<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ignite without rexec in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/ignite-without-rexec/m-p/3081939#M751541</link>
    <description>Hi Guys,&lt;BR /&gt;&lt;BR /&gt;Here we set up /var/adm/inetd.sec to allow access ONLY from the Ignite server(s).&lt;BR /&gt;Corp Security has blessed this, but like us, would rather disable r commands altogether.&lt;BR /&gt; &lt;BR /&gt;Rgds,&lt;BR /&gt;Jeff</description>
    <pubDate>Tue, 30 Sep 2003 13:10:23 GMT</pubDate>
    <dc:creator>Jeff Schussele</dc:creator>
    <dc:date>2003-09-30T13:10:23Z</dc:date>
    <item>
      <title>ignite without rexec</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ignite-without-rexec/m-p/3081927#M751529</link>
      <description>Was anyone able to get "Ignite UX" to work without rexec?</description>
      <pubDate>Tue, 30 Sep 2003 12:20:40 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ignite-without-rexec/m-p/3081927#M751529</guid>
      <dc:creator>Donny Jekels</dc:creator>
      <dc:date>2003-09-30T12:20:40Z</dc:date>
    </item>
    <item>
      <title>Re: ignite without rexec</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ignite-without-rexec/m-p/3081928#M751530</link>
      <description>Donny,&lt;BR /&gt; &lt;BR /&gt;I assume you're referring to make_net_recovery.  Make_tape_recovery seems to work just fine.&lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt;Pete&lt;BR /&gt; &lt;BR /&gt;</description>
      <pubDate>Tue, 30 Sep 2003 12:22:25 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ignite-without-rexec/m-p/3081928#M751530</guid>
      <dc:creator>Pete Randall</dc:creator>
      <dc:date>2003-09-30T12:22:25Z</dc:date>
    </item>
    <item>
      <title>Re: ignite without rexec</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ignite-without-rexec/m-p/3081929#M751531</link>
      <description>nope. not even there yet. trying to add a client to our ignite server, so I can push out the new Ignite client software.&lt;BR /&gt;&lt;BR /&gt;#rexec is commented out in /etc/inetd.conf</description>
      <pubDate>Tue, 30 Sep 2003 12:33:01 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ignite-without-rexec/m-p/3081929#M751531</guid>
      <dc:creator>Donny Jekels</dc:creator>
      <dc:date>2003-09-30T12:33:01Z</dc:date>
    </item>
    <item>
      <title>Re: ignite without rexec</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ignite-without-rexec/m-p/3081930#M751532</link>
      <description>Donny,&lt;BR /&gt; &lt;BR /&gt;Maybe SEP will pipe in here.  He does a lot with Ignite and I know he abhors the "r" commands.&lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt;Pete&lt;BR /&gt; &lt;BR /&gt;</description>
      <pubDate>Tue, 30 Sep 2003 12:36:40 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ignite-without-rexec/m-p/3081930#M751532</guid>
      <dc:creator>Pete Randall</dc:creator>
      <dc:date>2003-09-30T12:36:40Z</dc:date>
    </item>
    <item>
      <title>Re: ignite without rexec</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ignite-without-rexec/m-p/3081931#M751533</link>
      <description>Pete thanks, I read some of SEP's threads yes maybe he can help.</description>
      <pubDate>Tue, 30 Sep 2003 12:42:02 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ignite-without-rexec/m-p/3081931#M751533</guid>
      <dc:creator>Donny Jekels</dc:creator>
      <dc:date>2003-09-30T12:42:02Z</dc:date>
    </item>
    <item>
      <title>Re: ignite without rexec</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ignite-without-rexec/m-p/3081932#M751534</link>
      <description>If Ignite's compnents are configurable.. perhaps it can use SSH to do its thing?...</description>
      <pubDate>Tue, 30 Sep 2003 12:47:28 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ignite-without-rexec/m-p/3081932#M751534</guid>
      <dc:creator>Alzhy</dc:creator>
      <dc:date>2003-09-30T12:47:28Z</dc:date>
    </item>
    <item>
      <title>Re: ignite without rexec</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ignite-without-rexec/m-p/3081933#M751535</link>
      <description>Donny,&lt;BR /&gt; &lt;BR /&gt;I sent him an e-mail.  He's been quiet the last couple of hours but I'm sure he'll jump in when he can.&lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt;Pete&lt;BR /&gt; &lt;BR /&gt;</description>
      <pubDate>Tue, 30 Sep 2003 12:48:06 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ignite-without-rexec/m-p/3081933#M751535</guid>
      <dc:creator>Pete Randall</dc:creator>
      <dc:date>2003-09-30T12:48:06Z</dc:date>
    </item>
    <item>
      <title>Re: ignite without rexec</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ignite-without-rexec/m-p/3081934#M751536</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;I was doing some yucky work. Budgets are due today at 5 p.m.  Plus trying to spend last years money.&lt;BR /&gt; &lt;BR /&gt;To my knowledge, and I've had a few support calls with HP on this, the Berkley protocols, including rexec are required to run an Ignite/UX server.&lt;BR /&gt;&lt;BR /&gt;I have contacted HP and said that its an important Ignite enhancement to integrate this product with ssh.&lt;BR /&gt; &lt;BR /&gt;How I handle this obvious security problem is as follows:&lt;BR /&gt; &lt;BR /&gt;The Ignite Server has the protocols enabled in inetd.conf. It has no .rhosts file and it has an /etc/hosts.equiv file authorizing Ignite clients by IP address.&lt;BR /&gt;&lt;BR /&gt;This enables make_net_recovery jobs to be run out of cron by my two production servers to the Ignite Server.&lt;BR /&gt;&lt;BR /&gt;Those two servers, Ignite clients have the Berkley r-protocols commented out in inetd.conf. When I need to do DR or push a new image out to those servers, I uncomment the entries save the file and run ientd -c&lt;BR /&gt; &lt;BR /&gt;This is still a problem, I'd rather not run this way.  I read the docs on Ignite 4.3 and see no indication that ssh is supported.&lt;BR /&gt; &lt;BR /&gt;SEP</description>
      <pubDate>Tue, 30 Sep 2003 12:54:24 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ignite-without-rexec/m-p/3081934#M751536</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2003-09-30T12:54:24Z</dc:date>
    </item>
    <item>
      <title>Re: ignite without rexec</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ignite-without-rexec/m-p/3081935#M751537</link>
      <description>yuck! Thanks guys.</description>
      <pubDate>Tue, 30 Sep 2003 12:58:04 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ignite-without-rexec/m-p/3081935#M751537</guid>
      <dc:creator>Donny Jekels</dc:creator>
      <dc:date>2003-09-30T12:58:04Z</dc:date>
    </item>
    <item>
      <title>Re: ignite without rexec</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ignite-without-rexec/m-p/3081936#M751538</link>
      <description>quick refresher. &lt;BR /&gt;&lt;BR /&gt;inetd -c does not drop existing connections, or does it?</description>
      <pubDate>Tue, 30 Sep 2003 13:01:09 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ignite-without-rexec/m-p/3081936#M751538</guid>
      <dc:creator>Donny Jekels</dc:creator>
      <dc:date>2003-09-30T13:01:09Z</dc:date>
    </item>
    <item>
      <title>Re: ignite without rexec</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ignite-without-rexec/m-p/3081937#M751539</link>
      <description>No, existing connections will stay open.&lt;BR /&gt; &lt;BR /&gt;inetd -k will stop new connections, not disrupt existing ones.&lt;BR /&gt;&lt;BR /&gt; &lt;BR /&gt;SEP</description>
      <pubDate>Tue, 30 Sep 2003 13:03:52 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ignite-without-rexec/m-p/3081937#M751539</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2003-09-30T13:03:52Z</dc:date>
    </item>
    <item>
      <title>Re: ignite without rexec</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ignite-without-rexec/m-p/3081938#M751540</link>
      <description>yet another work around.&lt;BR /&gt;&lt;BR /&gt;Okay thank you.&lt;BR /&gt;peace&lt;BR /&gt;Donny</description>
      <pubDate>Tue, 30 Sep 2003 13:05:09 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ignite-without-rexec/m-p/3081938#M751540</guid>
      <dc:creator>Donny Jekels</dc:creator>
      <dc:date>2003-09-30T13:05:09Z</dc:date>
    </item>
    <item>
      <title>Re: ignite without rexec</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ignite-without-rexec/m-p/3081939#M751541</link>
      <description>Hi Guys,&lt;BR /&gt;&lt;BR /&gt;Here we set up /var/adm/inetd.sec to allow access ONLY from the Ignite server(s).&lt;BR /&gt;Corp Security has blessed this, but like us, would rather disable r commands altogether.&lt;BR /&gt; &lt;BR /&gt;Rgds,&lt;BR /&gt;Jeff</description>
      <pubDate>Tue, 30 Sep 2003 13:10:23 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ignite-without-rexec/m-p/3081939#M751541</guid>
      <dc:creator>Jeff Schussele</dc:creator>
      <dc:date>2003-09-30T13:10:23Z</dc:date>
    </item>
    <item>
      <title>Re: ignite without rexec</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ignite-without-rexec/m-p/3081940#M751542</link>
      <description>Jeff,&lt;BR /&gt;&lt;BR /&gt;this sounds like a great idea. send more info please.&lt;BR /&gt;&lt;BR /&gt;Thanks Donny</description>
      <pubDate>Tue, 30 Sep 2003 13:12:31 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ignite-without-rexec/m-p/3081940#M751542</guid>
      <dc:creator>Donny Jekels</dc:creator>
      <dc:date>2003-09-30T13:12:31Z</dc:date>
    </item>
    <item>
      <title>Re: ignite without rexec</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ignite-without-rexec/m-p/3081941#M751543</link>
      <description>Here is an ientd.sec example.&lt;BR /&gt;&lt;BR /&gt;ftp             allow   10.1.*  10.1.11.* prod tzfat hebron &lt;BR /&gt;tftp            allow   192.168.* 10.1.*  jufprod jufdev hebron moriah&lt;BR /&gt;login           allow   10.1.* 10.85.* 10.1.31.* 10.4* jufprod hebron moriah jufdev&lt;BR /&gt;telnet          allow   10.1.* 10.85.* 10.1.31.* 10.4* prod hebron moriah &lt;BR /&gt;&lt;BR /&gt;There are few limits on what you can do with this file, it can be very precise and limit the  chance that outsiders will get in.&lt;BR /&gt;&lt;BR /&gt; &lt;BR /&gt;SEP</description>
      <pubDate>Tue, 30 Sep 2003 13:18:08 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ignite-without-rexec/m-p/3081941#M751543</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2003-09-30T13:18:08Z</dc:date>
    </item>
    <item>
      <title>Re: ignite without rexec</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ignite-without-rexec/m-p/3081942#M751544</link>
      <description>does this mean i can add one entry for my ignite server - say&lt;BR /&gt;&lt;BR /&gt;/var/adm/inetd.sec&lt;BR /&gt;&lt;BR /&gt;rexec allow &lt;IGNITESERVER&gt;&lt;BR /&gt;&lt;BR /&gt;how does inetd knows to run rexec if it is commented out in inetd.conf?&lt;/IGNITESERVER&gt;</description>
      <pubDate>Tue, 30 Sep 2003 13:25:14 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ignite-without-rexec/m-p/3081942#M751544</guid>
      <dc:creator>Donny Jekels</dc:creator>
      <dc:date>2003-09-30T13:25:14Z</dc:date>
    </item>
    <item>
      <title>Re: ignite without rexec</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ignite-without-rexec/m-p/3081943#M751545</link>
      <description>Donny,&lt;BR /&gt;&lt;BR /&gt; &lt;BR /&gt;There comes a time when you need to try it.&lt;BR /&gt; &lt;BR /&gt;Now may be the time.  I tried it and it was accepted when I ran inetd.sec&lt;BR /&gt; &lt;BR /&gt;Also note, you can limit the NFS access that Ignite ALSO requires with /etc/exports.&lt;BR /&gt; &lt;BR /&gt;Here is mine.&lt;BR /&gt; &lt;BR /&gt;/images -anon=2,access=jufprod,access=hebron,access=tzfat&lt;BR /&gt;&lt;BR /&gt;Note the access limits based on hostnames.&lt;BR /&gt; &lt;BR /&gt;NFS is a problem because it transmits disk information unencrypted.&lt;BR /&gt; &lt;BR /&gt;SEP&lt;BR /&gt;</description>
      <pubDate>Tue, 30 Sep 2003 13:33:52 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ignite-without-rexec/m-p/3081943#M751545</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2003-09-30T13:33:52Z</dc:date>
    </item>
    <item>
      <title>Re: ignite without rexec</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ignite-without-rexec/m-p/3081944#M751546</link>
      <description>I emailed Berlene Herren on this issue.  Seems she read the the thread and she answered as follows(forgive the paraphrase).&lt;BR /&gt; &lt;BR /&gt;There is an enhancement request to the labs for Ignite to work with ssh.  &lt;BR /&gt;&lt;BR /&gt;She added our organization to the list of organizations that wants this feature.&lt;BR /&gt; &lt;BR /&gt;In my opinion, the way to make this happen is for customers such as you Donny, to contact HP and make their wishes known.&lt;BR /&gt; &lt;BR /&gt;I imagine based on my Ignite experience its a rather involved upgrade.&lt;BR /&gt; &lt;BR /&gt;SEP</description>
      <pubDate>Tue, 30 Sep 2003 14:25:54 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ignite-without-rexec/m-p/3081944#M751546</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2003-09-30T14:25:54Z</dc:date>
    </item>
    <item>
      <title>Re: ignite without rexec</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ignite-without-rexec/m-p/3081945#M751547</link>
      <description>Hi Donny,&lt;BR /&gt;&lt;BR /&gt;Sorry for the delayed reply - have been quite busy today.&lt;BR /&gt;&lt;BR /&gt;Anyway as SEP noted you need &lt;BR /&gt;&lt;BR /&gt;tftp deny &lt;BR /&gt;tftp allow ignite_server_ip&lt;BR /&gt;login deny&lt;BR /&gt;login allow ignite_server_ip&lt;BR /&gt;exec deny&lt;BR /&gt;exec allow ignite_server_ip&lt;BR /&gt; &lt;BR /&gt;on the Ignite client as well as the Ignite server. First entry denies ALL while the second explicitly allows all servers/IPs listed. You don't need to bounce inetd as the .sec file is read at every connection attempt. &lt;BR /&gt; &lt;BR /&gt;HTH,&lt;BR /&gt;Jeff</description>
      <pubDate>Tue, 30 Sep 2003 14:34:38 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ignite-without-rexec/m-p/3081945#M751547</guid>
      <dc:creator>Jeff Schussele</dc:creator>
      <dc:date>2003-09-30T14:34:38Z</dc:date>
    </item>
    <item>
      <title>Re: ignite without rexec</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ignite-without-rexec/m-p/3081946#M751548</link>
      <description>Sure thing, I can send emails and requests to HP, if I only knew where to send it with our next SD order :-(</description>
      <pubDate>Tue, 30 Sep 2003 15:01:56 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ignite-without-rexec/m-p/3081946#M751548</guid>
      <dc:creator>Donny Jekels</dc:creator>
      <dc:date>2003-09-30T15:01:56Z</dc:date>
    </item>
  </channel>
</rss>

