<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic trusted system in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/trusted-system/m-p/3126995#M748045</link>
    <description>Hi all!&lt;BR /&gt;&lt;BR /&gt;Can any of you tell me about his/her experience with trusted systems under hpux 11.00 and 11.11? The thing is we'd like to convert our systems to trusted and need to know if there is any disadvantage with it. Thanks.</description>
    <pubDate>Mon, 24 Nov 2003 04:12:54 GMT</pubDate>
    <dc:creator>Brozza_1</dc:creator>
    <dc:date>2003-11-24T04:12:54Z</dc:date>
    <item>
      <title>trusted system</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/trusted-system/m-p/3126995#M748045</link>
      <description>Hi all!&lt;BR /&gt;&lt;BR /&gt;Can any of you tell me about his/her experience with trusted systems under hpux 11.00 and 11.11? The thing is we'd like to convert our systems to trusted and need to know if there is any disadvantage with it. Thanks.</description>
      <pubDate>Mon, 24 Nov 2003 04:12:54 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/trusted-system/m-p/3126995#M748045</guid>
      <dc:creator>Brozza_1</dc:creator>
      <dc:date>2003-11-24T04:12:54Z</dc:date>
    </item>
    <item>
      <title>Re: trusted system</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/trusted-system/m-p/3126996#M748046</link>
      <description>Hi Brozza,&lt;BR /&gt;&lt;BR /&gt;on docs.hp.com you can find many useful hints and suggestions to manage your trusted system and eventual known problems.&lt;BR /&gt;Anyway &lt;BR /&gt;KBRC00012678 - TRUSTED:  System generated password length exceeds maximum length  &lt;BR /&gt;&lt;BR /&gt;already reports a warning about password lenghts and&lt;BR /&gt;&lt;BR /&gt;KBRC00010639 - Troubleshooting a Trusted system &lt;BR /&gt;&lt;BR /&gt;about a general troubleshooting on trusted system.&lt;BR /&gt;&lt;BR /&gt;I hope this helps you.&lt;BR /&gt;&lt;BR /&gt;Best regards,&lt;BR /&gt;Ettore</description>
      <pubDate>Mon, 24 Nov 2003 04:39:29 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/trusted-system/m-p/3126996#M748046</guid>
      <dc:creator>Fabio Ettore</dc:creator>
      <dc:date>2003-11-24T04:39:29Z</dc:date>
    </item>
    <item>
      <title>Re: trusted system</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/trusted-system/m-p/3126997#M748047</link>
      <description>In my experience, the most frequent problem reported for a Trusted System is that, the root user account being disabled, after root's password being keyed in wrong for 3 times (by default is 3 times).&lt;BR /&gt;&lt;BR /&gt;To resolve this, you must bring the system down to single-user mode to change the root password.&lt;BR /&gt;&lt;BR /&gt;Or you may want to increase the 'Unsuccessful Login Tries Allowed' from 'General User Account Policies' using SAM to increase the number.&lt;BR /&gt;&lt;BR /&gt;Hope this helps!</description>
      <pubDate>Mon, 24 Nov 2003 06:31:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/trusted-system/m-p/3126997#M748047</guid>
      <dc:creator>Mei Jiao</dc:creator>
      <dc:date>2003-11-24T06:31:21Z</dc:date>
    </item>
    <item>
      <title>Re: trusted system</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/trusted-system/m-p/3126998#M748048</link>
      <description>I never had any problems with trusted systems.&lt;BR /&gt;&lt;BR /&gt;Yiu have more control on passwors, expiry time and whole lot of other details. For accounts getting  disabled, you can set max. no. unsuccessful logins. For root I always set it bit high,&lt;BR /&gt;&lt;BR /&gt;Also immedialtely after to you convert to trusted systems , in order to avoid getting all logins expired, execute the following command.&lt;BR /&gt;&lt;BR /&gt;/usr/lbin/modprpw -V&lt;BR /&gt;&lt;BR /&gt;Check the man pages for getprpw, getprdef, modprpw, modprdef.&lt;BR /&gt;&lt;BR /&gt;Hope this helps.</description>
      <pubDate>Mon, 24 Nov 2003 07:25:52 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/trusted-system/m-p/3126998#M748048</guid>
      <dc:creator>RAC_1</dc:creator>
      <dc:date>2003-11-24T07:25:52Z</dc:date>
    </item>
    <item>
      <title>Re: trusted system</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/trusted-system/m-p/3126999#M748049</link>
      <description>Trusted Systems are very nice to have especially if your corporation is audited.  It allows you to set up password aging, accounts deactivation and neat security stuff. &lt;BR /&gt;&lt;BR /&gt;Most of the problems I've encountered have to do with account deactivation.  People don't always remember that they only have 3 (or x number of times) to get their password right before being locked.  Also, has already mentionned, root being locked can create havoc (especially if you don't have another root-type account), cause not only will it lock you root and stop from accessing it, but if you're using r-commands, like in ServiceGuard, it'll always ask you for password, and even if it's the right one, it won't work, causing jobs to fail. &lt;BR /&gt;&lt;BR /&gt;But in my mind, the advantages far outweight the disadvantages.</description>
      <pubDate>Mon, 24 Nov 2003 07:50:20 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/trusted-system/m-p/3126999#M748049</guid>
      <dc:creator>Marco Santerre</dc:creator>
      <dc:date>2003-11-24T07:50:20Z</dc:date>
    </item>
    <item>
      <title>Re: trusted system</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/trusted-system/m-p/3127000#M748050</link>
      <description>Brozza, can you tell us why you want to convert to trusted systems? Is it because of protected passwords, auditing, password restrictions or some other reason? Knowing what's important to you would help us give you better answers. &lt;BR /&gt;&lt;BR /&gt;Do you run NIS? You can't mix trusted mode and NIS.  &lt;BR /&gt;&lt;BR /&gt;If you decide to convert to trusted mode, be sure you have current patches for libsec, tsconvert and libpam before converting.  That will help you avoid several potential problems.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 25 Nov 2003 05:37:52 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/trusted-system/m-p/3127000#M748050</guid>
      <dc:creator>doug hosking</dc:creator>
      <dc:date>2003-11-25T05:37:52Z</dc:date>
    </item>
    <item>
      <title>Re: trusted system</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/trusted-system/m-p/3127001#M748051</link>
      <description>One point to note on re-enabling the root account after it has been disabled/locked.  You should not have to bring the system to single user mode in order to reactivate the account.  All you have to do is login successfully from the console as root.  Even with the system being trusted, root access is always allowed from the console, even if the account is locked.  The act of loggin in on the console as root will automatically reactivate the root account.&lt;BR /&gt;&lt;BR /&gt;JL</description>
      <pubDate>Tue, 25 Nov 2003 08:45:27 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/trusted-system/m-p/3127001#M748051</guid>
      <dc:creator>James Lynch</dc:creator>
      <dc:date>2003-11-25T08:45:27Z</dc:date>
    </item>
    <item>
      <title>Re: trusted system</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/trusted-system/m-p/3127002#M748052</link>
      <description>James, you're right. I've done testing on a server, after the root account being locked/disabled, login through its console can automatically re-activate the root account. Will take note of this. :)&lt;BR /&gt;&lt;BR /&gt;By the way, I think bring the system down to single-user mode to re-activate the root account is unavoidable for a workstation? Unless we have another active telnet session login as root?</description>
      <pubDate>Tue, 25 Nov 2003 21:32:25 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/trusted-system/m-p/3127002#M748052</guid>
      <dc:creator>Mei Jiao</dc:creator>
      <dc:date>2003-11-25T21:32:25Z</dc:date>
    </item>
    <item>
      <title>Re: trusted system</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/trusted-system/m-p/3127003#M748053</link>
      <description>I'm not 100% sure on this, since I don't have a workstation to test on, but I think that you should still be able to login as root without bringing down the system to single user mode.  Remember that the the graphics head that you normally login on is also the console port.  You may just need to bypass the CDE window environment.  This is usually accomplished by selecting an option from the login (dtgreet) screen to login as a text/normal session.&lt;BR /&gt;&lt;BR /&gt;JL</description>
      <pubDate>Wed, 26 Nov 2003 07:46:47 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/trusted-system/m-p/3127003#M748053</guid>
      <dc:creator>James Lynch</dc:creator>
      <dc:date>2003-11-26T07:46:47Z</dc:date>
    </item>
  </channel>
</rss>

