<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Block user accounts in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/block-user-accounts/m-p/5324675#M475650</link>
    <description>&lt;P&gt;Describing your system as 11i leaves a range of options - like 11.11, 11.23, 11.31, and more.&amp;nbsp; I would suggest you look at man (4) security, particularly the inactivity_maxdays parameter.&amp;nbsp; In 11.11, at least, this parameter only applies to non-trusted systems.&amp;nbsp; If you have a more current release then your mileage may vary.&lt;/P&gt;</description>
    <pubDate>Wed, 07 Sep 2011 16:03:56 GMT</pubDate>
    <dc:creator>Pete Randall</dc:creator>
    <dc:date>2011-09-07T16:03:56Z</dc:date>
    <item>
      <title>Block user accounts</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/block-user-accounts/m-p/5324627#M475649</link>
      <description>&lt;P&gt;I need one urgent information. How to block user accounts who has not logged in to the server last 6 months in HP-UX 11i (on both Trusted and non-Trusted) system. I don't want to execute command manually (like passwd -l username). Please advise ...&lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2011 14:50:45 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/block-user-accounts/m-p/5324627#M475649</guid>
      <dc:creator>Arunabha Banerjee</dc:creator>
      <dc:date>2011-09-07T14:50:45Z</dc:date>
    </item>
    <item>
      <title>Re: Block user accounts</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/block-user-accounts/m-p/5324675#M475650</link>
      <description>&lt;P&gt;Describing your system as 11i leaves a range of options - like 11.11, 11.23, 11.31, and more.&amp;nbsp; I would suggest you look at man (4) security, particularly the inactivity_maxdays parameter.&amp;nbsp; In 11.11, at least, this parameter only applies to non-trusted systems.&amp;nbsp; If you have a more current release then your mileage may vary.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2011 16:03:56 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/block-user-accounts/m-p/5324675#M475650</guid>
      <dc:creator>Pete Randall</dc:creator>
      <dc:date>2011-09-07T16:03:56Z</dc:date>
    </item>
    <item>
      <title>Re: Block user accounts</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/block-user-accounts/m-p/5324685#M475652</link>
      <description>&lt;P&gt;Oops!&amp;nbsp; Glad I double checked.&amp;nbsp; The man page I looked at was for 11.31.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the case of trusted systems, I would suggest that you take note of the fact that trusted systems are deprecated as of 11.31 and you should probably be looking into the shadow password feature instead.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2011 16:08:27 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/block-user-accounts/m-p/5324685#M475652</guid>
      <dc:creator>Pete Randall</dc:creator>
      <dc:date>2011-09-07T16:08:27Z</dc:date>
    </item>
    <item>
      <title>Re: Block user accounts</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/block-user-accounts/m-p/5324707#M475653</link>
      <description>&lt;P&gt;Hi:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Pete's comments (including the deprecation of Trusted Systems) are the same ones I would make.&amp;nbsp; I too would establish (at least where you can), the 'INACTIVITY_MAXDAYS﻿' in '/etc/default/security'.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In order to "clean up" users without recent activity, consider running 'last' and parsing out a list of users who haven't logged in or are absent from the underlying '/var/adm/wtmp' file which would mean that they have never logged in during the file's coverage period.&amp;nbsp; You might find that converting '/var/adm/wtmp' to its ASCII counterpart, which exposes Epoch dates, more useful:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;# /usr/sbin/acct/fwtmp &amp;lt; /var/adm/wtmp &amp;gt; /tmp/wtmp ﻿&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once you enumerate the users who haven't looged-in recently, a simple script to lock those accounts should be something any sysadmin could write.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;...JRF...&lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2011 16:21:08 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/block-user-accounts/m-p/5324707#M475653</guid>
      <dc:creator>James R. Ferguson</dc:creator>
      <dc:date>2011-09-07T16:21:08Z</dc:date>
    </item>
  </channel>
</rss>

