<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Block specific command for a user in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/block-specific-command-for-a-user/m-p/4583439#M733367</link>
    <description>Not really.  Not unless you replace these commands by a wrapper to check who is using them.  And somehow hide the originals away.</description>
    <pubDate>Sat, 13 Feb 2010 03:40:52 GMT</pubDate>
    <dc:creator>Dennis Handly</dc:creator>
    <dc:date>2010-02-13T03:40:52Z</dc:date>
    <item>
      <title>Block specific command for a user</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/block-specific-command-for-a-user/m-p/4583438#M733366</link>
      <description>We have a user called bnk and do not want this user to execute zcat and cpio. Is it possible to block specific commands to a specific user/group?</description>
      <pubDate>Sat, 13 Feb 2010 03:02:33 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/block-specific-command-for-a-user/m-p/4583438#M733366</guid>
      <dc:creator>Chris Campbell 77</dc:creator>
      <dc:date>2010-02-13T03:02:33Z</dc:date>
    </item>
    <item>
      <title>Re: Block specific command for a user</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/block-specific-command-for-a-user/m-p/4583439#M733367</link>
      <description>Not really.  Not unless you replace these commands by a wrapper to check who is using them.  And somehow hide the originals away.</description>
      <pubDate>Sat, 13 Feb 2010 03:40:52 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/block-specific-command-for-a-user/m-p/4583439#M733367</guid>
      <dc:creator>Dennis Handly</dc:creator>
      <dc:date>2010-02-13T03:40:52Z</dc:date>
    </item>
    <item>
      <title>Re: Block specific command for a user</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/block-specific-command-for-a-user/m-p/4583440#M733368</link>
      <description>&lt;!--!*#--&gt;&amp;gt; Not really. Not unless [...]&lt;BR /&gt;&lt;BR /&gt;      man acl&lt;BR /&gt;&lt;BR /&gt;[...]&lt;BR /&gt;For example, the following optional access control list entries can be associated with our file:&lt;BR /&gt;[...]&lt;BR /&gt;(george.%,---)&lt;BR /&gt;    Deny any access to user george in no specific group.&lt;BR /&gt;[...]&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Why would this be a useful thing to do?  What&lt;BR /&gt;damage could a normal user do with these&lt;BR /&gt;programs, which he could not do just as&lt;BR /&gt;easily with some other programs?</description>
      <pubDate>Sat, 13 Feb 2010 05:32:02 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/block-specific-command-for-a-user/m-p/4583440#M733368</guid>
      <dc:creator>Steven Schweda</dc:creator>
      <dc:date>2010-02-13T05:32:02Z</dc:date>
    </item>
    <item>
      <title>Re: Block specific command for a user</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/block-specific-command-for-a-user/m-p/4583441#M733369</link>
      <description>My boss instruction....&lt;BR /&gt;Our application uses a user ID for the environment which the app runs.&lt;BR /&gt;The database is backed up using zcat and compressed. He wants to ensure if the user was ever compromised they could not extract the data using zcat and cpio. I told him to use crypt on the compressed files but doesnt think its secure enough.</description>
      <pubDate>Sat, 13 Feb 2010 05:55:57 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/block-specific-command-for-a-user/m-p/4583441#M733369</guid>
      <dc:creator>Chris Campbell 77</dc:creator>
      <dc:date>2010-02-13T05:55:57Z</dc:date>
    </item>
    <item>
      <title>Re: Block specific command for a user</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/block-specific-command-for-a-user/m-p/4583442#M733370</link>
      <description>&lt;!--!*#--&gt;&amp;gt; He wants to ensure [...]&lt;BR /&gt;&lt;BR /&gt;And you can't do that with file permissions&lt;BR /&gt;on the data?&lt;BR /&gt;&lt;BR /&gt;And the user can't bring in his own zcat&lt;BR /&gt;and/or cpio programs?&lt;BR /&gt;&lt;BR /&gt;&amp;gt; [...] doesnt think its secure enough.&lt;BR /&gt;&lt;BR /&gt;What would be?  GnuPG is available.  But who&lt;BR /&gt;would be doing the encryption?  Who's trying&lt;BR /&gt;to hide what from whom?&lt;BR /&gt;&lt;BR /&gt;As usual, it might be more helpful if you&lt;BR /&gt;described the actual problem which you are&lt;BR /&gt;trying to solve, rather than asking how to&lt;BR /&gt;implement some sub-ideal "solution".</description>
      <pubDate>Sat, 13 Feb 2010 15:40:02 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/block-specific-command-for-a-user/m-p/4583442#M733370</guid>
      <dc:creator>Steven Schweda</dc:creator>
      <dc:date>2010-02-13T15:40:02Z</dc:date>
    </item>
    <item>
      <title>Re: Block specific command for a user</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/block-specific-command-for-a-user/m-p/4583443#M733371</link>
      <description>There is no problem. &lt;BR /&gt;Our backups are done with zcat and cpio via the app we are using . He wanted to know if the application account be restricted from extracting the data. Just wanted to know if it was possible to block maybe using a ACL.</description>
      <pubDate>Wed, 17 Feb 2010 20:37:03 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/block-specific-command-for-a-user/m-p/4583443#M733371</guid>
      <dc:creator>Chris Campbell 77</dc:creator>
      <dc:date>2010-02-17T20:37:03Z</dc:date>
    </item>
    <item>
      <title>Re: Block specific command for a user</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/block-specific-command-for-a-user/m-p/4583444#M733372</link>
      <description>Does this same application account create the backups?&lt;BR /&gt;&lt;BR /&gt;Are you wanting it to be able to back up the data with cpio and zcat, but not restore the data using the same commands?</description>
      <pubDate>Wed, 17 Feb 2010 21:06:00 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/block-specific-command-for-a-user/m-p/4583444#M733372</guid>
      <dc:creator>Patrick Wallek</dc:creator>
      <dc:date>2010-02-17T21:06:00Z</dc:date>
    </item>
    <item>
      <title>Re: Block specific command for a user</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/block-specific-command-for-a-user/m-p/4583445#M733373</link>
      <description>Hello,&lt;BR /&gt;&lt;BR /&gt;&amp;gt;Our backups are done with zcat and cpio via the app we are using . He wanted to know if the application account be restricted from extracting the data&lt;BR /&gt;&lt;BR /&gt;If some account is used for creating the archive (with zcat), why bother to hide the resulting archive from the person using the same account? I mean if he can access the original data, it is pointless to deny access to some archive that would contain the same data. &lt;BR /&gt;&lt;BR /&gt;Horia.</description>
      <pubDate>Thu, 18 Feb 2010 13:25:25 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/block-specific-command-for-a-user/m-p/4583445#M733373</guid>
      <dc:creator>Horia Chirculescu</dc:creator>
      <dc:date>2010-02-18T13:25:25Z</dc:date>
    </item>
  </channel>
</rss>

