<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Create UNIX user with restrictions in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/create-unix-user-with-restrictions/m-p/2711842#M60811</link>
    <description>But if you are in rsh it should not let you go to any other directories and also put an exit after the xomni command so that after xomni it exits .&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Manoj Srivastava</description>
    <pubDate>Fri, 26 Apr 2002 20:16:17 GMT</pubDate>
    <dc:creator>MANOJ SRIVASTAVA</dc:creator>
    <dc:date>2002-04-26T20:16:17Z</dc:date>
    <item>
      <title>Create UNIX user with restrictions</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/create-unix-user-with-restrictions/m-p/2711819#M60788</link>
      <description>HI,&lt;BR /&gt;&lt;BR /&gt;Would like to know how to create a UNIX user, who I only want to use omniback and shouldn't be bale to remove, delete, copy or anything else apart from logon to the system.&lt;BR /&gt;&lt;BR /&gt;Regards&lt;BR /&gt;&lt;BR /&gt;Khurram</description>
      <pubDate>Fri, 26 Apr 2002 10:01:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/create-unix-user-with-restrictions/m-p/2711819#M60788</guid>
      <dc:creator>Khurram Khan_1</dc:creator>
      <dc:date>2002-04-26T10:01:41Z</dc:date>
    </item>
    <item>
      <title>Re: Create UNIX user with restrictions</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/create-unix-user-with-restrictions/m-p/2711820#M60789</link>
      <description>Hi ,&lt;BR /&gt;&lt;BR /&gt;create a user with restricted shell&lt;BR /&gt;/bin/rsh&lt;BR /&gt;&lt;BR /&gt;make a link in users home dir to Omniback start script xomni&lt;BR /&gt;&lt;BR /&gt;Hope it helps&lt;BR /&gt;Michael</description>
      <pubDate>Fri, 26 Apr 2002 10:08:19 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/create-unix-user-with-restrictions/m-p/2711820#M60789</guid>
      <dc:creator>Michael Albrecht</dc:creator>
      <dc:date>2002-04-26T10:08:19Z</dc:date>
    </item>
    <item>
      <title>Re: Create UNIX user with restrictions</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/create-unix-user-with-restrictions/m-p/2711821#M60790</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Do you mind listing the commands step by step, thanks. &lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Regards&lt;BR /&gt;&lt;BR /&gt;Khurram</description>
      <pubDate>Fri, 26 Apr 2002 10:11:27 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/create-unix-user-with-restrictions/m-p/2711821#M60790</guid>
      <dc:creator>Khurram Khan_1</dc:creator>
      <dc:date>2002-04-26T10:11:27Z</dc:date>
    </item>
    <item>
      <title>Re: Create UNIX user with restrictions</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/create-unix-user-with-restrictions/m-p/2711822#M60791</link>
      <description>Hi Khurram,&lt;BR /&gt;&lt;BR /&gt;Do you want the user to just run the xomni &lt;BR /&gt;&lt;BR /&gt;............&lt;BR /&gt;/opt/omni/bin/xomni &lt;BR /&gt;exit&lt;BR /&gt;&lt;BR /&gt;This will just invoke the xomni whenever he logins. The moment he closes the xomni, the exit will be executed and he will be logged out of the session.&lt;BR /&gt;&lt;BR /&gt;Can anybody in the forum tell me, what are the threats which I will face with this...I mean can a user go to the shell prompt in any way.&lt;BR /&gt;&lt;BR /&gt;- Sukant&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;&lt;BR /&gt;Sukant</description>
      <pubDate>Fri, 26 Apr 2002 11:23:14 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/create-unix-user-with-restrictions/m-p/2711822#M60791</guid>
      <dc:creator>Sukant Naik</dc:creator>
      <dc:date>2002-04-26T11:23:14Z</dc:date>
    </item>
    <item>
      <title>Re: Create UNIX user with restrictions</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/create-unix-user-with-restrictions/m-p/2711823#M60792</link>
      <description>Hi Khurram,&lt;BR /&gt;&lt;BR /&gt;Do you want the user to just run the xomni &lt;BR /&gt;&lt;BR /&gt;............&lt;BR /&gt;/opt/omni/bin/xomni &lt;BR /&gt;exit&lt;BR /&gt;&lt;BR /&gt;This will just invoke the xomni whenever he logins. The moment he closes the xomni, the exit will be executed and he will be logged out of the session.&lt;BR /&gt;&lt;BR /&gt;Can anybody in the forum tell me, what are the threats which I will face with this...I mean can a user go to the shell prompt in any way.&lt;BR /&gt;&lt;BR /&gt;- Sukant&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 26 Apr 2002 11:23:25 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/create-unix-user-with-restrictions/m-p/2711823#M60792</guid>
      <dc:creator>Sukant Naik</dc:creator>
      <dc:date>2002-04-26T11:23:25Z</dc:date>
    </item>
    <item>
      <title>Re: Create UNIX user with restrictions</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/create-unix-user-with-restrictions/m-p/2711824#M60793</link>
      <description>Sorry for the incomplete answer which I sent earlier.&lt;BR /&gt;&lt;BR /&gt;You need to add the entry in the .profile of that user.&lt;BR /&gt;&lt;BR /&gt;- Sukant</description>
      <pubDate>Fri, 26 Apr 2002 11:25:03 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/create-unix-user-with-restrictions/m-p/2711824#M60793</guid>
      <dc:creator>Sukant Naik</dc:creator>
      <dc:date>2002-04-26T11:25:03Z</dc:date>
    </item>
    <item>
      <title>Re: Create UNIX user with restrictions</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/create-unix-user-with-restrictions/m-p/2711825#M60794</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;The users will log into Omniback using Reflections, which means they log into unix first and then type xomni&amp;amp;. So need to make sure when they log into UNIX, they should have very restricted permissions to do anything at all apart from type in the command xomni and not be able to move, copy or delete anything.&lt;BR /&gt;&lt;BR /&gt;Regards&lt;BR /&gt;&lt;BR /&gt;Khurram</description>
      <pubDate>Fri, 26 Apr 2002 12:02:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/create-unix-user-with-restrictions/m-p/2711825#M60794</guid>
      <dc:creator>Khurram Khan_1</dc:creator>
      <dc:date>2002-04-26T12:02:41Z</dc:date>
    </item>
    <item>
      <title>Re: Create UNIX user with restrictions</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/create-unix-user-with-restrictions/m-p/2711826#M60795</link>
      <description>&lt;BR /&gt;ps -ef | grep X | grep -v grep | awk '{print $2}' | xargs kill -HUP&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 26 Apr 2002 12:05:26 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/create-unix-user-with-restrictions/m-p/2711826#M60795</guid>
      <dc:creator>hpuxrox</dc:creator>
      <dc:date>2002-04-26T12:05:26Z</dc:date>
    </item>
    <item>
      <title>Re: Create UNIX user with restrictions</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/create-unix-user-with-restrictions/m-p/2711827#M60796</link>
      <description>Please disreguard my last post. I does't apply to this forum thread.&lt;BR /&gt;&lt;BR /&gt;Thanks,</description>
      <pubDate>Fri, 26 Apr 2002 12:08:45 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/create-unix-user-with-restrictions/m-p/2711827#M60796</guid>
      <dc:creator>hpuxrox</dc:creator>
      <dc:date>2002-04-26T12:08:45Z</dc:date>
    </item>
    <item>
      <title>Re: Create UNIX user with restrictions</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/create-unix-user-with-restrictions/m-p/2711828#M60797</link>
      <description>Hi Khurram, &lt;BR /&gt;&lt;BR /&gt;I'm not sure about Reflection but with Exceed you can create a session that only starts a single specific X application.  You may want to look into whether or not Reflection has this type of capability.&lt;BR /&gt;&lt;BR /&gt;Tony</description>
      <pubDate>Fri, 26 Apr 2002 12:21:08 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/create-unix-user-with-restrictions/m-p/2711828#M60797</guid>
      <dc:creator>Tony Contratto</dc:creator>
      <dc:date>2002-04-26T12:21:08Z</dc:date>
    </item>
    <item>
      <title>Re: Create UNIX user with restrictions</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/create-unix-user-with-restrictions/m-p/2711829#M60798</link>
      <description>&amp;gt; The users will log into Omniback using Reflections, which means they log into unix first and then type xomni&amp;amp;.&lt;BR /&gt;&lt;BR /&gt;*Where* do they type "xomni&amp;amp;"? In a (hpterm/xterm) window? If so, how do they *get* that window? If automatically (i.e. by X/CDE/VUE), then just put the "xomni" (no "&amp;amp;") in the startup (.profile) of that user/window and an "exit" after it. That will give them a 'busy' window with which they can do nothing, and the desired OmniBack GUI. This setup is not hacker-proof, but should be sufficient for a person which can be trusted, but might *accidentily* get hirself in trouble.</description>
      <pubDate>Fri, 26 Apr 2002 12:51:36 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/create-unix-user-with-restrictions/m-p/2711829#M60798</guid>
      <dc:creator>Frank Slootweg</dc:creator>
      <dc:date>2002-04-26T12:51:36Z</dc:date>
    </item>
    <item>
      <title>Re: Create UNIX user with restrictions</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/create-unix-user-with-restrictions/m-p/2711830#M60799</link>
      <description>&lt;BR /&gt;This solution of updating the .profile has been given by me to many non-IT companies here for making them work only on their application and the moment the user is through with his application he is just logged out when he closed his application.&lt;BR /&gt;&lt;BR /&gt;-Sukant</description>
      <pubDate>Fri, 26 Apr 2002 13:16:05 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/create-unix-user-with-restrictions/m-p/2711830#M60799</guid>
      <dc:creator>Sukant Naik</dc:creator>
      <dc:date>2002-04-26T13:16:05Z</dc:date>
    </item>
    <item>
      <title>Re: Create UNIX user with restrictions</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/create-unix-user-with-restrictions/m-p/2711831#M60800</link>
      <description>Hi Khurram&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Create a user normally , and edit /etc/passwd file and in the last field replace the shell by rsh .In the home direcoty of the user , edit the .profile with whatever command you want to give for running omni back.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Manoj Srivastava</description>
      <pubDate>Fri, 26 Apr 2002 13:26:49 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/create-unix-user-with-restrictions/m-p/2711831#M60800</guid>
      <dc:creator>MANOJ SRIVASTAVA</dc:creator>
      <dc:date>2002-04-26T13:26:49Z</dc:date>
    </item>
    <item>
      <title>Re: Create UNIX user with restrictions</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/create-unix-user-with-restrictions/m-p/2711832#M60801</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Adding the rsh in the password file definately works, not too sure what I need to add in the .profile. The command to access omniback is xomni or xomni&amp;amp;, and the path is /opt/omni/bin. So please advise as to what command to enter in the .profile, thanks.&lt;BR /&gt;&lt;BR /&gt;Regards&lt;BR /&gt;&lt;BR /&gt;Khurram</description>
      <pubDate>Fri, 26 Apr 2002 13:39:44 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/create-unix-user-with-restrictions/m-p/2711832#M60801</guid>
      <dc:creator>Khurram Khan_1</dc:creator>
      <dc:date>2002-04-26T13:39:44Z</dc:date>
    </item>
    <item>
      <title>Re: Create UNIX user with restrictions</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/create-unix-user-with-restrictions/m-p/2711833#M60802</link>
      <description>Hi Khurram&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;in the .profile&lt;BR /&gt;&lt;BR /&gt;add export DISPLAY=&lt;AA.BB.CC.DD&gt;&lt;BR /&gt;    /opt/omni/bin/xomni&lt;BR /&gt;&lt;BR /&gt;&lt;AA.BB.CC.DD. is="" the="" ip="" adress="" for="" that="" users="" desktop="" as="" you="" ahve="" to="" display="" the="" graphics="" version.=""&gt;&lt;/AA.BB.CC.DD.&gt;&lt;BR /&gt;also please note that you might have to give omnibak group to this user , or change the group to 3 which that of the super user.&lt;BR /&gt;&lt;BR /&gt;Manoj Srivastava&lt;/AA.BB.CC.DD&gt;</description>
      <pubDate>Fri, 26 Apr 2002 14:06:58 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/create-unix-user-with-restrictions/m-p/2711833#M60802</guid>
      <dc:creator>MANOJ SRIVASTAVA</dc:creator>
      <dc:date>2002-04-26T14:06:58Z</dc:date>
    </item>
    <item>
      <title>Re: Create UNIX user with restrictions</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/create-unix-user-with-restrictions/m-p/2711834#M60803</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;When I add the following:&lt;BR /&gt;&lt;BR /&gt;export DISPLAY=194.60.97.70  (the IP for the DB server / UNIX server)&lt;BR /&gt;/opt/omni/bin/xomni&lt;BR /&gt;&lt;BR /&gt;Now I get the error message:&lt;BR /&gt;&lt;BR /&gt;Error: Can't open display: 194.60.97.70 &lt;BR /&gt;&lt;BR /&gt;The entry in the password file is as follows:&lt;BR /&gt;enduser:OVw7qGPBcfpBI:103:111:,,,:/home/enduser:/usr/bin/sh  (if I change the sh to rsh, then I don't get anything at all)&lt;BR /&gt;&lt;BR /&gt;The users are using Reflections to open a X terminal window, I would like to restrict them so that they can't change anything at UNIX.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Regards&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Khurram</description>
      <pubDate>Fri, 26 Apr 2002 14:22:25 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/create-unix-user-with-restrictions/m-p/2711834#M60803</guid>
      <dc:creator>Khurram Khan_1</dc:creator>
      <dc:date>2002-04-26T14:22:25Z</dc:date>
    </item>
    <item>
      <title>Re: Create UNIX user with restrictions</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/create-unix-user-with-restrictions/m-p/2711835#M60804</link>
      <description>another thing should do if you are using the .profile method is -- trap all interrupt signals at the first line of your .profile, otherwise, a user can quickly issue a 'Ctrl-C' when login (before login gets to your command in the .profile, often at the bottom) and break into command line mode. &lt;BR /&gt;&lt;BR /&gt;You can test this by putting a 'sleep 30' in your profile before the line of user's script, and try to break it when login.&lt;BR /&gt;&lt;BR /&gt;cheers,&lt;BR /&gt;Gary&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 26 Apr 2002 14:25:38 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/create-unix-user-with-restrictions/m-p/2711835#M60804</guid>
      <dc:creator>Gary Yu</dc:creator>
      <dc:date>2002-04-26T14:25:38Z</dc:date>
    </item>
    <item>
      <title>Re: Create UNIX user with restrictions</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/create-unix-user-with-restrictions/m-p/2711836#M60805</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Assuming that the omni_user logs in  from reflection.&lt;BR /&gt;&lt;BR /&gt;create  this user with a restricted shell and in his .profile, export his Display ( you may need to read the ipaddress of the PC from whereever this user logs in).&lt;BR /&gt;Also allow xomni&amp;amp; to be executed from the .profile.&lt;BR /&gt;To avoid the user from branching out to the shell , restrict him with TRAP.&lt;BR /&gt;&lt;BR /&gt;In addition to this all omni executables ( /opt/omni/lbin,/opt/omni/bin) &amp;amp; configuration files ( /etc/opt/omni/*) may need to be given permissions for this user.&lt;BR /&gt;Just in case he needs to change the datalist or the schedules.&lt;BR /&gt;&lt;BR /&gt;An alternative will be using SCM ( service control manager.</description>
      <pubDate>Fri, 26 Apr 2002 14:26:31 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/create-unix-user-with-restrictions/m-p/2711836#M60805</guid>
      <dc:creator>Jacob_2</dc:creator>
      <dc:date>2002-04-26T14:26:31Z</dc:date>
    </item>
    <item>
      <title>Re: Create UNIX user with restrictions</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/create-unix-user-with-restrictions/m-p/2711837#M60806</link>
      <description>Hi Khurram&lt;BR /&gt;&lt;BR /&gt;I think I didnot make it clear , the IP that had to be exported is where the user is running the xomni and not that of the server .&lt;BR /&gt;Like i am using the desktop which has the reflection s/w loaded , i go to the dos prompt by typing command in the run mode in window , then i run a command  ipconfig and get the IP address of the desktop  . Also please modify the export DISPLAY as &lt;BR /&gt;&lt;BR /&gt;export DISPLAY=aa.bb.cc.dd:0.0&lt;BR /&gt;&lt;BR /&gt;Manoj Srivastava</description>
      <pubDate>Fri, 26 Apr 2002 14:29:09 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/create-unix-user-with-restrictions/m-p/2711837#M60806</guid>
      <dc:creator>MANOJ SRIVASTAVA</dc:creator>
      <dc:date>2002-04-26T14:29:09Z</dc:date>
    </item>
    <item>
      <title>Re: Create UNIX user with restrictions</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/create-unix-user-with-restrictions/m-p/2711838#M60807</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;May be I am not making it very clear, I will start from the very beginning:&lt;BR /&gt;&lt;BR /&gt;The end users have different computers, so there IP addressses will not be statitc and are using windows NT. They log into UNIX using Refelections (X term), which after entering there name e.g. enduser, are asked to enter there password. Once that is complete they log into UNIX, and then they type in Xomni or Xomni&amp;amp; to access Omniback. I have already restricted access to Omniback, but not too sure how I can restrict the access to UNIX, as I don't want users to delete, move, copy or do anything at UNIX apart from type in Xomni or go to Omniback dirrectly. Whatever the advise, please list in detail the commands to be used, thanks.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Regards&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Khurram</description>
      <pubDate>Fri, 26 Apr 2002 14:35:01 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/create-unix-user-with-restrictions/m-p/2711838#M60807</guid>
      <dc:creator>Khurram Khan_1</dc:creator>
      <dc:date>2002-04-26T14:35:01Z</dc:date>
    </item>
  </channel>
</rss>

