<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User Login in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/user-login/m-p/5171573#M458161</link>
    <description>Ravi,&lt;BR /&gt;&lt;BR /&gt;I changed the passwd field in the (my case) /etc/shadow file to LOCKED for a test user. Now you can use su - user to switch user, but you can not login directly with this user account.&lt;BR /&gt;&lt;BR /&gt;gorj:LOCKED:14361::::::&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Robert-Jan</description>
    <pubDate>Mon, 27 Apr 2009 10:27:22 GMT</pubDate>
    <dc:creator>Robert-Jan Goossens_1</dc:creator>
    <dc:date>2009-04-27T10:27:22Z</dc:date>
    <item>
      <title>User Login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/user-login/m-p/5171568#M458156</link>
      <description>hi,&lt;BR /&gt;&lt;BR /&gt;Following is my requirement.&lt;BR /&gt;&lt;BR /&gt;I have a unix user which controls the applicaiton. No one should login to the server using this account using ssh or telnet or any other application.&lt;BR /&gt;&lt;BR /&gt;They shud login using their individual account and then they should be able to do su - apps_account.&lt;BR /&gt;&lt;BR /&gt;Is it possible, if so, please explain.&lt;BR /&gt;&lt;BR /&gt;Cheers,&lt;BR /&gt;Ravi</description>
      <pubDate>Fri, 24 Apr 2009 11:57:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/user-login/m-p/5171568#M458156</guid>
      <dc:creator>G V R Shankar</dc:creator>
      <dc:date>2009-04-24T11:57:41Z</dc:date>
    </item>
    <item>
      <title>Re: User Login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/user-login/m-p/5171569#M458157</link>
      <description>Hi Ravi,&lt;BR /&gt;&lt;BR /&gt;Just lock the password of the user.&lt;BR /&gt;&lt;BR /&gt;# passwd -l user&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Robert-Jan</description>
      <pubDate>Fri, 24 Apr 2009 12:03:36 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/user-login/m-p/5171569#M458157</guid>
      <dc:creator>Robert-Jan Goossens_1</dc:creator>
      <dc:date>2009-04-24T12:03:36Z</dc:date>
    </item>
    <item>
      <title>Re: User Login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/user-login/m-p/5171570#M458158</link>
      <description>$ su - test&lt;BR /&gt;Your password was changed by root&lt;BR /&gt;Password:&lt;BR /&gt;Account is disabled - see Account Administrator&lt;BR /&gt;su: Sorry&lt;BR /&gt;&lt;BR /&gt;Doesn't meet my requirement.&lt;BR /&gt;&lt;BR /&gt;Ravi.</description>
      <pubDate>Fri, 24 Apr 2009 12:13:52 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/user-login/m-p/5171570#M458158</guid>
      <dc:creator>G V R Shankar</dc:creator>
      <dc:date>2009-04-24T12:13:52Z</dc:date>
    </item>
    <item>
      <title>Re: User Login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/user-login/m-p/5171571#M458159</link>
      <description>Hi Ravi,&lt;BR /&gt;&lt;BR /&gt;Keep the shell column of the user as /bin/false in /etc/passwd - this will meet ur requirement.&lt;BR /&gt;&lt;BR /&gt;Vinod</description>
      <pubDate>Fri, 24 Apr 2009 12:21:31 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/user-login/m-p/5171571#M458159</guid>
      <dc:creator>vinod_25</dc:creator>
      <dc:date>2009-04-24T12:21:31Z</dc:date>
    </item>
    <item>
      <title>Re: User Login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/user-login/m-p/5171572#M458160</link>
      <description>hi Vinod,&lt;BR /&gt;&lt;BR /&gt;If i keep the shell /bin/false, it will not allow me to login over ssh or even su - test.&lt;BR /&gt;&lt;BR /&gt;Ravi.</description>
      <pubDate>Mon, 27 Apr 2009 09:45:04 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/user-login/m-p/5171572#M458160</guid>
      <dc:creator>G V R Shankar</dc:creator>
      <dc:date>2009-04-27T09:45:04Z</dc:date>
    </item>
    <item>
      <title>Re: User Login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/user-login/m-p/5171573#M458161</link>
      <description>Ravi,&lt;BR /&gt;&lt;BR /&gt;I changed the passwd field in the (my case) /etc/shadow file to LOCKED for a test user. Now you can use su - user to switch user, but you can not login directly with this user account.&lt;BR /&gt;&lt;BR /&gt;gorj:LOCKED:14361::::::&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Robert-Jan</description>
      <pubDate>Mon, 27 Apr 2009 10:27:22 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/user-login/m-p/5171573#M458161</guid>
      <dc:creator>Robert-Jan Goossens_1</dc:creator>
      <dc:date>2009-04-27T10:27:22Z</dc:date>
    </item>
    <item>
      <title>Re: User Login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/user-login/m-p/5171574#M458162</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;There are 2 challeges here. When we change it to LOCKED, it actually changes the password field and whenever user types the password, it doesn't match the encrypted pasword, becoz, we have removed the encrypted password and put a new word LOCKED.&lt;BR /&gt;&lt;BR /&gt;So they user will never login to the server over telnet or ssh. instead of chnaging the encrypted portion, I can just change the password of the apps users and keep it with me ;)&lt;BR /&gt;&lt;BR /&gt;As you said, I can do su - test, but I can do it as root. I cannot switch to the user as a normal user. Again the password will not work.&lt;BR /&gt;&lt;BR /&gt;Cheers,&lt;BR /&gt;&lt;BR /&gt;Ravi.</description>
      <pubDate>Mon, 27 Apr 2009 12:38:14 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/user-login/m-p/5171574#M458162</guid>
      <dc:creator>G V R Shankar</dc:creator>
      <dc:date>2009-04-27T12:38:14Z</dc:date>
    </item>
    <item>
      <title>Re: User Login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/user-login/m-p/5171575#M458163</link>
      <description>Do you have sudo in your environment?  If so, you could set the password to something random and then setup a sudo profile for the users to be able to sudo to the account w/o a password.  Here's an example sudoers for this:&lt;BR /&gt;&lt;BR /&gt;User_Alias PROD =  user1, user2, user3&lt;BR /&gt;PROD ALL = NOPASSWD: /usr/bin/su [-] apps_acct&lt;BR /&gt;&lt;BR /&gt;The user would login with their account and then run: sudo su - apps_acct&lt;BR /&gt;&lt;BR /&gt;If configured properly, the users won't be prompted for the apps_acct password.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 27 Apr 2009 12:47:54 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/user-login/m-p/5171575#M458163</guid>
      <dc:creator>Autocross.US</dc:creator>
      <dc:date>2009-04-27T12:47:54Z</dc:date>
    </item>
    <item>
      <title>Re: User Login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/user-login/m-p/5171576#M458164</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Using sudo is the last thing in my mind. Is there any way to accomplish my requirement.&lt;BR /&gt;&lt;BR /&gt;Ravi.</description>
      <pubDate>Mon, 27 Apr 2009 13:27:34 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/user-login/m-p/5171576#M458164</guid>
      <dc:creator>G V R Shankar</dc:creator>
      <dc:date>2009-04-27T13:27:34Z</dc:date>
    </item>
    <item>
      <title>Re: User Login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/user-login/m-p/5171577#M458165</link>
      <description>"Using sudo is the last thing in my mind. Is there any way to accomplish my requirement."&lt;BR /&gt;&lt;BR /&gt;ok, locking the account means you can't "su -" as a normal user, as the password has to work.&lt;BR /&gt;&lt;BR /&gt;changing shell to "false" won't work as you need a shell.&lt;BR /&gt;&lt;BR /&gt;however, sudo will let "normal" users "su -" to the locked account using *their* password, because they'd be running the "su" as root.&lt;BR /&gt;&lt;BR /&gt;Maybe sudo need to move up on your list?&lt;BR /&gt;</description>
      <pubDate>Mon, 27 Apr 2009 13:38:58 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/user-login/m-p/5171577#M458165</guid>
      <dc:creator>OldSchool</dc:creator>
      <dc:date>2009-04-27T13:38:58Z</dc:date>
    </item>
    <item>
      <title>Re: User Login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/user-login/m-p/5171578#M458166</link>
      <description>You could do one of the following:&lt;BR /&gt;&lt;BR /&gt;- in the apps_account users .profile, create a script check to see if the account was logged into directly or by su (who am i).  The script would exit if logged into directly.  I've done something like this in Solaris.&lt;BR /&gt;&lt;BR /&gt;- Another method would be to deny the user access to each application.  See the 'DenyUsers' directive for ssh and ftpusers for ftp.  I'm sure most apps can be configured to deny a specific user.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 27 Apr 2009 15:00:20 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/user-login/m-p/5171578#M458166</guid>
      <dc:creator>Autocross.US</dc:creator>
      <dc:date>2009-04-27T15:00:20Z</dc:date>
    </item>
    <item>
      <title>Re: User Login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/user-login/m-p/5171579#M458167</link>
      <description>Implimented the solution provided by Autocross.US.&lt;BR /&gt;&lt;BR /&gt;Thank You.</description>
      <pubDate>Wed, 29 Apr 2009 15:18:15 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/user-login/m-p/5171579#M458167</guid>
      <dc:creator>G V R Shankar</dc:creator>
      <dc:date>2009-04-29T15:18:15Z</dc:date>
    </item>
  </channel>
</rss>

