<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Direct Root Login in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/direct-root-login/m-p/5226519#M467780</link>
    <description>Do you have the file:&lt;BR /&gt;&lt;BR /&gt;/etc/securetty&lt;BR /&gt;&lt;BR /&gt;Which is his content?&lt;BR /&gt;&lt;BR /&gt;cat /etc/securetty&lt;BR /&gt;&lt;BR /&gt;Horia.</description>
    <pubDate>Tue, 23 Feb 2010 14:43:31 GMT</pubDate>
    <dc:creator>Horia Chirculescu</dc:creator>
    <dc:date>2010-02-23T14:43:31Z</dc:date>
    <item>
      <title>Direct Root Login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/direct-root-login/m-p/5226502#M467763</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Please tell me the steps to enable direct root login access in HP Unix 11i v3.&lt;BR /&gt;&lt;BR /&gt;I have made the parameter PermitRootLogin yes in /etc/opt/ssh/sshd_config file.&lt;BR /&gt;&lt;BR /&gt;Have restarted the sshd also.. But still am unable to login directly with root.&lt;BR /&gt;&lt;BR /&gt;Could you please help me.&lt;BR /&gt;&lt;BR /&gt;Many Thanks!&lt;BR /&gt;Pauline</description>
      <pubDate>Tue, 23 Feb 2010 13:06:19 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/direct-root-login/m-p/5226502#M467763</guid>
      <dc:creator>Pauline Patricia</dc:creator>
      <dc:date>2010-02-23T13:06:19Z</dc:date>
    </item>
    <item>
      <title>Re: Direct Root Login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/direct-root-login/m-p/5226503#M467764</link>
      <description>see your /etc/securetty file . if this file exists do followuing steps&lt;BR /&gt;&lt;BR /&gt;cat /etc/securetty &lt;BR /&gt;&lt;BR /&gt;and see if thrd "console" is there in the file . if yes than comment out that console but this is not recommended due to security reasons because root can only login from the console. os the best practice is &lt;BR /&gt;&lt;BR /&gt;login as a simple user and do su to root.</description>
      <pubDate>Tue, 23 Feb 2010 13:12:02 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/direct-root-login/m-p/5226503#M467764</guid>
      <dc:creator>Jupinder Bedi</dc:creator>
      <dc:date>2010-02-23T13:12:02Z</dc:date>
    </item>
    <item>
      <title>Re: Direct Root Login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/direct-root-login/m-p/5226504#M467765</link>
      <description>Hi &lt;BR /&gt;&lt;BR /&gt;Kindly send the o/p of ps -ef |grep -i ssh command.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 23 Feb 2010 13:12:05 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/direct-root-login/m-p/5226504#M467765</guid>
      <dc:creator>Sachin Kumbla</dc:creator>
      <dc:date>2010-02-23T13:12:05Z</dc:date>
    </item>
    <item>
      <title>Re: Direct Root Login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/direct-root-login/m-p/5226505#M467766</link>
      <description>Hello, Patricia&lt;BR /&gt;&lt;BR /&gt;You should check your log files in order to find more informations about this issue.&lt;BR /&gt;&lt;BR /&gt;Check /var/adm/syslog/syslog.conf)&lt;BR /&gt;&lt;BR /&gt;Horia.</description>
      <pubDate>Tue, 23 Feb 2010 13:13:29 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/direct-root-login/m-p/5226505#M467766</guid>
      <dc:creator>Horia Chirculescu</dc:creator>
      <dc:date>2010-02-23T13:13:29Z</dc:date>
    </item>
    <item>
      <title>Re: Direct Root Login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/direct-root-login/m-p/5226506#M467767</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;/etc/securetty file is not available in my server.&lt;BR /&gt;&lt;BR /&gt;Here is the o/p of ps -ef |grep sshd&lt;BR /&gt;&lt;BR /&gt;wfapp:root-/&amp;gt;ps -ef |grep sshd&lt;BR /&gt;    root  8623     1  0  Feb 22  ?         0:00 sshd: dr199476 [priv]&lt;BR /&gt;dr199480 14567 14565  0 18:43:25 ?         0:00 sshd: dr199480@pts/6&lt;BR /&gt;    root 14565  8876  0 18:43:20 ?         0:00 sshd: dr199480 [priv]&lt;BR /&gt;    root  8876     1  0  Feb 22  ?         0:00 /opt/ssh/sbin/sshd&lt;BR /&gt;    root 14609 14581  0 18:44:16 pts/6     0:00 grep sshd&lt;BR /&gt;dr199476  8625  8623  0  Feb 22  ?         0:00 sshd: dr199476@pts/5&lt;BR /&gt;wfapp:root-/&amp;gt;</description>
      <pubDate>Tue, 23 Feb 2010 13:16:14 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/direct-root-login/m-p/5226506#M467767</guid>
      <dc:creator>Pauline Patricia</dc:creator>
      <dc:date>2010-02-23T13:16:14Z</dc:date>
    </item>
    <item>
      <title>Re: Direct Root Login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/direct-root-login/m-p/5226507#M467768</link>
      <description>Hi&lt;BR /&gt;&lt;BR /&gt;you need to change the parameter &lt;BR /&gt;&lt;BR /&gt;PermitRootLogin yes in the following file&lt;BR /&gt;&lt;BR /&gt;/opt/ssh/etc/sshd_config.&lt;BR /&gt;&lt;BR /&gt;&amp;amp; then restart the daemon.&lt;BR /&gt;&lt;BR /&gt;Rgds.,&lt;BR /&gt;Sachin Kumbla</description>
      <pubDate>Tue, 23 Feb 2010 13:18:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/direct-root-login/m-p/5226507#M467768</guid>
      <dc:creator>Sachin Kumbla</dc:creator>
      <dc:date>2010-02-23T13:18:41Z</dc:date>
    </item>
    <item>
      <title>Re: Direct Root Login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/direct-root-login/m-p/5226508#M467769</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;As I mentioned earlier I have done changes in sshd_config file as well restarted the sshd daemon.&lt;BR /&gt;&lt;BR /&gt;Dear Horia,&lt;BR /&gt;&lt;BR /&gt;I could not find any file syslog.conf under /var/adm/syslog/ directory.&lt;BR /&gt;&lt;BR /&gt;This server is hardened with Bastille Hardening Tool.</description>
      <pubDate>Tue, 23 Feb 2010 13:22:03 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/direct-root-login/m-p/5226508#M467769</guid>
      <dc:creator>Pauline Patricia</dc:creator>
      <dc:date>2010-02-23T13:22:03Z</dc:date>
    </item>
    <item>
      <title>Re: Direct Root Login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/direct-root-login/m-p/5226509#M467770</link>
      <description>&amp;gt;I could not find any file syslog.conf under /var/adm/syslog/ directory.&lt;BR /&gt;&lt;BR /&gt;Check /etc/syslog.conf in order to find out where the syslogd daemon writes the logs.&lt;BR /&gt;&lt;BR /&gt;Horia.</description>
      <pubDate>Tue, 23 Feb 2010 13:25:16 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/direct-root-login/m-p/5226509#M467770</guid>
      <dc:creator>Horia Chirculescu</dc:creator>
      <dc:date>2010-02-23T13:25:16Z</dc:date>
    </item>
    <item>
      <title>Re: Direct Root Login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/direct-root-login/m-p/5226510#M467771</link>
      <description>&amp;gt;This server is hardened with Bastille Hardening Tool.&lt;BR /&gt;&lt;BR /&gt;Bastille does not have any customization to disallow root logins from remote? You should check this.&lt;BR /&gt;&lt;BR /&gt;Horia.</description>
      <pubDate>Tue, 23 Feb 2010 13:27:27 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/direct-root-login/m-p/5226510#M467771</guid>
      <dc:creator>Horia Chirculescu</dc:creator>
      <dc:date>2010-02-23T13:27:27Z</dc:date>
    </item>
    <item>
      <title>Re: Direct Root Login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/direct-root-login/m-p/5226511#M467772</link>
      <description>Please Check "below" from my server sshd_config&lt;BR /&gt;try placing # in all Permit from ssh config file.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;# grep -i Permit /opt/ssh/etc/sshd_config&lt;BR /&gt;#PermitRootLogin forced-commands-only&lt;BR /&gt;#PermitEmptyPasswords no&lt;BR /&gt;# PasswordAuthentication, PermitEmptyPasswords, and&lt;BR /&gt;# "PermitRootLogin without-password". If you just want the PAM account and&lt;BR /&gt;#PermitUserEnvironment no&lt;BR /&gt;#PermitTunnel no&lt;BR /&gt;&lt;BR /&gt;HTH,&lt;BR /&gt;Johnson</description>
      <pubDate>Tue, 23 Feb 2010 13:59:47 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/direct-root-login/m-p/5226511#M467772</guid>
      <dc:creator>Johnson Punniyalingam</dc:creator>
      <dc:date>2010-02-23T13:59:47Z</dc:date>
    </item>
    <item>
      <title>Re: Direct Root Login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/direct-root-login/m-p/5226512#M467773</link>
      <description>I could not find any parameter in bastille configuration file that is disallowing root login.&lt;BR /&gt;&lt;BR /&gt;Hoping that bastille configuration does not come into picture.&lt;BR /&gt;&lt;BR /&gt;Since this server is running HP 11i v3, is there any other changes need to be done??</description>
      <pubDate>Tue, 23 Feb 2010 14:03:57 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/direct-root-login/m-p/5226512#M467773</guid>
      <dc:creator>Pauline Patricia</dc:creator>
      <dc:date>2010-02-23T14:03:57Z</dc:date>
    </item>
    <item>
      <title>Re: Direct Root Login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/direct-root-login/m-p/5226513#M467774</link>
      <description>&amp;gt;&amp;gt; But still am unable to login directly with root.&lt;BR /&gt;&lt;BR /&gt;What happens when you attempt to login as root?  What command do you run?  What error do you get?  Commands run and actual errors received would be a very big help in trying to solve this.</description>
      <pubDate>Tue, 23 Feb 2010 14:07:36 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/direct-root-login/m-p/5226513#M467774</guid>
      <dc:creator>Patrick Wallek</dc:creator>
      <dc:date>2010-02-23T14:07:36Z</dc:date>
    </item>
    <item>
      <title>Re: Direct Root Login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/direct-root-login/m-p/5226514#M467775</link>
      <description>Pauline, please read the paragraph below. I have extracted from:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://docs.hp.com/en/B2355-90950/apbs01.html" target="_blank"&gt;http://docs.hp.com/en/B2355-90950/apbs01.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;"Q: Should Bastille disallow root logins from network tty's? [N] [N]&lt;BR /&gt;&lt;BR /&gt;Level: Account Security&lt;BR /&gt;&lt;BR /&gt;Bastille can restrict root from logging into a tty over the network. &lt;BR /&gt;This will force administrators to log in first as a non-root user, then&lt;BR /&gt;su to become root.  Root logins will still be permitted on the console and&lt;BR /&gt;through services that do not use tty's ( e.g. HP-UX Secure Shell ).&lt;BR /&gt; &lt;BR /&gt;This can stop an attacker who has only been able to steal the root password&lt;BR /&gt;from logging in directly to a tty.  The attacker has to steal a second account's&lt;BR /&gt;password to make use of the root password via the network, or gain access to a&lt;BR /&gt;non-tty login mechanism.&lt;BR /&gt; &lt;BR /&gt;MAKE SURE that you can login using a non-root account before you do this,&lt;BR /&gt;or you will obviously need access to the console or a non-tty remote login&lt;BR /&gt;mechanism, e.g. Secure Shell, to login."&lt;BR /&gt;&lt;BR /&gt;Horia.</description>
      <pubDate>Tue, 23 Feb 2010 14:11:12 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/direct-root-login/m-p/5226514#M467775</guid>
      <dc:creator>Horia Chirculescu</dc:creator>
      <dc:date>2010-02-23T14:11:12Z</dc:date>
    </item>
    <item>
      <title>Re: Direct Root Login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/direct-root-login/m-p/5226515#M467776</link>
      <description>Dear Patrick,&lt;BR /&gt;&lt;BR /&gt;Am just trying to login to my server via ssh through putty with root login.&lt;BR /&gt;&lt;BR /&gt;Its just giving "Access Denied".&lt;BR /&gt;&lt;BR /&gt;Dear Horiam&lt;BR /&gt;&lt;BR /&gt;I checked this parameter in bastille configuration file.&lt;BR /&gt;&lt;BR /&gt;# Q:  Should Bastille disallow root logins from network TTYs? [N]&lt;BR /&gt;AccountSecurity.create_securetty="N"&lt;BR /&gt;&lt;BR /&gt;Its not enabled..</description>
      <pubDate>Tue, 23 Feb 2010 14:17:27 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/direct-root-login/m-p/5226515#M467776</guid>
      <dc:creator>Pauline Patricia</dc:creator>
      <dc:date>2010-02-23T14:17:27Z</dc:date>
    </item>
    <item>
      <title>Re: Direct Root Login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/direct-root-login/m-p/5226516#M467777</link>
      <description>There i sone way to actually clarify this for good:&lt;BR /&gt;&lt;BR /&gt;Just enable telnet (if not allready enabled) on the server and try to actually telnet into this server from a remote location.&lt;BR /&gt;&lt;BR /&gt;Also, you should try to find out if &lt;BR /&gt;&lt;BR /&gt;ssh localhost &lt;BR /&gt;&lt;BR /&gt;is working on the server (in order to find out if you have a global issue or only a network related problem).&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Horia.</description>
      <pubDate>Tue, 23 Feb 2010 14:24:49 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/direct-root-login/m-p/5226516#M467777</guid>
      <dc:creator>Horia Chirculescu</dc:creator>
      <dc:date>2010-02-23T14:24:49Z</dc:date>
    </item>
    <item>
      <title>Re: Direct Root Login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/direct-root-login/m-p/5226517#M467778</link>
      <description>I enabled telnet. Tried to login with root via telnet ..but giving access denied.&lt;BR /&gt;&lt;BR /&gt;I tried to ssh localhost...Prompted for root password.. after giving the password it says "Permission denied, please try again.&lt;BR /&gt;"</description>
      <pubDate>Tue, 23 Feb 2010 14:35:31 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/direct-root-login/m-p/5226517#M467778</guid>
      <dc:creator>Pauline Patricia</dc:creator>
      <dc:date>2010-02-23T14:35:31Z</dc:date>
    </item>
    <item>
      <title>Re: Direct Root Login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/direct-root-login/m-p/5226518#M467779</link>
      <description>If you can login as a non-root user, then your problem is with security settings. Maybe Bastille is not working as expected or you have missed some settings. &lt;BR /&gt;&lt;BR /&gt;Horia.&lt;BR /&gt;</description>
      <pubDate>Tue, 23 Feb 2010 14:39:36 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/direct-root-login/m-p/5226518#M467779</guid>
      <dc:creator>Horia Chirculescu</dc:creator>
      <dc:date>2010-02-23T14:39:36Z</dc:date>
    </item>
    <item>
      <title>Re: Direct Root Login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/direct-root-login/m-p/5226519#M467780</link>
      <description>Do you have the file:&lt;BR /&gt;&lt;BR /&gt;/etc/securetty&lt;BR /&gt;&lt;BR /&gt;Which is his content?&lt;BR /&gt;&lt;BR /&gt;cat /etc/securetty&lt;BR /&gt;&lt;BR /&gt;Horia.</description>
      <pubDate>Tue, 23 Feb 2010 14:43:31 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/direct-root-login/m-p/5226519#M467780</guid>
      <dc:creator>Horia Chirculescu</dc:creator>
      <dc:date>2010-02-23T14:43:31Z</dc:date>
    </item>
    <item>
      <title>Re: Direct Root Login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/direct-root-login/m-p/5226520#M467781</link>
      <description>No.. /etc/securetty is not available..</description>
      <pubDate>Tue, 23 Feb 2010 14:45:06 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/direct-root-login/m-p/5226520#M467781</guid>
      <dc:creator>Pauline Patricia</dc:creator>
      <dc:date>2010-02-23T14:45:06Z</dc:date>
    </item>
    <item>
      <title>Re: Direct Root Login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/direct-root-login/m-p/5226521#M467782</link>
      <description>Hi,&lt;BR /&gt;    login to the console and check #ssh 0 or #telnet 0. if it is not working then revert back the bastille and try it...&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;Shanmugam.B</description>
      <pubDate>Thu, 25 Feb 2010 12:16:00 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/direct-root-login/m-p/5226521#M467782</guid>
      <dc:creator>shanmuhanandam</dc:creator>
      <dc:date>2010-02-25T12:16:00Z</dc:date>
    </item>
  </channel>
</rss>

