<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: RBAC Implementaion in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/rbac-implementaion/m-p/5659257#M732248</link>
    <description>&lt;P&gt;use correct path thats sbin instead of bin, Problem resolved.&lt;/P&gt;</description>
    <pubDate>Wed, 16 May 2012 09:07:28 GMT</pubDate>
    <dc:creator>vishnu.khandare</dc:creator>
    <dc:date>2012-05-16T09:07:28Z</dc:date>
    <item>
      <title>RBAC Implementaion</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/rbac-implementaion/m-p/5617343#M732246</link>
      <description>&lt;P&gt;Hi Friends,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I m facing n issues while implementing the RBAC, pls find belwo error.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;$ privrun /usr/sbin/useradd new_user&lt;BR /&gt;privrun: authorization check failed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any permission issue, do we need to provide the rbac dir.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Pls help to resolve&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Vishnu&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Apr 2012 08:49:58 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/rbac-implementaion/m-p/5617343#M732246</guid>
      <dc:creator>vishnu.khandare</dc:creator>
      <dc:date>2012-04-13T08:49:58Z</dc:date>
    </item>
    <item>
      <title>Re: RBAC Implementaion</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/rbac-implementaion/m-p/5636669#M732247</link>
      <description>&lt;P&gt;Does the user you are running the command as have the correct authorization?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1st check what roles the user has:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;# roleadm list user=foo&lt;BR /&gt;foo:userAdmins&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then check what authorizations those roles have:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;# authadm list role=userAdmins&lt;BR /&gt;userAdmins: (hpux.user.add, *)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To run the useradd command (via privrun) the user must have the&amp;nbsp;hpux.user.add authorization &amp;nbsp;AND you must uncomment the useradd entry in the /etc/rbac/cmd_priv file:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;# grep useradd /etc/rbac/cmd_priv&lt;BR /&gt;#/usr/sbin/useradd :dflt :(hpux.user.add,*) :0/0// :dflt :dflt :dflt :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The reason that this &amp;nbsp;is commented out is because if you allow a user to run useradd they can create a user with a uidnumber of 0 and they now have a root account on the system.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the cmd_priv file:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;# The following entries are known to be equivalent to granting&lt;BR /&gt;# unconstrained root. Specifically, the commands may be used&lt;BR /&gt;# to obtain an account with uid=0.&lt;BR /&gt;#&lt;BR /&gt;#/usr/sbin/useradd :dflt :(hpux.user.add,*)&lt;BR /&gt;:0/0// :dflt :dflt :dflt :&lt;/P&gt;&lt;P&gt;....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Apr 2012 16:29:18 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/rbac-implementaion/m-p/5636669#M732247</guid>
      <dc:creator>Doug_Lamoureux</dc:creator>
      <dc:date>2012-04-26T16:29:18Z</dc:date>
    </item>
    <item>
      <title>Re: RBAC Implementaion</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/rbac-implementaion/m-p/5659257#M732248</link>
      <description>&lt;P&gt;use correct path thats sbin instead of bin, Problem resolved.&lt;/P&gt;</description>
      <pubDate>Wed, 16 May 2012 09:07:28 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/rbac-implementaion/m-p/5659257#M732248</guid>
      <dc:creator>vishnu.khandare</dc:creator>
      <dc:date>2012-05-16T09:07:28Z</dc:date>
    </item>
  </channel>
</rss>

