Tue, 04 Dec 2001 16:49:51 GMT</pubDate>
    <dc:creator>Craig Rants</dc:creator>
    <dc:date>2001-12-04T16:49:51Z</dc:date>
    <item>
      <title>How do I force users to su to a non-root account?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-do-i-force-users-to-su-to-a-non-root-account/m-p/2625049#M39639</link>
      <description>&lt;BR /&gt;I have an account (non-root) that I want to force users to "su" to.  Is that possible?&lt;BR /&gt;&lt;BR /&gt;Thanks ...&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 04 Dec 2001 16:47:57 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-do-i-force-users-to-su-to-a-non-root-account/m-p/2625049#M39639</guid>
      <dc:creator>DAN HENDERSON</dc:creator>
      <dc:date>2001-12-04T16:47:57Z</dc:date>
    </item>
    <item>
      <title>Re: How do I force users to su to a non-root account?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-do-i-force-users-to-su-to-a-non-root-account/m-p/2625050#M39640</link>
      <description>Try making their shell /usr/bin/su - userid.&lt;BR /&gt;&lt;BR /&gt;Good Luck,&lt;BR /&gt;C</description>
      <pubDate>Tue, 04 Dec 2001 16:49:51 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-do-i-force-users-to-su-to-a-non-root-account/m-p/2625050#M39640</guid>
      <dc:creator>Craig Rants</dc:creator>
      <dc:date>2001-12-04T16:49:51Z</dc:date>
    </item>
    <item>
      <title>Re: How do I force users to su to a non-root account?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-do-i-force-users-to-su-to-a-non-root-account/m-p/2625051#M39641</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;This would be possible if you create(incase you don't have one) a file in /etc/securetty&lt;BR /&gt;add an entry called console in that.&lt;BR /&gt;&lt;BR /&gt;This would only allow su to all the users if they want to root access&lt;BR /&gt;&lt;BR /&gt;Goodluck&lt;BR /&gt;-USA..</description>
      <pubDate>Tue, 04 Dec 2001 16:51:06 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-do-i-force-users-to-su-to-a-non-root-account/m-p/2625051#M39641</guid>
      <dc:creator>Uday_S_Ankolekar</dc:creator>
      <dc:date>2001-12-04T16:51:06Z</dc:date>
    </item>
    <item>
      <title>Re: How do I force users to su to a non-root account?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-do-i-force-users-to-su-to-a-non-root-account/m-p/2625052#M39642</link>
      <description>Hi Dan,&lt;BR /&gt;&lt;BR /&gt;Try:&lt;BR /&gt;su - username&lt;BR /&gt;exit&lt;BR /&gt;in the last 2 lines of the .profile file of the user.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;   Justo.</description>
      <pubDate>Tue, 04 Dec 2001 16:53:04 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-do-i-force-users-to-su-to-a-non-root-account/m-p/2625052#M39642</guid>
      <dc:creator>Justo Exposito</dc:creator>
      <dc:date>2001-12-04T16:53:04Z</dc:date>
    </item>
    <item>
      <title>Re: How do I force users to su to a non-root account?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-do-i-force-users-to-su-to-a-non-root-account/m-p/2625053#M39643</link>
      <description>Justo,&lt;BR /&gt;If it was in their .profile, the user could Cntl-C out of the su, granted they are not a novice. Making it their shell gives them no option.&lt;BR /&gt;&lt;BR /&gt;Uday,&lt;BR /&gt;The console entry in /etc/securetty only allows root logins from telnet and rlogin at the console, it does not affect other users.&lt;BR /&gt;&lt;BR /&gt;C</description>
      <pubDate>Tue, 04 Dec 2001 16:56:34 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-do-i-force-users-to-su-to-a-non-root-account/m-p/2625053#M39643</guid>
      <dc:creator>Craig Rants</dc:creator>
      <dc:date>2001-12-04T16:56:34Z</dc:date>
    </item>
    <item>
      <title>Re: How do I force users to su to a non-root account?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-do-i-force-users-to-su-to-a-non-root-account/m-p/2625054#M39644</link>
      <description>Sorry, I misunderstood your question.. Thanks to Craig for correcting it.&lt;BR /&gt;</description>
      <pubDate>Tue, 04 Dec 2001 16:59:49 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-do-i-force-users-to-su-to-a-non-root-account/m-p/2625054#M39644</guid>
      <dc:creator>Uday_S_Ankolekar</dc:creator>
      <dc:date>2001-12-04T16:59:49Z</dc:date>
    </item>
    <item>
      <title>Re: How do I force users to su to a non-root account?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-do-i-force-users-to-su-to-a-non-root-account/m-p/2625055#M39645</link>
      <description>hi,&lt;BR /&gt;&lt;BR /&gt;Yes, Craig you are ok. But you can use stty command in the .profile to lock the contol-C, and you can develop with shell a menu to access the system with many options.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Justo.</description>
      <pubDate>Tue, 04 Dec 2001 17:03:54 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-do-i-force-users-to-su-to-a-non-root-account/m-p/2625055#M39645</guid>
      <dc:creator>Justo Exposito</dc:creator>
      <dc:date>2001-12-04T17:03:54Z</dc:date>
    </item>
    <item>
      <title>Re: How do I force users to su to a non-root account?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-do-i-force-users-to-su-to-a-non-root-account/m-p/2625056#M39646</link>
      <description>If you mean, like a DBA, who has to log in under his *own* account before he can su to oracle... This has come up several times before... see the attached link:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://forums.itrc.hp.com/cm/QuestionAnswer/1,,0x7924cbaac6dcd5118ff40090279cd0f9,00.html" target="_blank"&gt;http://forums.itrc.hp.com/cm/QuestionAnswer/1,,0x7924cbaac6dcd5118ff40090279cd0f9,00.html&lt;/A&gt;</description>
      <pubDate>Tue, 04 Dec 2001 17:04:03 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-do-i-force-users-to-su-to-a-non-root-account/m-p/2625056#M39646</guid>
      <dc:creator>Duncan Edmonstone</dc:creator>
      <dc:date>2001-12-04T17:04:03Z</dc:date>
    </item>
    <item>
      <title>Re: How do I force users to su to a non-root account?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-do-i-force-users-to-su-to-a-non-root-account/m-p/2625057#M39647</link>
      <description>I can't even write today.&lt;BR /&gt;&lt;BR /&gt;/etc/securetty with an entry of console disallows telnet and rlogin attempts as root, root can only login on the console.&lt;BR /&gt;&lt;BR /&gt;Geez, was that so hard.&lt;BR /&gt;&lt;BR /&gt;Sorry for my giberish,&lt;BR /&gt;C</description>
      <pubDate>Tue, 04 Dec 2001 17:04:22 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-do-i-force-users-to-su-to-a-non-root-account/m-p/2625057#M39647</guid>
      <dc:creator>Craig Rants</dc:creator>
      <dc:date>2001-12-04T17:04:22Z</dc:date>
    </item>
    <item>
      <title>Re: How do I force users to su to a non-root account?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-do-i-force-users-to-su-to-a-non-root-account/m-p/2625058#M39648</link>
      <description>Justo,&lt;BR /&gt;Yes you are right, forgot about that option.</description>
      <pubDate>Tue, 04 Dec 2001 17:06:07 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-do-i-force-users-to-su-to-a-non-root-account/m-p/2625058#M39648</guid>
      <dc:creator>Craig Rants</dc:creator>
      <dc:date>2001-12-04T17:06:07Z</dc:date>
    </item>
    <item>
      <title>Re: How do I force users to su to a non-root account?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-do-i-force-users-to-su-to-a-non-root-account/m-p/2625059#M39649</link>
      <description>Dan&lt;BR /&gt;&lt;BR /&gt;This does not seem to be in line with the answers given above!  However, I think this is what you want.&lt;BR /&gt;&lt;BR /&gt;if you have a generic non-root user account, say informix you obviously do not want users to directly telnet or rlogin into those accouts as there is no audit trail.  In effect you want a /etc/securetty for regular users (I think).  I do not know of such a beast.  However, if in the .profile of informix you put&lt;BR /&gt;&lt;BR /&gt;wai=$(/usr/bin/logname)&lt;BR /&gt;if [ $wai = informix ]&lt;BR /&gt;then&lt;BR /&gt;        echo "Access denied, use su - user"&lt;BR /&gt;        exec sleep 5&lt;BR /&gt;        exit&lt;BR /&gt;fi&lt;BR /&gt;&lt;BR /&gt;Obviously these files cannot be owned by informix so make them owned by root &amp;amp; readable &lt;BR /&gt;# chmod 440 ~informix/.profile&lt;BR /&gt;OR&lt;BR /&gt;# chmod 444 ~informix/.profile&lt;BR /&gt;# chown root:informix ~informix/.profile&lt;BR /&gt;&lt;BR /&gt;Tim</description>
      <pubDate>Tue, 04 Dec 2001 17:12:02 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-do-i-force-users-to-su-to-a-non-root-account/m-p/2625059#M39649</guid>
      <dc:creator>Tim D Fulford</dc:creator>
      <dc:date>2001-12-04T17:12:02Z</dc:date>
    </item>
    <item>
      <title>Re: How do I force users to su to a non-root account?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-do-i-force-users-to-su-to-a-non-root-account/m-p/2625060#M39650</link>
      <description>Dan, &lt;BR /&gt;can you clarify the question?  Do you want users to automatically su to that account when they login? &lt;BR /&gt;Or do you want that non-root account to only be used by "su" to it, instead of direct login?  An example would be a database generic account such as "oracle" or "sybase".  Can't think of a great way for the first scenario.  For the second, I've accomplished that by modified /etc/profile in the same way that Tim suggests doing in a local .profile.  Either way will work, but I prefer /etc/profile as it makes it a bit easier to administer.</description>
      <pubDate>Tue, 04 Dec 2001 17:21:15 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-do-i-force-users-to-su-to-a-non-root-account/m-p/2625060#M39650</guid>
      <dc:creator>Bernie Vande Griend</dc:creator>
      <dc:date>2001-12-04T17:21:15Z</dc:date>
    </item>
    <item>
      <title>Re: How do I force users to su to a non-root account?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-do-i-force-users-to-su-to-a-non-root-account/m-p/2625061#M39651</link>
      <description>Hi Dan,&lt;BR /&gt;&lt;BR /&gt;There is no HPUX mechanism such as securetty for non-root accounts.  I believe you will have to put edits in /etc/profile to do what you want (or /etc/csh.login if a csh account).&lt;BR /&gt;&lt;BR /&gt;You may try putting the edits in the account's .profile but you would have to put sticky bit on the directory, chown the directory to root, and generally a bunch of stuff that makes life more difficult for that account.&lt;BR /&gt;&lt;BR /&gt;There's a number of threads along this line in the forums.  My best search results are from search.hp.com on something like:  +login +su +restrict&lt;BR /&gt;&lt;BR /&gt;Darrell</description>
      <pubDate>Tue, 04 Dec 2001 17:23:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-do-i-force-users-to-su-to-a-non-root-account/m-p/2625061#M39651</guid>
      <dc:creator>Darrell Allen</dc:creator>
      <dc:date>2001-12-04T17:23:21Z</dc:date>
    </item>
    <item>
      <title>Re: How do I force users to su to a non-root account?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-do-i-force-users-to-su-to-a-non-root-account/m-p/2625062#M39652</link>
      <description>Tim,&lt;BR /&gt;&lt;BR /&gt;The code is good, but you can't protect anything that goes in a users .profile....&lt;BR /&gt;&lt;BR /&gt;Remember that the user 'informix' owns it home directory, so they can delete any file in there. If I was the informix DBA, and the code you'd added was annoying me I'd do this:&lt;BR /&gt;&lt;BR /&gt;cp .profile .profile.new&lt;BR /&gt;&amp;lt; remove those annoying lines in .profile.new&amp;gt;&lt;BR /&gt;rm -f .profile&lt;BR /&gt;mv .profile.new .profile&lt;BR /&gt;&lt;BR /&gt;So to stop this you must add the code to /etc/profile, which is also run  at login, but the user *can't* edit or change&lt;BR /&gt;&lt;BR /&gt;HTH&lt;BR /&gt;&lt;BR /&gt;Duncan</description>
      <pubDate>Tue, 04 Dec 2001 17:24:00 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-do-i-force-users-to-su-to-a-non-root-account/m-p/2625062#M39652</guid>
      <dc:creator>Duncan Edmonstone</dc:creator>
      <dc:date>2001-12-04T17:24:00Z</dc:date>
    </item>
    <item>
      <title>Re: How do I force users to su to a non-root account?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-do-i-force-users-to-su-to-a-non-root-account/m-p/2625063#M39653</link>
      <description>Hi Dan,&lt;BR /&gt;&lt;BR /&gt;Try these links,&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://us-support2.external.hp.com/cki/bin/doc.pl/sid=25405b930db750f8a0/screen=ckiDisplayDocument?docId=200000051899524" target="_blank"&gt;http://us-support2.external.hp.com/cki/bin/doc.pl/sid=25405b930db750f8a0/screen=ckiDisplayDocument?docId=200000051899524&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://us-support2.external.hp.com/cki/bin/doc.pl/sid=25405b930db750f8a0/screen=ckiDisplayDocument?docId=200000027709182" target="_blank"&gt;http://us-support2.external.hp.com/cki/bin/doc.pl/sid=25405b930db750f8a0/screen=ckiDisplayDocument?docId=200000027709182&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Hope this helps.&lt;BR /&gt;&lt;BR /&gt;Regds&lt;BR /&gt;</description>
      <pubDate>Tue, 04 Dec 2001 18:08:14 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-do-i-force-users-to-su-to-a-non-root-account/m-p/2625063#M39653</guid>
      <dc:creator>Sanjay_6</dc:creator>
      <dc:date>2001-12-04T18:08:14Z</dc:date>
    </item>
    <item>
      <title>Re: How do I force users to su to a non-root account?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/how-do-i-force-users-to-su-to-a-non-root-account/m-p/2625064#M39654</link>
      <description>Ok, so the question is you want an account that users cannot login as, but can su to. Guess I missed the intent.&lt;BR /&gt;&lt;BR /&gt;C</description>
      <pubDate>Tue, 04 Dec 2001 20:21:25 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/how-do-i-force-users-to-su-to-a-non-root-account/m-p/2625064#M39654</guid>
      <dc:creator>Craig Rants</dc:creator>
      <dc:date>2001-12-04T20:21:25Z</dc:date>
    </item>
  </channel>
</rss>

