<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Disabling trusted mode - impact? in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/disabling-trusted-mode-impact/m-p/5978897#M604259</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are planning for a centralized authentication for our HP-UX and Linux servers through LDAP using the OID (Oracle Internet Directory) integrated with our Microsoft Active Directory.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To enable this we need to convert our systems to untrusted mode as in trusted mode long usernames are not supported.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;We are planning to centralize only the system/DB administrators and operators user-ids and the service accounts used for application installation will remail locally in the individual server.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Want to know if there will be any impact on the applications like Oracle Databases, Oracle Ebusiness suite, Oracle Apps servers etc. installed on these servers?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What will be the overall impact in converting a server from trusted mode to untrusted mode on a production environment?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Srividhya&lt;/P&gt;</description>
    <pubDate>Thu, 28 Feb 2013 09:34:57 GMT</pubDate>
    <dc:creator>PM Srividhya</dc:creator>
    <dc:date>2013-02-28T09:34:57Z</dc:date>
    <item>
      <title>Disabling trusted mode - impact?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/disabling-trusted-mode-impact/m-p/5978897#M604259</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are planning for a centralized authentication for our HP-UX and Linux servers through LDAP using the OID (Oracle Internet Directory) integrated with our Microsoft Active Directory.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To enable this we need to convert our systems to untrusted mode as in trusted mode long usernames are not supported.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;We are planning to centralize only the system/DB administrators and operators user-ids and the service accounts used for application installation will remail locally in the individual server.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Want to know if there will be any impact on the applications like Oracle Databases, Oracle Ebusiness suite, Oracle Apps servers etc. installed on these servers?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What will be the overall impact in converting a server from trusted mode to untrusted mode on a production environment?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Srividhya&lt;/P&gt;</description>
      <pubDate>Thu, 28 Feb 2013 09:34:57 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/disabling-trusted-mode-impact/m-p/5978897#M604259</guid>
      <dc:creator>PM Srividhya</dc:creator>
      <dc:date>2013-02-28T09:34:57Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling trusted mode - impact?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/disabling-trusted-mode-impact/m-p/5979847#M604260</link>
      <description>&lt;P&gt;The biggest negative to disabling trusted mode is that your hashed passwords will now be visible in the /etc/passwd file for those accounts you are keeping local. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since /etc/passwd must be readable by everyone that is a very bad idea. &amp;nbsp;Someone could potentially grab the passwd file, take it home, and start running programs like John The Ripper or Crack or other things to try to discover passwords.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Feb 2013 21:28:46 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/disabling-trusted-mode-impact/m-p/5979847#M604260</guid>
      <dc:creator>Patrick Wallek</dc:creator>
      <dc:date>2013-02-28T21:28:46Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling trusted mode - impact?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/disabling-trusted-mode-impact/m-p/5980381#M604261</link>
      <description>&lt;P&gt;How about switching to shadow password mode? That would fix the weakness of having the local password hashes visible in /etc/passwd.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As far as I know, most Oracle products you mentioned would tend to have their own built-in authentication systems, instead of relying on system passwords. So the impact to applications from the trusted -&amp;gt; non-trusted (-&amp;gt; shadow?) transition should be minimal or non-existent.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just remember that a transition from trusted to non-trusted mode will truncate the stored password hashes so that only the first 8 characters of the stored passwords are retained. So if the user has more than 8 characters in his/her password, there might be some issues. (Usually the non-trusted mode will simply ignore any characters after the 8th when checking a password, but there might be some special snowflake software that insists on exact match. )&lt;/P&gt;</description>
      <pubDate>Fri, 01 Mar 2013 09:52:13 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/disabling-trusted-mode-impact/m-p/5980381#M604261</guid>
      <dc:creator>Matti_Kurkela</dc:creator>
      <dc:date>2013-03-01T09:52:13Z</dc:date>
    </item>
  </channel>
</rss>

