<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: stop users from changing password in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/stop-users-from-changing-password/m-p/2624980#M756038</link>
    <description>Since it is a trusted system I would go with the previous suggestion of setting the minimum time between change to the same amount of time that the password lifetime is set to. But this kind of defeats the purpose of using trusted system policies. You could change the password format to be stricter if you are concerned about users picking easy passwords. Or have th system generate a password for them.&lt;BR /&gt;&lt;BR /&gt;Good Luck,&lt;BR /&gt;C</description>
    <pubDate>Tue, 04 Dec 2001 16:18:32 GMT</pubDate>
    <dc:creator>Craig Rants</dc:creator>
    <dc:date>2001-12-04T16:18:32Z</dc:date>
    <item>
      <title>stop users from changing password</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/stop-users-from-changing-password/m-p/2624975#M756033</link>
      <description>How do I stop users from changing their password on a trusted system?  When you convert to a trusted system the option for "only allow superuser to change password" is no longer available.</description>
      <pubDate>Tue, 04 Dec 2001 16:07:10 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/stop-users-from-changing-password/m-p/2624975#M756033</guid>
      <dc:creator>Mike Burk</dc:creator>
      <dc:date>2001-12-04T16:07:10Z</dc:date>
    </item>
    <item>
      <title>Re: stop users from changing password</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/stop-users-from-changing-password/m-p/2624976#M756034</link>
      <description>Are you serious?&lt;BR /&gt;&lt;BR /&gt;live free or die&lt;BR /&gt;harry</description>
      <pubDate>Tue, 04 Dec 2001 16:09:26 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/stop-users-from-changing-password/m-p/2624976#M756034</guid>
      <dc:creator>harry d brown jr</dc:creator>
      <dc:date>2001-12-04T16:09:26Z</dc:date>
    </item>
    <item>
      <title>Re: stop users from changing password</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/stop-users-from-changing-password/m-p/2624977#M756035</link>
      <description>&lt;BR /&gt;You can remove the execute permission on the /usr/bin/passwd binary.&lt;BR /&gt;chmod 5550  /usr/sbin/passwd&lt;BR /&gt;&lt;BR /&gt;Or since this is a trusted system, you can set the minimum time required between password changes to a very largenumber.&lt;BR /&gt;&lt;BR /&gt;Any reason to do this?&lt;BR /&gt;&lt;BR /&gt;-raj</description>
      <pubDate>Tue, 04 Dec 2001 16:13:20 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/stop-users-from-changing-password/m-p/2624977#M756035</guid>
      <dc:creator>Roger Baptiste</dc:creator>
      <dc:date>2001-12-04T16:13:20Z</dc:date>
    </item>
    <item>
      <title>Re: stop users from changing password</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/stop-users-from-changing-password/m-p/2624978#M756036</link>
      <description>I agree with RajMan ..&lt;BR /&gt;I dont see any other way.&lt;BR /&gt;&lt;BR /&gt;Richard</description>
      <pubDate>Tue, 04 Dec 2001 16:15:51 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/stop-users-from-changing-password/m-p/2624978#M756036</guid>
      <dc:creator>someone_4</dc:creator>
      <dc:date>2001-12-04T16:15:51Z</dc:date>
    </item>
    <item>
      <title>Re: stop users from changing password</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/stop-users-from-changing-password/m-p/2624979#M756037</link>
      <description>Why would you want to prevent your users from changing their passwords??  If anything you should be completely opposite, stricly enforcing password policies and educating your users accordingly.  You wouldn't even want the burden of that responsibility anyway, especially if you have any real number of users on your system(s).&lt;BR /&gt;&lt;BR /&gt;Hope this helps&lt;BR /&gt;Chris</description>
      <pubDate>Tue, 04 Dec 2001 16:15:56 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/stop-users-from-changing-password/m-p/2624979#M756037</guid>
      <dc:creator>Christopher McCray_1</dc:creator>
      <dc:date>2001-12-04T16:15:56Z</dc:date>
    </item>
    <item>
      <title>Re: stop users from changing password</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/stop-users-from-changing-password/m-p/2624980#M756038</link>
      <description>Since it is a trusted system I would go with the previous suggestion of setting the minimum time between change to the same amount of time that the password lifetime is set to. But this kind of defeats the purpose of using trusted system policies. You could change the password format to be stricter if you are concerned about users picking easy passwords. Or have th system generate a password for them.&lt;BR /&gt;&lt;BR /&gt;Good Luck,&lt;BR /&gt;C</description>
      <pubDate>Tue, 04 Dec 2001 16:18:32 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/stop-users-from-changing-password/m-p/2624980#M756038</guid>
      <dc:creator>Craig Rants</dc:creator>
      <dc:date>2001-12-04T16:18:32Z</dc:date>
    </item>
    <item>
      <title>Re: stop users from changing password</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/stop-users-from-changing-password/m-p/2624981#M756039</link>
      <description>Yes Harry I am serious.  Sorry if it is such a dumb question but I thought the purpose of this forum is to ask and answer hp-ux related questions.  If the question is not hard enough for you then just don't answer it.</description>
      <pubDate>Tue, 04 Dec 2001 16:18:46 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/stop-users-from-changing-password/m-p/2624981#M756039</guid>
      <dc:creator>Mike Burk</dc:creator>
      <dc:date>2001-12-04T16:18:46Z</dc:date>
    </item>
    <item>
      <title>Re: stop users from changing password</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/stop-users-from-changing-password/m-p/2624982#M756040</link>
      <description>Hi Mike,&lt;BR /&gt;&lt;BR /&gt;Haven't seen this request for a while now. why would you want to do this? &lt;BR /&gt;In any case, just remove the setuid bid off on the /usr/bin/passwd, or remove the execute permissions of the binary.&lt;BR /&gt;&lt;BR /&gt;chmod 4550 /usr/bin/passwd or&lt;BR /&gt;chmod 555 /usr/bin/passwd&lt;BR /&gt;&lt;BR /&gt;The user will get different errors based on how you change it.&lt;BR /&gt;&lt;BR /&gt;-HTH&lt;BR /&gt;Ramesh</description>
      <pubDate>Tue, 04 Dec 2001 16:19:49 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/stop-users-from-changing-password/m-p/2624982#M756040</guid>
      <dc:creator>linuxfan</dc:creator>
      <dc:date>2001-12-04T16:19:49Z</dc:date>
    </item>
    <item>
      <title>Re: stop users from changing password</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/stop-users-from-changing-password/m-p/2624983#M756041</link>
      <description>Hello Mike,&lt;BR /&gt;&lt;BR /&gt;I suppose that you want to know and contol the password that your users have. But you don't need it because you as user root can change th passwords when you want and can use the "su" command to change to any users. Then you can give license to your users to change their passwords and if there are problems you can solve it.&lt;BR /&gt;&lt;BR /&gt;Hope this help you.&lt;BR /&gt;    Justo.</description>
      <pubDate>Tue, 04 Dec 2001 16:29:43 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/stop-users-from-changing-password/m-p/2624983#M756041</guid>
      <dc:creator>Justo Exposito</dc:creator>
      <dc:date>2001-12-04T16:29:43Z</dc:date>
    </item>
    <item>
      <title>Re: stop users from changing password</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/stop-users-from-changing-password/m-p/2624984#M756042</link>
      <description>This is an example when those of us who ask questions, shouldn't be so negative.  We have no idea what Mike's system is doing or how it is configured, what applications are on it.  I can think of at least one example where this may be a necessary configuration:  An application server that has only a generic user id such as "oracle" where you don't want them to change the password unless it is done by an admin. Remember, there are benefits to having a Trusted system besides password aging. Granted, I probably still wouldn't be it this way, but thats not the point. This should be a forum where we can ask any question, and be warned where it may not be the wisest approach, but negativity should always be avoided.&lt;BR /&gt;&lt;BR /&gt;To answer your question, I see 2 solutions:&lt;BR /&gt;1) Change the permissions on the passwd command so only root can run it.&lt;BR /&gt;2) Set the minimum time to change a password to the same amount as the password life, but set the password life as high as you can.&lt;BR /&gt;</description>
      <pubDate>Tue, 04 Dec 2001 16:40:16 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/stop-users-from-changing-password/m-p/2624984#M756042</guid>
      <dc:creator>Bernie Vande Griend</dc:creator>
      <dc:date>2001-12-04T16:40:16Z</dc:date>
    </item>
    <item>
      <title>Re: stop users from changing password</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/stop-users-from-changing-password/m-p/2624985#M756043</link>
      <description>Mike, I can understand your situation if your concern is to avoid help desk calls becasue people have issues/problems when they change their password and then forget the one they changed it too.  It is a common problem actually.  Users can't seem to remember their passwords and when they finally have it burned into their brains, they change it and the help desk calls start coming in. However the inconvienence needs to be weighed against the risk. There is a password aging parameter that prevents users from changing their password before x days have expired. &lt;BR /&gt;&lt;BR /&gt;Tony</description>
      <pubDate>Tue, 04 Dec 2001 16:42:38 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/stop-users-from-changing-password/m-p/2624985#M756043</guid>
      <dc:creator>Anthony deRito</dc:creator>
      <dc:date>2001-12-04T16:42:38Z</dc:date>
    </item>
    <item>
      <title>Re: stop users from changing password</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/stop-users-from-changing-password/m-p/2624986#M756044</link>
      <description>I agree totally with you, Bernie, in that their should be a alevel of tact in dealing with any question, no matter what.  Consider this; although this certainly not one of those instances, isn't it our duty to prevent one from doing possibly the wrong thing instead of telling them how, just for the sake of helping out?  I also have generic accounts, but we ahve specific people who manage them.  oracle belongs to our dba group, for example.  I just wanted to put in my pro and con and in no means want to be inflammatory; I just want to hopefully provide the most feasible solution.  Thanks to all who will tolerate my ramblings and for everyone's outstanding support.&lt;BR /&gt;&lt;BR /&gt;Chris</description>
      <pubDate>Tue, 04 Dec 2001 16:49:15 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/stop-users-from-changing-password/m-p/2624986#M756044</guid>
      <dc:creator>Christopher McCray_1</dc:creator>
      <dc:date>2001-12-04T16:49:15Z</dc:date>
    </item>
    <item>
      <title>Re: stop users from changing password</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/stop-users-from-changing-password/m-p/2624987#M756045</link>
      <description>Yes Chris and Bernie it's ok.&lt;BR /&gt;&lt;BR /&gt;Regards.&lt;BR /&gt;&lt;BR /&gt;  Justo.</description>
      <pubDate>Tue, 04 Dec 2001 16:55:33 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/stop-users-from-changing-password/m-p/2624987#M756045</guid>
      <dc:creator>Justo Exposito</dc:creator>
      <dc:date>2001-12-04T16:55:33Z</dc:date>
    </item>
    <item>
      <title>Re: stop users from changing password</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/stop-users-from-changing-password/m-p/2624988#M756046</link>
      <description>Yes Christopher, we're on the same page. We should warn someone if we feel another course of action is better. It should be done in a professional manner of course. Then the author can decide what to do with the information.  I just wanted to point out that we don't always know the intentions or the exact scenario that an author is dealing with, and should be careful to jump to conclusions.  That is all, and I appreciate everyone's input and involvment as well.  Thanks.</description>
      <pubDate>Tue, 04 Dec 2001 16:56:32 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/stop-users-from-changing-password/m-p/2624988#M756046</guid>
      <dc:creator>Bernie Vande Griend</dc:creator>
      <dc:date>2001-12-04T16:56:32Z</dc:date>
    </item>
    <item>
      <title>Re: stop users from changing password</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/stop-users-from-changing-password/m-p/2624989#M756047</link>
      <description>(music playing in background) All we are saying, is give peace a chance</description>
      <pubDate>Tue, 04 Dec 2001 16:59:19 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/stop-users-from-changing-password/m-p/2624989#M756047</guid>
      <dc:creator>Craig Rants</dc:creator>
      <dc:date>2001-12-04T16:59:19Z</dc:date>
    </item>
    <item>
      <title>Re: stop users from changing password</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/stop-users-from-changing-password/m-p/2624990#M756048</link>
      <description>Good music, Craig.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;&lt;BR /&gt;Justo.</description>
      <pubDate>Tue, 04 Dec 2001 17:05:39 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/stop-users-from-changing-password/m-p/2624990#M756048</guid>
      <dc:creator>Justo Exposito</dc:creator>
      <dc:date>2001-12-04T17:05:39Z</dc:date>
    </item>
    <item>
      <title>Re: stop users from changing password</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/stop-users-from-changing-password/m-p/2624991#M756049</link>
      <description>Thanks, to everyone for the support.  To answer some of your questions, I have a requirement for the minimum password length to be no less than 8 alpha-numerics.  I can not set the min to anything more than 6.  So I have to set the users password and remove the permissions to change it.  If anyone has any suggestions on how to set the min password to 8 then I would be greatfull.&lt;BR /&gt;&lt;BR /&gt;Thanks again.&lt;BR /&gt;&lt;BR /&gt;Mike</description>
      <pubDate>Tue, 04 Dec 2001 17:32:44 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/stop-users-from-changing-password/m-p/2624991#M756049</guid>
      <dc:creator>Mike Burk</dc:creator>
      <dc:date>2001-12-04T17:32:44Z</dc:date>
    </item>
    <item>
      <title>Re: stop users from changing password</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/stop-users-from-changing-password/m-p/2624992#M756050</link>
      <description>&lt;BR /&gt;&lt;BR /&gt;  o MIN_PASSWORD_LENGTH (introduced in 11.00 via PHCO_24390)&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.faqs.org/faqs/hp/hpux-faq/section-67.html" target="_blank"&gt;http://www.faqs.org/faqs/hp/hpux-faq/section-67.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;live free or die&lt;BR /&gt;harry</description>
      <pubDate>Tue, 04 Dec 2001 17:49:57 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/stop-users-from-changing-password/m-p/2624992#M756050</guid>
      <dc:creator>harry d brown jr</dc:creator>
      <dc:date>2001-12-04T17:49:57Z</dc:date>
    </item>
    <item>
      <title>Re: stop users from changing password</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/stop-users-from-changing-password/m-p/2624993#M756051</link>
      <description>&lt;BR /&gt;Mike,&lt;BR /&gt;&lt;BR /&gt;We get a lot of "strange" questions here, were people could make their systems open to hackers. &lt;BR /&gt;&lt;BR /&gt;First you stated that the machine is "trusted", then you say you don't want users to change their passwords, which in my mind is an oxymoron. So, it wasn't an attack on you, just a clarification as to the goals you are trying to accomplish.&lt;BR /&gt;&lt;BR /&gt;live free or die&lt;BR /&gt;harry</description>
      <pubDate>Tue, 04 Dec 2001 17:53:40 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/stop-users-from-changing-password/m-p/2624993#M756051</guid>
      <dc:creator>harry d brown jr</dc:creator>
      <dc:date>2001-12-04T17:53:40Z</dc:date>
    </item>
  </channel>
</rss>

