<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: OpenSSH and TCB in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/openssh-and-tcb/m-p/3016960#M750554</link>
    <description>Hi Karen,&lt;BR /&gt;&lt;BR /&gt;Unfortunately this is the same situation on all Unix platforms as SSH is written to be as generic and portable as possible. In order to generic the authors could not easily tie SSH into each OS's password ageing system.&lt;BR /&gt;&lt;BR /&gt;You also have the same situation if you use keys to login, and there's nothing to stop you choosing a passphrase of &lt;ENTER&gt;/Nothing, and there is no history management or timeout.&lt;BR /&gt;&lt;BR /&gt;The only solution I can offer is to only allow users to SSH to other unprivileged users, and then "su". You can then enforce the password ageing on those accounts, and you also have a record of who used them, and when.&lt;BR /&gt;&lt;BR /&gt;Andrew&lt;/ENTER&gt;</description>
    <pubDate>Tue, 08 Jul 2003 04:49:06 GMT</pubDate>
    <dc:creator>Andrew Cowan</dc:creator>
    <dc:date>2003-07-08T04:49:06Z</dc:date>
    <item>
      <title>OpenSSH and TCB</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/openssh-and-tcb/m-p/3016959#M750553</link>
      <description>On hpux 11.00 server with TCB enabled and openssh 2.5.1p1 installed, users will be forced to change password as set up when they login using telnet. But this is skipped/by-passed when they use SSH. &lt;BR /&gt;&lt;BR /&gt;Any idea why and how to prevent it?&lt;BR /&gt;&lt;BR /&gt;Thanks!&lt;BR /&gt;&lt;BR /&gt;Karen</description>
      <pubDate>Mon, 07 Jul 2003 17:09:14 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/openssh-and-tcb/m-p/3016959#M750553</guid>
      <dc:creator>Karen Shen_1</dc:creator>
      <dc:date>2003-07-07T17:09:14Z</dc:date>
    </item>
    <item>
      <title>Re: OpenSSH and TCB</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/openssh-and-tcb/m-p/3016960#M750554</link>
      <description>Hi Karen,&lt;BR /&gt;&lt;BR /&gt;Unfortunately this is the same situation on all Unix platforms as SSH is written to be as generic and portable as possible. In order to generic the authors could not easily tie SSH into each OS's password ageing system.&lt;BR /&gt;&lt;BR /&gt;You also have the same situation if you use keys to login, and there's nothing to stop you choosing a passphrase of &lt;ENTER&gt;/Nothing, and there is no history management or timeout.&lt;BR /&gt;&lt;BR /&gt;The only solution I can offer is to only allow users to SSH to other unprivileged users, and then "su". You can then enforce the password ageing on those accounts, and you also have a record of who used them, and when.&lt;BR /&gt;&lt;BR /&gt;Andrew&lt;/ENTER&gt;</description>
      <pubDate>Tue, 08 Jul 2003 04:49:06 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/openssh-and-tcb/m-p/3016960#M750554</guid>
      <dc:creator>Andrew Cowan</dc:creator>
      <dc:date>2003-07-08T04:49:06Z</dc:date>
    </item>
    <item>
      <title>Re: OpenSSH and TCB</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/openssh-and-tcb/m-p/3016961#M750555</link>
      <description>just hit submit once and wait&lt;BR /&gt;&lt;BR /&gt;for some reason it comes back almost immediately but it is not done</description>
      <pubDate>Tue, 08 Jul 2003 12:53:04 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/openssh-and-tcb/m-p/3016961#M750555</guid>
      <dc:creator>John Bolene</dc:creator>
      <dc:date>2003-07-08T12:53:04Z</dc:date>
    </item>
    <item>
      <title>Re: OpenSSH and TCB</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/openssh-and-tcb/m-p/3016962#M750556</link>
      <description>I think this has been added as a "feature" in the latest openssh release..&lt;BR /&gt;&lt;BR /&gt;GooD LUck</description>
      <pubDate>Tue, 08 Jul 2003 20:50:53 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/openssh-and-tcb/m-p/3016962#M750556</guid>
      <dc:creator>D. Jackson_1</dc:creator>
      <dc:date>2003-07-08T20:50:53Z</dc:date>
    </item>
    <item>
      <title>Re: OpenSSH and TCB</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/openssh-and-tcb/m-p/3016963#M750557</link>
      <description>Hi John,&lt;BR /&gt;&lt;BR /&gt;Thanks for sorting out my duplicate posts. Sometimes when I press submit I can wait for 20 minutes and then get a "page not found" error, and perhaps nothing is posted. Here at the bank we have an E3 connection so it should (and 90% of the time does) happen pretty-much instantly, however every now and again it seems to go pear-shaped.&lt;BR /&gt;</description>
      <pubDate>Wed, 09 Jul 2003 03:54:36 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/openssh-and-tcb/m-p/3016963#M750557</guid>
      <dc:creator>Andrew Cowan</dc:creator>
      <dc:date>2003-07-09T03:54:36Z</dc:date>
    </item>
    <item>
      <title>Re: OpenSSH and TCB</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/openssh-and-tcb/m-p/3016964#M750558</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Your version of openssh is extremely old. You should upgrade it to the latest which fixes quite a number of security issues since openssh 2.5.1p1.&lt;BR /&gt;&lt;BR /&gt;As for your question, offhand, I believe you can workaround this limitation by writing scripts to interface your system login scripts with /tcb files.  With a combination of trap signals used in your script, you should be able to enforce password changes.&lt;BR /&gt;&lt;BR /&gt;Hope this helps. Regards.&lt;BR /&gt;&lt;BR /&gt;Steven Sim Kok Leong</description>
      <pubDate>Sat, 12 Jul 2003 01:54:48 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/openssh-and-tcb/m-p/3016964#M750558</guid>
      <dc:creator>Steven Sim Kok Leong</dc:creator>
      <dc:date>2003-07-12T01:54:48Z</dc:date>
    </item>
  </channel>
</rss>

