<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: I need help finding a way to search for disabled account in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/i-need-help-finding-a-way-to-search-for-disabled-account/m-p/5076586#M439664</link>
    <description>closig with the current informations. Thanks to all.</description>
    <pubDate>Sun, 18 Nov 2007 19:22:01 GMT</pubDate>
    <dc:creator>skt_skt</dc:creator>
    <dc:date>2007-11-18T19:22:01Z</dc:date>
    <item>
      <title>I need help finding a way to search for disabled account</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/i-need-help-finding-a-way-to-search-for-disabled-account/m-p/5076573#M439651</link>
      <description>I need help finding a way to search for disabled account in linux</description>
      <pubDate>Fri, 26 Oct 2007 15:27:30 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/i-need-help-finding-a-way-to-search-for-disabled-account/m-p/5076573#M439651</guid>
      <dc:creator>skt_skt</dc:creator>
      <dc:date>2007-10-26T15:27:30Z</dc:date>
    </item>
    <item>
      <title>Re: I need help finding a way to search for disabled account</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/i-need-help-finding-a-way-to-search-for-disabled-account/m-p/5076574#M439652</link>
      <description>disabled/deactivated..</description>
      <pubDate>Fri, 26 Oct 2007 15:28:28 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/i-need-help-finding-a-way-to-search-for-disabled-account/m-p/5076574#M439652</guid>
      <dc:creator>skt_skt</dc:creator>
      <dc:date>2007-10-26T15:28:28Z</dc:date>
    </item>
    <item>
      <title>Re: I need help finding a way to search for disabled account</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/i-need-help-finding-a-way-to-search-for-disabled-account/m-p/5076575#M439653</link>
      <description>Run a 'passwd -Sa' (that is a capital S and a lowercase a) and look for accounts that have an 'LK' in the 2nd column.  Those accounts are locked.</description>
      <pubDate>Fri, 26 Oct 2007 15:41:24 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/i-need-help-finding-a-way-to-search-for-disabled-account/m-p/5076575#M439653</guid>
      <dc:creator>Patrick Wallek</dc:creator>
      <dc:date>2007-10-26T15:41:24Z</dc:date>
    </item>
    <item>
      <title>Re: I need help finding a way to search for disabled account</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/i-need-help-finding-a-way-to-search-for-disabled-account/m-p/5076576#M439654</link>
      <description>Patrick...you missed the "in linux" part&lt;BR /&gt;he's got 2 posts in the Linux forums as well.</description>
      <pubDate>Fri, 26 Oct 2007 15:56:58 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/i-need-help-finding-a-way-to-search-for-disabled-account/m-p/5076576#M439654</guid>
      <dc:creator>OldSchool</dc:creator>
      <dc:date>2007-10-26T15:56:58Z</dc:date>
    </item>
    <item>
      <title>Re: I need help finding a way to search for disabled account</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/i-need-help-finding-a-way-to-search-for-disabled-account/m-p/5076577#M439655</link>
      <description>Umm...No I didn't miss the "Linux" part.&lt;BR /&gt;&lt;BR /&gt;I ran the "passwd -Sa" on my SuSE Linux Enterprise Server 10 machine and it works great.&lt;BR /&gt;&lt;BR /&gt;Now since he didn't mention WHICH LINUX, I can't be responsible if what works on my SLES box doesn't work on his "other Linux flavor" box.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 26 Oct 2007 16:16:59 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/i-need-help-finding-a-way-to-search-for-disabled-account/m-p/5076577#M439655</guid>
      <dc:creator>Patrick Wallek</dc:creator>
      <dc:date>2007-10-26T16:16:59Z</dc:date>
    </item>
    <item>
      <title>Re: I need help finding a way to search for disabled account</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/i-need-help-finding-a-way-to-search-for-disabled-account/m-p/5076578#M439656</link>
      <description>let me be clear; i am looking for an answer in HP-UX since it is an HP-UX forum. I have a separate question in linux.(i forgot to remove "linux" filed while posting the similar question in HP-UX forum).&lt;BR /&gt;&lt;BR /&gt;[/root] /usr/lbin/getprpw kumarts&lt;BR /&gt;uid=19806, bootpw=NO, audid=2351, audflg=1, mintm=-1, maxpwln=-1, exptm=-1, lftm=-1, spwchg=Mon Oct 15 15:17:03 2007, upwchg=Fri Sep  7 15:53:26 2007, acctexp=-1, llog=-1, expwarn=-1, usrpick=DFT, syspnpw=DFT, rstrpw=DFT, nullpw=DFT, admnum=-1, syschpw=DFT, sysltpw=DFT, timeod=-1, slogint=Fri Oct 26 19:18:49 2007, ulogint=Fri Oct 26 09:05:52 2007, sloginy=tty, culogin=-1, uloginy=-1, umaxlntr=-1, alock=NO, lockout=0000000&lt;BR /&gt;&lt;BR /&gt;the value lockout=0000000 tells me the account is NOT locked.&lt;BR /&gt;&lt;BR /&gt;May be i am confused with account deactivated and locked. is there a  diffrence between deactivated and locked state.&lt;BR /&gt;&lt;BR /&gt;My intention is to delete the deactivated accounts. But i DONT want the accounts to be deleted whihc are locked (example due to 5 login failures; a needed account can be in locked state at that point of time).&lt;BR /&gt;&lt;BR /&gt;So i want to identify only deactivated accounts?&lt;BR /&gt;&lt;BR /&gt;here my concern i see some of the accounts are in deactivated state but they are still in use/can be used.This i observed for set of ftp accounts and thier properties are below.(Please note that this accounts was recreated recently as the account was deleted assuming not in use/deactivated; so you can see new dates for spwchg,slogint now)&lt;BR /&gt;&lt;BR /&gt;/usr/lbin/getprpw amsboa01&lt;BR /&gt;uid=154, bootpw=NO, audid=2740, audflg=1, mintm=0, maxpwln=-1, exptm=0, lftm=0, spwchg=Thu Oct 25 09:05:39 2007, upwchg=-1, acctexp=-1, llog=0, expwarn=0, usrpick=DFT, syspnpw=DFT, rstrpw=DFT, nullpw=DFT, admnum=-1, syschpw=DFT, sysltpw=DFT, timeod=-1, slogint=Thu Oct 25 08:43:26 2007, ulogint=-1, sloginy=-1, culogin=-1, uloginy=-1, umaxlntr=-1, alock=NO, lockout=0000000&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;did i get that correct(accounts are in deactivated state but they are still in use)?if that is correct/incorrect , how we can explain that scenario?&lt;BR /&gt;</description>
      <pubDate>Fri, 26 Oct 2007 18:43:57 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/i-need-help-finding-a-way-to-search-for-disabled-account/m-p/5076578#M439656</guid>
      <dc:creator>skt_skt</dc:creator>
      <dc:date>2007-10-26T18:43:57Z</dc:date>
    </item>
    <item>
      <title>Re: I need help finding a way to search for disabled account</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/i-need-help-finding-a-way-to-search-for-disabled-account/m-p/5076579#M439657</link>
      <description>If you are on HP-UX 11.11 or higher then do a 'man getprpw' and look for the "lockout" section.  There you will see what each position of the 'lockout=0000000' means.  Each position mean a different thing.  &lt;BR /&gt;&lt;BR /&gt;The bottom line though is if ANY position has a '1' in it, then the user can't login.</description>
      <pubDate>Fri, 26 Oct 2007 20:04:01 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/i-need-help-finding-a-way-to-search-for-disabled-account/m-p/5076579#M439657</guid>
      <dc:creator>Patrick Wallek</dc:creator>
      <dc:date>2007-10-26T20:04:01Z</dc:date>
    </item>
    <item>
      <title>Re: I need help finding a way to search for disabled account</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/i-need-help-finding-a-way-to-search-for-disabled-account/m-p/5076580#M439658</link>
      <description>WWhy don't you check in /etc/passwd file.The entries having * for there passwd field are the disabled ones.&lt;BR /&gt;</description>
      <pubDate>Fri, 26 Oct 2007 23:06:38 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/i-need-help-finding-a-way-to-search-for-disabled-account/m-p/5076580#M439658</guid>
      <dc:creator>Sachin Rajput</dc:creator>
      <dc:date>2007-10-26T23:06:38Z</dc:date>
    </item>
    <item>
      <title>Re: I need help finding a way to search for disabled account</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/i-need-help-finding-a-way-to-search-for-disabled-account/m-p/5076581#M439659</link>
      <description>i know about this 7 bits.&lt;BR /&gt;&lt;BR /&gt;REASON[1]="past password lifetime" &lt;BR /&gt;REASON[2]="past last login time" &lt;BR /&gt;REASON[3]="past absolute account lifetime" &lt;BR /&gt;REASON[4]="exceeding unsuccessful login attempts" &lt;BR /&gt;REASON[5]="password required and a null password" &lt;BR /&gt;REASON[6]="admin lock" &lt;BR /&gt;REASON[7]="password is a *" &lt;BR /&gt;&lt;BR /&gt;So did u mean if the account is locked(one of the bits is one) the account is in "deactivated" state?</description>
      <pubDate>Sat, 27 Oct 2007 20:13:59 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/i-need-help-finding-a-way-to-search-for-disabled-account/m-p/5076581#M439659</guid>
      <dc:creator>skt_skt</dc:creator>
      <dc:date>2007-10-27T20:13:59Z</dc:date>
    </item>
    <item>
      <title>Re: I need help finding a way to search for disabled account</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/i-need-help-finding-a-way-to-search-for-disabled-account/m-p/5076582#M439660</link>
      <description>You said:  "So did u mean if the account is locked(one of the bits is one) the account is in "deactivated" state?"&lt;BR /&gt;&lt;BR /&gt;If there is a '1' in ANY position in the lockout string, then the user CANNOT login.  Whether you call that locked, disabled or deactivated is entirely up to you.</description>
      <pubDate>Sat, 27 Oct 2007 21:46:35 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/i-need-help-finding-a-way-to-search-for-disabled-account/m-p/5076582#M439660</guid>
      <dc:creator>Patrick Wallek</dc:creator>
      <dc:date>2007-10-27T21:46:35Z</dc:date>
    </item>
    <item>
      <title>Re: I need help finding a way to search for disabled account</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/i-need-help-finding-a-way-to-search-for-disabled-account/m-p/5076583#M439661</link>
      <description>Note to  Sachin Rajput:&lt;BR /&gt;&lt;BR /&gt;You said:  " WWhy don't you check in /etc/passwd file.The entries having * for there passwd field are the disabled ones."&lt;BR /&gt;&lt;BR /&gt;Since Santhosh asked about the output of the getprpw command, specifically the "lockout" value, that indicated that this system is set up as a TRUSTED system.  If you review how a trusted system works, you will discover that ALL account have a '*' in the passwd field in the /etc/passwd file.  That is because the password is NOT actually stored there.  The passwords are stored in the /tcb/files/auth/* directory structure.  &lt;BR /&gt;&lt;BR /&gt;In this case the '*' does NOT indicate the account is disabled.&lt;BR /&gt;</description>
      <pubDate>Sat, 27 Oct 2007 21:50:05 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/i-need-help-finding-a-way-to-search-for-disabled-account/m-p/5076583#M439661</guid>
      <dc:creator>Patrick Wallek</dc:creator>
      <dc:date>2007-10-27T21:50:05Z</dc:date>
    </item>
    <item>
      <title>Re: I need help finding a way to search for disabled account</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/i-need-help-finding-a-way-to-search-for-disabled-account/m-p/5076584#M439662</link>
      <description>awk -F: '{print $1}|while read list&lt;BR /&gt;do&lt;BR /&gt;/usr/lbin/getprpw -m lockout $list|awk -F= '$2 != "0000000" {print "DEACTIVATED"}'&lt;BR /&gt;done&lt;BR /&gt;&lt;BR /&gt;Add your own tweaks as needed.&lt;BR /&gt;</description>
      <pubDate>Mon, 29 Oct 2007 11:04:19 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/i-need-help-finding-a-way-to-search-for-disabled-account/m-p/5076584#M439662</guid>
      <dc:creator>Tim Nelson</dc:creator>
      <dc:date>2007-10-29T11:04:19Z</dc:date>
    </item>
    <item>
      <title>Re: I need help finding a way to search for disabled account</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/i-need-help-finding-a-way-to-search-for-disabled-account/m-p/5076585#M439663</link>
      <description>ooops.&lt;BR /&gt;&lt;BR /&gt;awk -F: '{print $1} /etc/passwd|while read list&lt;BR /&gt;do&lt;BR /&gt;/usr/lbin/getprpw -m lockout $list|awk -F= '$2 != "0000000" {print "DEACTIVATED"}'&lt;BR /&gt;done&lt;BR /&gt;</description>
      <pubDate>Mon, 29 Oct 2007 11:15:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/i-need-help-finding-a-way-to-search-for-disabled-account/m-p/5076585#M439663</guid>
      <dc:creator>Tim Nelson</dc:creator>
      <dc:date>2007-10-29T11:15:41Z</dc:date>
    </item>
    <item>
      <title>Re: I need help finding a way to search for disabled account</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/i-need-help-finding-a-way-to-search-for-disabled-account/m-p/5076586#M439664</link>
      <description>closig with the current informations. Thanks to all.</description>
      <pubDate>Sun, 18 Nov 2007 19:22:01 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/i-need-help-finding-a-way-to-search-for-disabled-account/m-p/5076586#M439664</guid>
      <dc:creator>skt_skt</dc:creator>
      <dc:date>2007-11-18T19:22:01Z</dc:date>
    </item>
    <item>
      <title>Re: I need help finding a way to search for disabled account</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/i-need-help-finding-a-way-to-search-for-disabled-account/m-p/5076587#M439665</link>
      <description>closig with the current informations. Thanks to all.</description>
      <pubDate>Sun, 18 Nov 2007 19:22:19 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/i-need-help-finding-a-way-to-search-for-disabled-account/m-p/5076587#M439665</guid>
      <dc:creator>skt_skt</dc:creator>
      <dc:date>2007-11-18T19:22:19Z</dc:date>
    </item>
  </channel>
</rss>

