<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unix default users in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/unix-default-users/m-p/5094386#M442938</link>
    <description>I would not touch any of the &lt;BR /&gt;daemon, bin, sys, adm, lp, nobody. They are traditional system accounts and some critical system areas have these as owners or their associated group id as group owner.&lt;BR /&gt;&lt;BR /&gt;uucp, nuupc: Unless you are using uucp (which I have not seen anyone using it since the 1980s) you can remove these accounts&lt;BR /&gt;&lt;BR /&gt;hpdb: Can be deleted. It was a default user for an old HP database (I can't remember its name)&lt;BR /&gt;&lt;BR /&gt;ssh: Used by the sshd service&lt;BR /&gt;&lt;BR /&gt;www, iwww, owww: used by hpws (HP web Services). Even if you dont run any of the hpws services (hpadmin etc) you should leave these alone. They may be needed down the line or during a patch install, upgrade etc.&lt;BR /&gt;&lt;BR /&gt;smbnull: Used by SAMBA (aka CIFS). If you don't run SAMBA the account can be deleted.&lt;BR /&gt;&lt;BR /&gt;mysql: Used by the OpenSQL. It can be deleted if you don't use the openSQL.&lt;BR /&gt;&lt;BR /&gt;tftp: Should be deleted. And keep looking because it gets added back every time you install a new version of igniteUX.&lt;BR /&gt;&lt;BR /&gt;When you clean up your server you should also look into all the installed software and swremove some of those as well. Some of the accounts if removed have istalled software that could also be removed.</description>
    <pubDate>Wed, 05 Mar 2008 13:16:38 GMT</pubDate>
    <dc:creator>TTr</dc:creator>
    <dc:date>2008-03-05T13:16:38Z</dc:date>
    <item>
      <title>Unix default users</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/unix-default-users/m-p/5094382#M442934</link>
      <description>Hi Bodies,&lt;BR /&gt;&lt;BR /&gt;I'm having security compliance observations... one is about the users that exist by default on Unix and its secureness, so the cuestion is:&lt;BR /&gt;Where can I find information about the users that exists by default on Unix and what are the Best Practices to its management?&lt;BR /&gt;&lt;BR /&gt;Thanks,</description>
      <pubDate>Mon, 25 Feb 2008 22:53:24 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/unix-default-users/m-p/5094382#M442934</guid>
      <dc:creator>Gamaliel</dc:creator>
      <dc:date>2008-02-25T22:53:24Z</dc:date>
    </item>
    <item>
      <title>Re: Unix default users</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/unix-default-users/m-p/5094383#M442935</link>
      <description>Hi:&lt;BR /&gt;&lt;BR /&gt;I suspect that you are asking about accounts like 'bin', 'sys', 'daemon', 'adm'. 'uucp', 'lp', 'nobody'.  These are used for daemon processes and to provide some degree of granular security for subsystems like printing and NFS.  You will note that the password associated with these accounts is an asterisk ("*") which means that direct login is not allowed.  Hence, tell you auditors to look elsewhere :-)&lt;BR /&gt;&lt;BR /&gt;Regards!&lt;BR /&gt;&lt;BR /&gt;...JRF...</description>
      <pubDate>Mon, 25 Feb 2008 23:44:45 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/unix-default-users/m-p/5094383#M442935</guid>
      <dc:creator>James R. Ferguson</dc:creator>
      <dc:date>2008-02-25T23:44:45Z</dc:date>
    </item>
    <item>
      <title>Re: Unix default users</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/unix-default-users/m-p/5094384#M442936</link>
      <description>Hi James,&lt;BR /&gt;&lt;BR /&gt;Maybe I'll sound so silly, but...&lt;BR /&gt;&lt;BR /&gt;I think all the passwords are marked as * because the server is configured in trusted mode, isn't? The users daemon, bin, sys, adm, lp, hpdb, www, webadmin, sshd can't connect because they have /usr/bin/false as their starting shell. I have other users as uucp, nuucp, smbnull, iwww, owww, mysql that seem to be as default users... anyway they stand for what? Any documentation?</description>
      <pubDate>Tue, 04 Mar 2008 22:49:01 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/unix-default-users/m-p/5094384#M442936</guid>
      <dc:creator>Gamaliel</dc:creator>
      <dc:date>2008-03-04T22:49:01Z</dc:date>
    </item>
    <item>
      <title>Re: Unix default users</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/unix-default-users/m-p/5094385#M442937</link>
      <description>Jo,&lt;BR /&gt;&lt;BR /&gt;refer to this &lt;A href="http://docs.hp.com/en/B2355-90950/ch08s03.html" target="_blank"&gt;http://docs.hp.com/en/B2355-90950/ch08s03.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Eliminating Pseudo-Accounts and Protecting Key Subsystems &lt;BR /&gt; &lt;BR /&gt;By tradition, the /etc/passwd file contains numerous â  pseudo-accountsâ   â   entries not associated with individual users and which do not have true interactive login shells.&lt;BR /&gt;&lt;BR /&gt;WK&lt;BR /&gt;</description>
      <pubDate>Wed, 05 Mar 2008 06:17:09 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/unix-default-users/m-p/5094385#M442937</guid>
      <dc:creator>whiteknight</dc:creator>
      <dc:date>2008-03-05T06:17:09Z</dc:date>
    </item>
    <item>
      <title>Re: Unix default users</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/unix-default-users/m-p/5094386#M442938</link>
      <description>I would not touch any of the &lt;BR /&gt;daemon, bin, sys, adm, lp, nobody. They are traditional system accounts and some critical system areas have these as owners or their associated group id as group owner.&lt;BR /&gt;&lt;BR /&gt;uucp, nuupc: Unless you are using uucp (which I have not seen anyone using it since the 1980s) you can remove these accounts&lt;BR /&gt;&lt;BR /&gt;hpdb: Can be deleted. It was a default user for an old HP database (I can't remember its name)&lt;BR /&gt;&lt;BR /&gt;ssh: Used by the sshd service&lt;BR /&gt;&lt;BR /&gt;www, iwww, owww: used by hpws (HP web Services). Even if you dont run any of the hpws services (hpadmin etc) you should leave these alone. They may be needed down the line or during a patch install, upgrade etc.&lt;BR /&gt;&lt;BR /&gt;smbnull: Used by SAMBA (aka CIFS). If you don't run SAMBA the account can be deleted.&lt;BR /&gt;&lt;BR /&gt;mysql: Used by the OpenSQL. It can be deleted if you don't use the openSQL.&lt;BR /&gt;&lt;BR /&gt;tftp: Should be deleted. And keep looking because it gets added back every time you install a new version of igniteUX.&lt;BR /&gt;&lt;BR /&gt;When you clean up your server you should also look into all the installed software and swremove some of those as well. Some of the accounts if removed have istalled software that could also be removed.</description>
      <pubDate>Wed, 05 Mar 2008 13:16:38 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/unix-default-users/m-p/5094386#M442938</guid>
      <dc:creator>TTr</dc:creator>
      <dc:date>2008-03-05T13:16:38Z</dc:date>
    </item>
    <item>
      <title>Re: Unix default users</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/unix-default-users/m-p/5094387#M442939</link>
      <description>Thank you all, your comments where helpful as always.&lt;BR /&gt;&lt;BR /&gt;JSG</description>
      <pubDate>Tue, 18 Mar 2008 16:13:56 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/unix-default-users/m-p/5094387#M442939</guid>
      <dc:creator>Gamaliel</dc:creator>
      <dc:date>2008-03-18T16:13:56Z</dc:date>
    </item>
  </channel>
</rss>

