<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sam &amp;quot;pasword aging&amp;quot; and Trusted default password aging  setting in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/sam-quot-pasword-aging-quot-and-trusted-default-password-aging/m-p/3824946#M740004</link>
    <description>The Sam values are the same as the Trusted system values. What I do not understand is, why when listing the user login values by&lt;BR /&gt;(getprpw "username") the values listed are not the same as the Trusted system values and or the SAM values. Also, the Trusted or Sam system defaults value are not enforced by the system. Example; expwarm default value is (5 days) and there are no advance warnings of password expiration.  The only operation to apply the values is in SAM menu "Modify Security Policies" and changing the "password aging policy" from  "Default (enable)" to "enable". Only then the vaules are listed for the user&lt;BR /&gt;Thanks&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;</description>
    <pubDate>Mon, 17 Jul 2006 15:15:25 GMT</pubDate>
    <dc:creator>frank jordan_1</dc:creator>
    <dc:date>2006-07-17T15:15:25Z</dc:date>
    <item>
      <title>Sam "pasword aging" and Trusted default password aging  setting</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/sam-quot-pasword-aging-quot-and-trusted-default-password-aging/m-p/3824943#M740001</link>
      <description>Hello,&lt;BR /&gt;My questions is why when creating an new user account thru SAM on a trusted system, the /tcb/files/auth/system/default setting are not applied to the newly created user. The user values are all "-1" see below;&lt;BR /&gt; upwchg=-1, acctexp=-1, llog=-1, expwarn=-1,</description>
      <pubDate>Mon, 17 Jul 2006 13:20:46 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/sam-quot-pasword-aging-quot-and-trusted-default-password-aging/m-p/3824943#M740001</guid>
      <dc:creator>frank jordan_1</dc:creator>
      <dc:date>2006-07-17T13:20:46Z</dc:date>
    </item>
    <item>
      <title>Re: Sam "pasword aging" and Trusted default password aging  setting</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/sam-quot-pasword-aging-quot-and-trusted-default-password-aging/m-p/3824944#M740002</link>
      <description>Because you are reading something into the values that is not there. When the users' personal values are left undefined then the system default values are used. If you look at the underlying getprpwent() - see the man page -- you will find that the user's values and the system-wide value are retrieved for each user and there are flags to indicate whether the user's value or the system-wide value is in use for any given field. Man modprpw and look under the -m option.&lt;BR /&gt;</description>
      <pubDate>Mon, 17 Jul 2006 13:43:22 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/sam-quot-pasword-aging-quot-and-trusted-default-password-aging/m-p/3824944#M740002</guid>
      <dc:creator>A. Clay Stephenson</dc:creator>
      <dc:date>2006-07-17T13:43:22Z</dc:date>
    </item>
    <item>
      <title>Re: Sam "pasword aging" and Trusted default password aging  setting</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/sam-quot-pasword-aging-quot-and-trusted-default-password-aging/m-p/3824945#M740003</link>
      <description>Shalom,&lt;BR /&gt;&lt;BR /&gt;Okay you are using sam to create users. I don't agree with the approach, but it is your system.&lt;BR /&gt;&lt;BR /&gt;Default settings are right in the same section of sam.&lt;BR /&gt;&lt;BR /&gt;You set them to what you want in the gui.&lt;BR /&gt;&lt;BR /&gt;right now the settings you display show no expiration warning, pretty much no optional settings.&lt;BR /&gt;&lt;BR /&gt;Password aging was set by default on my 11.11 systems in the US to 90 days.&lt;BR /&gt;&lt;BR /&gt;This you control however with the global or systems setting on sam.&lt;BR /&gt;&lt;BR /&gt;You can set defaults and password complexity in the /etc/defaults/security section of your system.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Mon, 17 Jul 2006 13:55:02 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/sam-quot-pasword-aging-quot-and-trusted-default-password-aging/m-p/3824945#M740003</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2006-07-17T13:55:02Z</dc:date>
    </item>
    <item>
      <title>Re: Sam "pasword aging" and Trusted default password aging  setting</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/sam-quot-pasword-aging-quot-and-trusted-default-password-aging/m-p/3824946#M740004</link>
      <description>The Sam values are the same as the Trusted system values. What I do not understand is, why when listing the user login values by&lt;BR /&gt;(getprpw "username") the values listed are not the same as the Trusted system values and or the SAM values. Also, the Trusted or Sam system defaults value are not enforced by the system. Example; expwarm default value is (5 days) and there are no advance warnings of password expiration.  The only operation to apply the values is in SAM menu "Modify Security Policies" and changing the "password aging policy" from  "Default (enable)" to "enable". Only then the vaules are listed for the user&lt;BR /&gt;Thanks&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;</description>
      <pubDate>Mon, 17 Jul 2006 15:15:25 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/sam-quot-pasword-aging-quot-and-trusted-default-password-aging/m-p/3824946#M740004</guid>
      <dc:creator>frank jordan_1</dc:creator>
      <dc:date>2006-07-17T15:15:25Z</dc:date>
    </item>
    <item>
      <title>Re: Sam "pasword aging" and Trusted default password aging  setting</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/sam-quot-pasword-aging-quot-and-trusted-default-password-aging/m-p/3824947#M740005</link>
      <description>Hi Frank,&lt;BR /&gt;&lt;BR /&gt;getprpw is a command designed for use within SAM - it's only relatively recently that it has been documented for public use.  The values that it returns are the user's values, so SAM would also check for the system defaults and determine if they should also be applied.&lt;BR /&gt;&lt;BR /&gt;If you edit the Security Policies within SAM for a particular user you are overriding the default, hence it will appear in the user's tcb file which is what getprpw is reading.&lt;BR /&gt;&lt;BR /&gt;How are you testing the expwarn settings?&lt;BR /&gt;&lt;BR /&gt;regards,&lt;BR /&gt;&lt;BR /&gt;Darren.</description>
      <pubDate>Tue, 18 Jul 2006 03:55:32 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/sam-quot-pasword-aging-quot-and-trusted-default-password-aging/m-p/3824947#M740005</guid>
      <dc:creator>Darren Prior</dc:creator>
      <dc:date>2006-07-18T03:55:32Z</dc:date>
    </item>
    <item>
      <title>Re: Sam "pasword aging" and Trusted default password aging  setting</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/sam-quot-pasword-aging-quot-and-trusted-default-password-aging/m-p/3824948#M740006</link>
      <description>same issue, SAM is not inheriting the u_life and expiration for password from the default file.&lt;BR /&gt;running 11.23&lt;BR /&gt;example:&lt;BR /&gt;/usr/lbin/getprpw sancho&lt;BR /&gt;uid=109, bootpw=NO, audid=35, audflg=1, mintm=-1, maxpwln=-1, exptm=-1, lftm=-1, spwchg=-1, upwchg=-1, acctexp=-1, llog=-1, expwarn=-1, usrpick=DFT, syspnpw=DFT, rstrpw=DFT, nullpw=DFT, admnum=-1, syschpw=DFT, sysltpw=DFT, timeod=-1, slogint=Fri Apr 20 12:04:09 2007, ulogint=-1, sloginy=-1, culogin=-1, uloginy=-1, umaxlntr=-1, alock=NO, lockout=0000001&lt;BR /&gt;&lt;BR /&gt;although the default file is:&lt;BR /&gt;more /tcb/files/auth/system/default&lt;BR /&gt;default:\&lt;BR /&gt;        :d_name=default:\&lt;BR /&gt;        :d_boot_authenticate@:\&lt;BR /&gt;        :u_pwd=*:\&lt;BR /&gt;        :u_owner=root:u_auditflag#-1:\&lt;BR /&gt;        :u_minchg#0:u_maxlen#8:u_exp#15724800:u_life#16934400:\&lt;BR /&gt;        :u_pw_expire_warning#604800:u_pswduser=root:u_pickpw:u_genpwd:\&lt;BR /&gt;        :u_restrict@:u_nullpw@:u_genchars@:u_genletters:\&lt;BR /&gt;        :u_suclog#0:u_unsuclog#0:u_maxtries#3:u_lock:\&lt;BR /&gt;        :\&lt;BR /&gt;        :t_logdelay#2:t_maxtries#10:t_login_timeout#0:\&lt;BR /&gt;        :chkent:&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;and that is creating the account using useradd not SAM</description>
      <pubDate>Fri, 20 Apr 2007 11:17:02 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/sam-quot-pasword-aging-quot-and-trusted-default-password-aging/m-p/3824948#M740006</guid>
      <dc:creator>IT Response</dc:creator>
      <dc:date>2007-04-20T11:17:02Z</dc:date>
    </item>
  </channel>
</rss>

