<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Politics user problem in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/politics-user-problem/m-p/5214468#M465563</link>
    <description>Hi&lt;BR /&gt;&lt;BR /&gt;I would also use same for all user administration.  Its much faster and reliable and you've got other more important things to do than waste an hour figureing out usermod arguements..</description>
    <pubDate>Tue, 15 Dec 2009 16:32:11 GMT</pubDate>
    <dc:creator>Michael Steele_2</dc:creator>
    <dc:date>2009-12-15T16:32:11Z</dc:date>
    <item>
      <title>Politics user problem</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/politics-user-problem/m-p/5214466#M465561</link>
      <description>I have a problem with a policy server.&lt;BR /&gt;&lt;BR /&gt;User policy exists that the user's password expires every 3 months&lt;BR /&gt;I need to exclude a patron of that policy&lt;BR /&gt;Where can I find the documentation, the steps to perform this task</description>
      <pubDate>Tue, 15 Dec 2009 16:21:10 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/politics-user-problem/m-p/5214466#M465561</guid>
      <dc:creator>Eli Daniel</dc:creator>
      <dc:date>2009-12-15T16:21:10Z</dc:date>
    </item>
    <item>
      <title>Re: Politics user problem</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/politics-user-problem/m-p/5214467#M465562</link>
      <description>You got to love the "the policy applies to everyone except me" types.&lt;BR /&gt;&lt;BR /&gt;This can be set through SAM by selecting the user and modifying the security policies for that user.&lt;BR /&gt;&lt;BR /&gt;This could also be done from the command line with the modprpw command.&lt;BR /&gt;&lt;BR /&gt;/usr/lbin/modprpw -m exptime=180 user-id&lt;BR /&gt;&lt;BR /&gt;Where the number after exptime is the number of days before the password expires.&lt;BR /&gt;&lt;BR /&gt;See the modprpw man page for more information.</description>
      <pubDate>Tue, 15 Dec 2009 16:29:09 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/politics-user-problem/m-p/5214467#M465562</guid>
      <dc:creator>Patrick Wallek</dc:creator>
      <dc:date>2009-12-15T16:29:09Z</dc:date>
    </item>
    <item>
      <title>Re: Politics user problem</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/politics-user-problem/m-p/5214468#M465563</link>
      <description>Hi&lt;BR /&gt;&lt;BR /&gt;I would also use same for all user administration.  Its much faster and reliable and you've got other more important things to do than waste an hour figureing out usermod arguements..</description>
      <pubDate>Tue, 15 Dec 2009 16:32:11 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/politics-user-problem/m-p/5214468#M465563</guid>
      <dc:creator>Michael Steele_2</dc:creator>
      <dc:date>2009-12-15T16:32:11Z</dc:date>
    </item>
    <item>
      <title>Re: Politics user problem</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/politics-user-problem/m-p/5214469#M465564</link>
      <description>Oops.  Typo.  Should read..."I would also use SAM..."</description>
      <pubDate>Tue, 15 Dec 2009 16:32:45 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/politics-user-problem/m-p/5214469#M465564</guid>
      <dc:creator>Michael Steele_2</dc:creator>
      <dc:date>2009-12-15T16:32:45Z</dc:date>
    </item>
    <item>
      <title>Re: Politics user problem</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/politics-user-problem/m-p/5214470#M465565</link>
      <description>Shalom,&lt;BR /&gt;&lt;BR /&gt;sam and its successor smh have an interface that lets you mark a user password never to expire.&lt;BR /&gt;&lt;BR /&gt;There is a similar option on Windows domain controllers, and LDAP systems released by Red Hat.&lt;BR /&gt;&lt;BR /&gt;This is however an exception to security guidelines and can cause you to fail a security audit.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Tue, 15 Dec 2009 16:45:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/politics-user-problem/m-p/5214470#M465565</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2009-12-15T16:45:41Z</dc:date>
    </item>
    <item>
      <title>Re: Politics user problem</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/politics-user-problem/m-p/5214471#M465566</link>
      <description>&lt;!--!*#--&gt;&amp;gt; This is however an exception to security&lt;BR /&gt;&amp;gt; guidelines and can cause you to fail a&lt;BR /&gt;&amp;gt; security audit.&lt;BR /&gt;&lt;BR /&gt;Of course, if the principal outcome of&lt;BR /&gt;requiring users to change passwords&lt;BR /&gt;frequently is users posting their passwords&lt;BR /&gt;in their work areas using sticky notes, then&lt;BR /&gt;creating an exception for every user may&lt;BR /&gt;provide better security, auditors (and policy&lt;BR /&gt;makers) notwithstanding.</description>
      <pubDate>Tue, 15 Dec 2009 17:41:36 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/politics-user-problem/m-p/5214471#M465566</guid>
      <dc:creator>Steven Schweda</dc:creator>
      <dc:date>2009-12-15T17:41:36Z</dc:date>
    </item>
    <item>
      <title>Re: Politics user problem</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/politics-user-problem/m-p/5214472#M465567</link>
      <description>Personally, I think if a user can not remember a password and needs to use a postit note, thats a problem.&lt;BR /&gt;&lt;BR /&gt;Data security is a serious issue in Corporate America and all over the globe.&lt;BR /&gt;&lt;BR /&gt;Users should be able to use words in combination with numbers to create something memorable. If so, there should be no reason to write them down.&lt;BR /&gt;&lt;BR /&gt;The exception two jobs ago was the organization president. I've dealt with these issues. Passwords are important enough that some time should be spent to remember them.&lt;BR /&gt;&lt;BR /&gt;Everybody should have to change them periodically.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Tue, 15 Dec 2009 20:22:36 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/politics-user-problem/m-p/5214472#M465567</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2009-12-15T20:22:36Z</dc:date>
    </item>
    <item>
      <title>Re: Politics user problem</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/politics-user-problem/m-p/5214473#M465568</link>
      <description>really is an application service, the service sends information through a user, but there is a policy that every 3 months, users have to change the password.&lt;BR /&gt;The recommended option is to go to sam and deselect "password aging policies"</description>
      <pubDate>Tue, 15 Dec 2009 20:51:13 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/politics-user-problem/m-p/5214473#M465568</guid>
      <dc:creator>Eli Daniel</dc:creator>
      <dc:date>2009-12-15T20:51:13Z</dc:date>
    </item>
    <item>
      <title>Re: Politics user problem</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/politics-user-problem/m-p/5214474#M465569</link>
      <description>Hi&lt;BR /&gt;&lt;BR /&gt;What application please.  PowerBroker?</description>
      <pubDate>Tue, 15 Dec 2009 23:14:55 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/politics-user-problem/m-p/5214474#M465569</guid>
      <dc:creator>Michael Steele_2</dc:creator>
      <dc:date>2009-12-15T23:14:55Z</dc:date>
    </item>
    <item>
      <title>Re: Politics user problem</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/politics-user-problem/m-p/5214475#M465570</link>
      <description>Looks like you have the "workaround", but I'm compelled to emphasize what others have written.&lt;BR /&gt;&lt;BR /&gt;No user account should be have password expiration of less than 90 days. We have a wide variety of users.  Most log in daily, while others log in anywhere from weekly to annually.  Our policy is the same for all.  &lt;BR /&gt;&lt;BR /&gt;After 90 days of no activity, the account is locked.  After an additional 30 days, the account is deleted.  After this, a new user account must be requested.&lt;BR /&gt;&lt;BR /&gt;NOTE:  This is explained to every user and supported by mgmt.  So, the users that don't log in after 120+ days know they must re-apply.  Normally, they get the same login.&lt;BR /&gt;&lt;BR /&gt;Application accounts are either locked or the password is maintained by sys admin staff.  For those, we change the password every 90 days regardless if used or not.&lt;BR /&gt;&lt;BR /&gt;Users that actually need access to an application account are provided sudo access.  For example, all sys admin's use sudo for root commands and dba's for oracle commands.&lt;BR /&gt;&lt;BR /&gt;Critical logins, including sys admins, root, oracle accounts are monitored for changes.&lt;BR /&gt;&lt;BR /&gt;Of course, we have an exception request for those very, very rare occasions.  We don't want to prevent anyone from doing there job, but any exceptions must be documented, validated, and approved by upper mgmt.&lt;BR /&gt;&lt;BR /&gt;Hope this helps...&lt;BR /&gt;:-)&lt;BR /&gt;</description>
      <pubDate>Wed, 16 Dec 2009 03:49:03 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/politics-user-problem/m-p/5214475#M465570</guid>
      <dc:creator>John Donovan</dc:creator>
      <dc:date>2009-12-16T03:49:03Z</dc:date>
    </item>
    <item>
      <title>Re: Politics user problem</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/politics-user-problem/m-p/5214476#M465571</link>
      <description>&lt;!--!*#--&gt;&amp;gt; Users should be able to use words in&lt;BR /&gt;&amp;gt; combination with numbers to create&lt;BR /&gt;&amp;gt; something memorable.&lt;BR /&gt;&lt;BR /&gt;I agree.  However, few people these days have&lt;BR /&gt;only one password to remember, and&lt;BR /&gt;remembering many good passwords may be more&lt;BR /&gt;difficult than remembering one.  Every&lt;BR /&gt;organization gets to set its own policy, but&lt;BR /&gt;choosing an optimal password lifetime is, I&lt;BR /&gt;claim, not a trivial problem.&lt;BR /&gt;&lt;BR /&gt;Everything's complicated.</description>
      <pubDate>Wed, 16 Dec 2009 06:32:00 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/politics-user-problem/m-p/5214476#M465571</guid>
      <dc:creator>Steven Schweda</dc:creator>
      <dc:date>2009-12-16T06:32:00Z</dc:date>
    </item>
    <item>
      <title>Re: Politics user problem</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/politics-user-problem/m-p/5214477#M465572</link>
      <description>re users having to remember multiple passwords &amp;amp; sticky notes...&lt;BR /&gt;&lt;BR /&gt;One solution is for users to use a Password Vault Application - I use KeePass, which also has approval by my IT organisation.&lt;BR /&gt;&lt;BR /&gt;Main Advantage is that users can then apply more rigorous passwords for individual accounts, which can then be made unique - so should a password ever be compromised/discovered, then the damage limitation can be more effective (alternative scenario is that a very few passwords are used all over - which increases the risk for damage in the event of compromise/password discovery...)&lt;BR /&gt;&lt;BR /&gt;Hope it helps&lt;BR /&gt;&lt;BR /&gt;Nick 'dubya'&lt;BR /&gt;</description>
      <pubDate>Wed, 16 Dec 2009 10:44:51 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/politics-user-problem/m-p/5214477#M465572</guid>
      <dc:creator>Nick W</dc:creator>
      <dc:date>2009-12-16T10:44:51Z</dc:date>
    </item>
    <item>
      <title>Re: Politics user problem</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/politics-user-problem/m-p/5214478#M465573</link>
      <description>&lt;!--!*#--&gt;The option SAM "Modify Security Policies..." "Password Aging Policies.."&lt;BR /&gt; &lt;BR /&gt;&lt;BR /&gt;if this disable, the password never expire?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Note: view attachment&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 16 Dec 2009 13:20:45 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/politics-user-problem/m-p/5214478#M465573</guid>
      <dc:creator>Eli Daniel</dc:creator>
      <dc:date>2009-12-16T13:20:45Z</dc:date>
    </item>
    <item>
      <title>Re: Politics user problem</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/politics-user-problem/m-p/5214479#M465574</link>
      <description>Correct.</description>
      <pubDate>Wed, 16 Dec 2009 13:59:13 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/politics-user-problem/m-p/5214479#M465574</guid>
      <dc:creator>Patrick Wallek</dc:creator>
      <dc:date>2009-12-16T13:59:13Z</dc:date>
    </item>
    <item>
      <title>Re: Politics user problem</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/politics-user-problem/m-p/5214480#M465575</link>
      <description>&lt;!--!*#--&gt;patrick one last question, according to the attachment as it is the actual expiration time of this password 90 days or 180 days? I do not understand these options attachment</description>
      <pubDate>Wed, 16 Dec 2009 14:17:35 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/politics-user-problem/m-p/5214480#M465575</guid>
      <dc:creator>Eli Daniel</dc:creator>
      <dc:date>2009-12-16T14:17:35Z</dc:date>
    </item>
    <item>
      <title>Re: Politics user problem</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/politics-user-problem/m-p/5214481#M465576</link>
      <description>Hi Eli,&lt;BR /&gt;&lt;BR /&gt;    90 days refers that your password will get expired after 90 days and 180 days in your attachment says that even if you dont change your password after your password expiration time for another 90 days i.e. total of 180 days, your user account will get locked.</description>
      <pubDate>Wed, 16 Dec 2009 15:36:19 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/politics-user-problem/m-p/5214481#M465576</guid>
      <dc:creator>Vishu</dc:creator>
      <dc:date>2009-12-16T15:36:19Z</dc:date>
    </item>
    <item>
      <title>Re: Politics user problem</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/politics-user-problem/m-p/5214482#M465577</link>
      <description>So this would be a bad practice?&lt;BR /&gt;Time Between Password Changes (days): 1&lt;BR /&gt;Password Expiration Time (days): 90&lt;BR /&gt;Password Expiration Warning Time (days): 7&lt;BR /&gt;Password Life Time (days): 180&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;the best practice should be:&lt;BR /&gt;Time Between Password Changes (days): 1&lt;BR /&gt;Password Expiration Time (days): 90&lt;BR /&gt;Password Expiration Warning Time (days): 7&lt;BR /&gt;Password Life Time (days): 90&lt;BR /&gt;this is correct?&lt;BR /&gt;I need is to force the user to change their password after 90 days&lt;BR /&gt;(with the single-user exepcion)</description>
      <pubDate>Wed, 16 Dec 2009 15:46:49 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/politics-user-problem/m-p/5214482#M465577</guid>
      <dc:creator>Eli Daniel</dc:creator>
      <dc:date>2009-12-16T15:46:49Z</dc:date>
    </item>
    <item>
      <title>Re: Politics user problem</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/politics-user-problem/m-p/5214483#M465578</link>
      <description>Thanks &lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 16 Dec 2009 19:17:43 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/politics-user-problem/m-p/5214483#M465578</guid>
      <dc:creator>Eli Daniel</dc:creator>
      <dc:date>2009-12-16T19:17:43Z</dc:date>
    </item>
  </channel>
</rss>

