<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Restrict su command for particular user in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/restrict-su-command-for-particular-user/m-p/5915375#M482771</link>
    <description>&lt;P&gt;&amp;gt;I want to restrict the su command&amp;nbsp; for list of users.&amp;nbsp; We are using su command in scripts&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can change your scripts check for those users before you do the su command.&lt;/P&gt;&lt;P&gt;(Of course the user could copy the script and remove those checks.)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 27 Dec 2012 12:05:28 GMT</pubDate>
    <dc:creator>Dennis Handly</dc:creator>
    <dc:date>2012-12-27T12:05:28Z</dc:date>
    <item>
      <title>Restrict su command for particular user</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/restrict-su-command-for-particular-user/m-p/5915349#M482768</link>
      <description>&lt;P&gt;Hi experts&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In HP-UX is it possible to restrict su command for specific user?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For eg .users .profile file i set alias name for su&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;alias su='hostname'&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Other Than any options available...? please suggest&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in Aadvance.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Dec 2012 11:36:44 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/restrict-su-command-for-particular-user/m-p/5915349#M482768</guid>
      <dc:creator>Ajin_1</dc:creator>
      <dc:date>2012-12-27T11:36:44Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict su command for particular user</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/restrict-su-command-for-particular-user/m-p/5915355#M482769</link>
      <description>&lt;P&gt;Why do you care?&amp;nbsp; He has to know the password.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Otherwise you would have to make a SUID script to check for that user, then invoke the real su.&lt;/P&gt;&lt;P&gt;And the real su would have to have its permissions changed to only allow root to execute it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(Hmm, unfortunately, then that changed su would never ask for passwords.&amp;nbsp; )-:&lt;/P&gt;</description>
      <pubDate>Thu, 27 Dec 2012 11:42:47 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/restrict-su-command-for-particular-user/m-p/5915355#M482769</guid>
      <dc:creator>Dennis Handly</dc:creator>
      <dc:date>2012-12-27T11:42:47Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict su command for particular user</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/restrict-su-command-for-particular-user/m-p/5915363#M482770</link>
      <description>&lt;P&gt;Hi Dennis&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My requirement is i want to restrict the su command&amp;nbsp; for list of users .&lt;/P&gt;&lt;P&gt;We are using su command in scripts ,so&lt;/P&gt;</description>
      <pubDate>Thu, 27 Dec 2012 11:54:20 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/restrict-su-command-for-particular-user/m-p/5915363#M482770</guid>
      <dc:creator>Ajin_1</dc:creator>
      <dc:date>2012-12-27T11:54:20Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict su command for particular user</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/restrict-su-command-for-particular-user/m-p/5915375#M482771</link>
      <description>&lt;P&gt;&amp;gt;I want to restrict the su command&amp;nbsp; for list of users.&amp;nbsp; We are using su command in scripts&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can change your scripts check for those users before you do the su command.&lt;/P&gt;&lt;P&gt;(Of course the user could copy the script and remove those checks.)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Dec 2012 12:05:28 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/restrict-su-command-for-particular-user/m-p/5915375#M482771</guid>
      <dc:creator>Dennis Handly</dc:creator>
      <dc:date>2012-12-27T12:05:28Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict su command for particular user</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/restrict-su-command-for-particular-user/m-p/5915449#M482772</link>
      <description>&lt;P&gt;There are no built-in security features for the su command. If the user knows the password to the user they are trying to become, then they can use it.&amp;nbsp; Many shops where security is an issue remove the su command and make users and scripts use either sudo or RBAC.&amp;nbsp; The sudo utilities have been around for a long time and are more common. However, they are open source and not directly supported by HP.&amp;nbsp; I would suggest using the HP-UX RBAC packages built into 11.31 and available for 11.23. They let you get very granular in granting privileges and give you logs. They are no harder to structure than sudo and I think they work better, once you get past the learning curve.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Dec 2012 13:54:17 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/restrict-su-command-for-particular-user/m-p/5915449#M482772</guid>
      <dc:creator>Ken Grabowski</dc:creator>
      <dc:date>2012-12-27T13:54:17Z</dc:date>
    </item>
  </channel>
</rss>

