<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Restrict initial logins to accounts other than root? in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/restrict-initial-logins-to-accounts-other-than-root/m-p/5016400#M427503</link>
    <description>Hi (again) Carl:&lt;BR /&gt;&lt;BR /&gt;Hmmm...0-points for attempting to help you when your question/problem description assumes someone is Miss Cleo...&lt;BR /&gt;&lt;BR /&gt;...JRF...</description>
    <pubDate>Thu, 30 Nov 2006 14:02:01 GMT</pubDate>
    <dc:creator>James R. Ferguson</dc:creator>
    <dc:date>2006-11-30T14:02:01Z</dc:date>
    <item>
      <title>Restrict initial logins to accounts other than root?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/restrict-initial-logins-to-accounts-other-than-root/m-p/5016393#M427496</link>
      <description>Is there any way to do this?   We have several accounts that are used for running an application and would prefer that users not initially login to those accounts.  Instead, they should use their personal login and then su to the application account.  The purpose is to have some audit trail in syslog of who was operating under those accounts.&lt;BR /&gt;&lt;BR /&gt;I know how to do this for CDE, but what about telnet and sshd?&lt;BR /&gt;&lt;BR /&gt;thanks all...</description>
      <pubDate>Thu, 30 Nov 2006 12:08:43 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/restrict-initial-logins-to-accounts-other-than-root/m-p/5016393#M427496</guid>
      <dc:creator>Carl Houseman</dc:creator>
      <dc:date>2006-11-30T12:08:43Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict initial logins to accounts other than root?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/restrict-initial-logins-to-accounts-other-than-root/m-p/5016394#M427497</link>
      <description>Hi Carl,&lt;BR /&gt;&lt;BR /&gt;This thread should be able to help you:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=123216&amp;amp;admit=-682735245+1164908912885+28353475" target="_blank"&gt;http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=123216&amp;amp;admit=-682735245+1164908912885+28353475&lt;/A&gt;</description>
      <pubDate>Thu, 30 Nov 2006 12:49:17 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/restrict-initial-logins-to-accounts-other-than-root/m-p/5016394#M427497</guid>
      <dc:creator>Coolmar</dc:creator>
      <dc:date>2006-11-30T12:49:17Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict initial logins to accounts other than root?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/restrict-initial-logins-to-accounts-other-than-root/m-p/5016395#M427498</link>
      <description>A link earlier in that thread doesn't work.&lt;BR /&gt;&lt;BR /&gt;Later on in the thread it suggests changes to .profile but there's a hitch I forgot to mention.   Users need to be able to&lt;BR /&gt;&lt;BR /&gt;su - name&lt;BR /&gt;&lt;BR /&gt;to get to the restricted acount.  So they will execute the .profile from su.  Need another way.</description>
      <pubDate>Thu, 30 Nov 2006 13:11:10 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/restrict-initial-logins-to-accounts-other-than-root/m-p/5016395#M427498</guid>
      <dc:creator>Carl Houseman</dc:creator>
      <dc:date>2006-11-30T13:11:10Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict initial logins to accounts other than root?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/restrict-initial-logins-to-accounts-other-than-root/m-p/5016396#M427499</link>
      <description>This is the thread you need:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=1023896" target="_blank"&gt;http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=1023896&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;The example is for oracle but you can modify it to use with any account.</description>
      <pubDate>Thu, 30 Nov 2006 13:14:48 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/restrict-initial-logins-to-accounts-other-than-root/m-p/5016396#M427499</guid>
      <dc:creator>Ivan Ferreira</dc:creator>
      <dc:date>2006-11-30T13:14:48Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict initial logins to accounts other than root?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/restrict-initial-logins-to-accounts-other-than-root/m-p/5016397#M427500</link>
      <description>Hi Carl:&lt;BR /&gt;&lt;BR /&gt;Executing 'su - logname' will cause the '.profile' for the 'logname' to be executed.  [Posix shell assumed, here.]&lt;BR /&gt;&lt;BR /&gt;As the last piece of the '.profile':&lt;BR /&gt;&lt;BR /&gt;# exec /your_application_code&lt;BR /&gt;&lt;BR /&gt;Regards!&lt;BR /&gt;&lt;BR /&gt;...JRF...</description>
      <pubDate>Thu, 30 Nov 2006 13:18:00 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/restrict-initial-logins-to-accounts-other-than-root/m-p/5016397#M427500</guid>
      <dc:creator>James R. Ferguson</dc:creator>
      <dc:date>2006-11-30T13:18:00Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict initial logins to accounts other than root?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/restrict-initial-logins-to-accounts-other-than-root/m-p/5016398#M427501</link>
      <description>How about any of these suggestions:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=1048593" target="_blank"&gt;http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=1048593&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=1070664" target="_blank"&gt;http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=1070664&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 30 Nov 2006 13:19:29 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/restrict-initial-logins-to-accounts-other-than-root/m-p/5016398#M427501</guid>
      <dc:creator>Coolmar</dc:creator>
      <dc:date>2006-11-30T13:19:29Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict initial logins to accounts other than root?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/restrict-initial-logins-to-accounts-other-than-root/m-p/5016399#M427502</link>
      <description>Ivan's reference thread had everything I need to fix up both sshd and telnet (with .profile changes).  Thanks Ivan!&lt;BR /&gt;&lt;BR /&gt;And in case that thread disappears, the solutions I've implemented are:&lt;BR /&gt;&lt;BR /&gt;sshd_config:&lt;BR /&gt;  DenyUsers username&lt;BR /&gt;&lt;BR /&gt;.profile:&lt;BR /&gt;if [ `who -m|grep 'acctname'|wc -l` -gt 0 ]&lt;BR /&gt;then&lt;BR /&gt;  exit&lt;BR /&gt;fi&lt;BR /&gt;&lt;BR /&gt;with .profile owned by root and restricted permissions to prevent user changes.</description>
      <pubDate>Thu, 30 Nov 2006 13:46:33 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/restrict-initial-logins-to-accounts-other-than-root/m-p/5016399#M427502</guid>
      <dc:creator>Carl Houseman</dc:creator>
      <dc:date>2006-11-30T13:46:33Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict initial logins to accounts other than root?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/restrict-initial-logins-to-accounts-other-than-root/m-p/5016400#M427503</link>
      <description>Hi (again) Carl:&lt;BR /&gt;&lt;BR /&gt;Hmmm...0-points for attempting to help you when your question/problem description assumes someone is Miss Cleo...&lt;BR /&gt;&lt;BR /&gt;...JRF...</description>
      <pubDate>Thu, 30 Nov 2006 14:02:01 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/restrict-initial-logins-to-accounts-other-than-root/m-p/5016400#M427503</guid>
      <dc:creator>James R. Ferguson</dc:creator>
      <dc:date>2006-11-30T14:02:01Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict initial logins to accounts other than root?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/restrict-initial-logins-to-accounts-other-than-root/m-p/5016401#M427504</link>
      <description>Apparently others in this topic were more in touch with Miss Cleo than you, James.&lt;BR /&gt;&lt;BR /&gt;Either that or Miss Cleo wasn't really needed.&lt;BR /&gt;</description>
      <pubDate>Thu, 30 Nov 2006 14:09:58 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/restrict-initial-logins-to-accounts-other-than-root/m-p/5016401#M427504</guid>
      <dc:creator>Carl Houseman</dc:creator>
      <dc:date>2006-11-30T14:09:58Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict initial logins to accounts other than root?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/restrict-initial-logins-to-accounts-other-than-root/m-p/5016402#M427505</link>
      <description>Hi:&lt;BR /&gt;&lt;BR /&gt;&amp;gt; Apparently others in this topic were more in touch with Miss Cleo than you, James.  Either that or Miss Cleo wasn't really needed.&lt;BR /&gt;&lt;BR /&gt;Yeah, and I'll venture to say that you probably wouldn't say "thank you" to someone who even held a door open for you.&lt;BR /&gt;&lt;BR /&gt;Don't worry, I got your point (no pun intended).&lt;BR /&gt;&lt;BR /&gt;...JRF...</description>
      <pubDate>Thu, 30 Nov 2006 14:16:38 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/restrict-initial-logins-to-accounts-other-than-root/m-p/5016402#M427505</guid>
      <dc:creator>James R. Ferguson</dc:creator>
      <dc:date>2006-11-30T14:16:38Z</dc:date>
    </item>
  </channel>
</rss>

