<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic disable certain user login but allow su - in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/disable-certain-user-login-but-allow-su/m-p/4980352#M419710</link>
    <description>I very quick easy question I hope.&lt;BR /&gt;&lt;BR /&gt;On a HP-UX 11.11 system that uses a tcb database is it possible to stop certain users from logging in interactively but allowing su access to them.&lt;BR /&gt;&lt;BR /&gt;I know I could do something with their .profile, but I was wondering if it is possible to do this with a setting in the /etc/passwd file or in the tcb database?&lt;BR /&gt;</description>
    <pubDate>Tue, 23 May 2006 08:54:57 GMT</pubDate>
    <dc:creator>Steve Blackwell</dc:creator>
    <dc:date>2006-05-23T08:54:57Z</dc:date>
    <item>
      <title>disable certain user login but allow su -</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/disable-certain-user-login-but-allow-su/m-p/4980352#M419710</link>
      <description>I very quick easy question I hope.&lt;BR /&gt;&lt;BR /&gt;On a HP-UX 11.11 system that uses a tcb database is it possible to stop certain users from logging in interactively but allowing su access to them.&lt;BR /&gt;&lt;BR /&gt;I know I could do something with their .profile, but I was wondering if it is possible to do this with a setting in the /etc/passwd file or in the tcb database?&lt;BR /&gt;</description>
      <pubDate>Tue, 23 May 2006 08:54:57 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/disable-certain-user-login-but-allow-su/m-p/4980352#M419710</guid>
      <dc:creator>Steve Blackwell</dc:creator>
      <dc:date>2006-05-23T08:54:57Z</dc:date>
    </item>
    <item>
      <title>Re: disable certain user login but allow su -</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/disable-certain-user-login-but-allow-su/m-p/4980353#M419711</link>
      <description>Hi,&lt;BR /&gt;you can try to put a * simbol in the password field in the /etc/passwd file.&lt;BR /&gt;&lt;BR /&gt;Enrico</description>
      <pubDate>Tue, 23 May 2006 09:05:14 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/disable-certain-user-login-but-allow-su/m-p/4980353#M419711</guid>
      <dc:creator>Enrico P.</dc:creator>
      <dc:date>2006-05-23T09:05:14Z</dc:date>
    </item>
    <item>
      <title>Re: disable certain user login but allow su -</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/disable-certain-user-login-but-allow-su/m-p/4980354#M419712</link>
      <description>Hi,&lt;BR /&gt;you can try to put a * simbol in the password field in the /etc/passwd file.&lt;BR /&gt;&lt;BR /&gt;Remember to save you passwd file first&lt;BR /&gt;&lt;BR /&gt;Enrico</description>
      <pubDate>Tue, 23 May 2006 09:05:49 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/disable-certain-user-login-but-allow-su/m-p/4980354#M419712</guid>
      <dc:creator>Enrico P.</dc:creator>
      <dc:date>2006-05-23T09:05:49Z</dc:date>
    </item>
    <item>
      <title>Re: disable certain user login but allow su -</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/disable-certain-user-login-but-allow-su/m-p/4980355#M419713</link>
      <description>Because the system is trusted the * in the /etc/passwd file already exists.&lt;BR /&gt;&lt;BR /&gt;Is there a setting for the tcb database?&lt;BR /&gt;&lt;BR /&gt;Steve</description>
      <pubDate>Tue, 23 May 2006 09:12:09 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/disable-certain-user-login-but-allow-su/m-p/4980355#M419713</guid>
      <dc:creator>Steve Blackwell</dc:creator>
      <dc:date>2006-05-23T09:12:09Z</dc:date>
    </item>
    <item>
      <title>Re: disable certain user login but allow su -</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/disable-certain-user-login-but-allow-su/m-p/4980356#M419714</link>
      <description>As a trusted system, you will want the /tcb/files/auth directory area. From this point the subdirectory would match the 1st letter of the account name.&lt;BR /&gt;Example, for the root account, /tcb/files/auth/r (root starts with the letter 'r' so proceed down this subdirectory)&lt;BR /&gt;&lt;BR /&gt;Put a star in the passwd field in here and you will lock the account. &lt;BR /&gt;&lt;BR /&gt;HPUX does not really have Role Based Access Control (RBAC) until version 11.23.&lt;BR /&gt;&lt;BR /&gt;There are numerous previous posts concerning this subject.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 23 May 2006 09:30:56 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/disable-certain-user-login-but-allow-su/m-p/4980356#M419714</guid>
      <dc:creator>Rick Garland</dc:creator>
      <dc:date>2006-05-23T09:30:56Z</dc:date>
    </item>
    <item>
      <title>Re: disable certain user login but allow su -</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/disable-certain-user-login-but-allow-su/m-p/4980357#M419715</link>
      <description>In rethinking, the better option would be to use the modprpw command to lock the accounts. No need to fool around in the tcb database by yourself. Let the command do it for you.</description>
      <pubDate>Tue, 23 May 2006 10:50:33 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/disable-certain-user-login-but-allow-su/m-p/4980357#M419715</guid>
      <dc:creator>Rick Garland</dc:creator>
      <dc:date>2006-05-23T10:50:33Z</dc:date>
    </item>
    <item>
      <title>Re: disable certain user login but allow su -</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/disable-certain-user-login-but-allow-su/m-p/4980358#M419716</link>
      <description>However, you should note that if you lock the account either by entering an impossible passwd hash (e.g. '*') or by explicitly locking the account via passwd -l or modprpw the only a superuser will be able to su to that account; all other users will be prompted for a password or told that the account is locked.</description>
      <pubDate>Tue, 23 May 2006 10:56:26 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/disable-certain-user-login-but-allow-su/m-p/4980358#M419716</guid>
      <dc:creator>A. Clay Stephenson</dc:creator>
      <dc:date>2006-05-23T10:56:26Z</dc:date>
    </item>
    <item>
      <title>Re: disable certain user login but allow su -</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/disable-certain-user-login-but-allow-su/m-p/4980359#M419717</link>
      <description>Lock the password as noted above and use&lt;BR /&gt;the sudo package to su to the account. &lt;BR /&gt;The password prompted for by sudo is the account executing the su command not the&lt;BR /&gt;target account.  su will be done as system&lt;BR /&gt;and will not require an active password.&lt;BR /&gt;</description>
      <pubDate>Tue, 23 May 2006 11:04:50 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/disable-certain-user-login-but-allow-su/m-p/4980359#M419717</guid>
      <dc:creator>Bill Thorsteinson</dc:creator>
      <dc:date>2006-05-23T11:04:50Z</dc:date>
    </item>
    <item>
      <title>Re: disable certain user login but allow su -</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/disable-certain-user-login-but-allow-su/m-p/4980360#M419718</link>
      <description>You have all confirmed my thoughts.&lt;BR /&gt;&lt;BR /&gt;Cheers&lt;BR /&gt;&lt;BR /&gt;Steve</description>
      <pubDate>Thu, 25 May 2006 03:42:36 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/disable-certain-user-login-but-allow-su/m-p/4980360#M419718</guid>
      <dc:creator>Steve Blackwell</dc:creator>
      <dc:date>2006-05-25T03:42:36Z</dc:date>
    </item>
  </channel>
</rss>

