<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: user with root access, but is not allowed to login in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/user-with-root-access-but-is-not-allowed-to-login/m-p/2573073#M857510</link>
    <description>Shawn : &lt;BR /&gt;  &lt;BR /&gt;   With '*' in the pasword field, a use will never be able to login. Iam assuming that this particular user is created manually. So easiest way to get out this problem is to remove '*' in the /etc/passwd filed and leave it blank ( You should be able to see :: in the password field ) then issue passwd command to have some known password and then change user-id field /etc/passwd to 0.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;...Madhu</description>
    <pubDate>Thu, 30 Aug 2001 18:30:16 GMT</pubDate>
    <dc:creator>Madhu Sudhan_1</dc:creator>
    <dc:date>2001-08-30T18:30:16Z</dc:date>
    <item>
      <title>user with root access, but is not allowed to login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/user-with-root-access-but-is-not-allowed-to-login/m-p/2573069#M857506</link>
      <description>I am trying to create a new user with root access, but is not allowed to login, that means, I only can su to this user, is that possible? Why?&lt;BR /&gt;</description>
      <pubDate>Thu, 30 Aug 2001 17:25:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/user-with-root-access-but-is-not-allowed-to-login/m-p/2573069#M857506</guid>
      <dc:creator>Victor_5</dc:creator>
      <dc:date>2001-08-30T17:25:21Z</dc:date>
    </item>
    <item>
      <title>Re: user with root access, but is not allowed to login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/user-with-root-access-but-is-not-allowed-to-login/m-p/2573070#M857507</link>
      <description>If you set up a user with an invalid password in the password filed in /etc/passwd, then you will only be able to do 'su - username' to get to that user.  An invalid password would be a * in the password field in /etc/password.</description>
      <pubDate>Thu, 30 Aug 2001 17:50:18 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/user-with-root-access-but-is-not-allowed-to-login/m-p/2573070#M857507</guid>
      <dc:creator>Patrick Wallek</dc:creator>
      <dc:date>2001-08-30T17:50:18Z</dc:date>
    </item>
    <item>
      <title>Re: user with root access, but is not allowed to login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/user-with-root-access-but-is-not-allowed-to-login/m-p/2573071#M857508</link>
      <description>I think /etc/securetty is effective for any user with id 0.&lt;BR /&gt;&lt;BR /&gt;So, try out keeping "/dev/console" in /etc/securetty.&lt;BR /&gt;&lt;BR /&gt;-Sri</description>
      <pubDate>Thu, 30 Aug 2001 17:51:03 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/user-with-root-access-but-is-not-allowed-to-login/m-p/2573071#M857508</guid>
      <dc:creator>Sridhar Bhaskarla</dc:creator>
      <dc:date>2001-08-30T17:51:03Z</dc:date>
    </item>
    <item>
      <title>Re: user with root access, but is not allowed to login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/user-with-root-access-but-is-not-allowed-to-login/m-p/2573072#M857509</link>
      <description>Hi Patrick:&lt;BR /&gt;&lt;BR /&gt;I did the test, changed the second field of that user in /etc/passwd to '*', but when I issued the 'su - username', it still need password, so I was unable to switch to that user.&lt;BR /&gt;&lt;BR /&gt;From my understanding, the system still need to read /etc/passwd even you issue su, after input invalid password, of course I can not login, but I cannot su either. More detail information?&lt;BR /&gt;&lt;BR /&gt;Hi Sridhar:&lt;BR /&gt;On my system, I could not find the file:&lt;BR /&gt;/etc/securetty?&lt;BR /&gt;</description>
      <pubDate>Thu, 30 Aug 2001 18:21:14 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/user-with-root-access-but-is-not-allowed-to-login/m-p/2573072#M857509</guid>
      <dc:creator>Victor_5</dc:creator>
      <dc:date>2001-08-30T18:21:14Z</dc:date>
    </item>
    <item>
      <title>Re: user with root access, but is not allowed to login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/user-with-root-access-but-is-not-allowed-to-login/m-p/2573073#M857510</link>
      <description>Shawn : &lt;BR /&gt;  &lt;BR /&gt;   With '*' in the pasword field, a use will never be able to login. Iam assuming that this particular user is created manually. So easiest way to get out this problem is to remove '*' in the /etc/passwd filed and leave it blank ( You should be able to see :: in the password field ) then issue passwd command to have some known password and then change user-id field /etc/passwd to 0.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;...Madhu</description>
      <pubDate>Thu, 30 Aug 2001 18:30:16 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/user-with-root-access-but-is-not-allowed-to-login/m-p/2573073#M857510</guid>
      <dc:creator>Madhu Sudhan_1</dc:creator>
      <dc:date>2001-08-30T18:30:16Z</dc:date>
    </item>
    <item>
      <title>Re: user with root access, but is not allowed to login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/user-with-root-access-but-is-not-allowed-to-login/m-p/2573074#M857511</link>
      <description>Hi Madhu:&lt;BR /&gt;&lt;BR /&gt;Good try! However, I need another different user not root, if change uid to 0 in /etc/passwd, when I create some file, the owner is root not another one which I need. Any other idea?&lt;BR /&gt;</description>
      <pubDate>Thu, 30 Aug 2001 18:52:10 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/user-with-root-access-but-is-not-allowed-to-login/m-p/2573074#M857511</guid>
      <dc:creator>Victor_5</dc:creator>
      <dc:date>2001-08-30T18:52:10Z</dc:date>
    </item>
    <item>
      <title>Re: user with root access, but is not allowed to login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/user-with-root-access-but-is-not-allowed-to-login/m-p/2573075#M857512</link>
      <description>Shawn,&lt;BR /&gt;&lt;BR /&gt;Simple&lt;BR /&gt;&lt;BR /&gt;echo "/dev/console" &amp;gt;&amp;gt; /etc/securetty&lt;BR /&gt;&lt;BR /&gt;And change the permissions to 600&lt;BR /&gt;&lt;BR /&gt;-Sri</description>
      <pubDate>Thu, 30 Aug 2001 19:06:50 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/user-with-root-access-but-is-not-allowed-to-login/m-p/2573075#M857512</guid>
      <dc:creator>Sridhar Bhaskarla</dc:creator>
      <dc:date>2001-08-30T19:06:50Z</dc:date>
    </item>
    <item>
      <title>Re: user with root access, but is not allowed to login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/user-with-root-access-but-is-not-allowed-to-login/m-p/2573076#M857513</link>
      <description>Sorry, one more idea.&lt;BR /&gt;&lt;BR /&gt;As Patrick said, create a user with id 0  say superuser but keep the password as *. Now, this user cannot login because of the invalid password.&lt;BR /&gt;&lt;BR /&gt;Keep .rhosts entry in superuser's home directory like this&lt;BR /&gt;&lt;BR /&gt;your_system_name your_user&lt;BR /&gt;&lt;BR /&gt;Now, your_user can successfully rlogin to the system and get in as the super_user.&lt;BR /&gt;&lt;BR /&gt;This is a security violation. But having another user with uid 0 is more dangerous so I think this can be considered.&lt;BR /&gt;&lt;BR /&gt;But /etc/securetty is the best way. This file will not be there by default. You need to create one.&lt;BR /&gt;&lt;BR /&gt;-Sri</description>
      <pubDate>Thu, 30 Aug 2001 19:10:38 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/user-with-root-access-but-is-not-allowed-to-login/m-p/2573076#M857513</guid>
      <dc:creator>Sridhar Bhaskarla</dc:creator>
      <dc:date>2001-08-30T19:10:38Z</dc:date>
    </item>
    <item>
      <title>Re: user with root access, but is not allowed to login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/user-with-root-access-but-is-not-allowed-to-login/m-p/2573077#M857514</link>
      <description>I think I see what you are trying to do, but I am not sure it is possible.  For a user other than root, to have all the same privileges as root, it must have uid 0.  You can't create a user and assign privileges to it so that it is "equivalent" to root.&lt;BR /&gt;&lt;BR /&gt;If a user needs to be able to execute something as root you can try 'sudo'.  Sudo can be downloaded from the porting center.&lt;BR /&gt;&lt;A href="http://hpux.connect.org.uk/hppd/hpux/Sysadmin/sudo-1.6.2b1/" target="_blank"&gt;http://hpux.connect.org.uk/hppd/hpux/Sysadmin/sudo-1.6.2b1/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;When I mentioned su'ing to a user with an invalid password, only root can do that.  Sorry!&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 30 Aug 2001 19:11:16 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/user-with-root-access-but-is-not-allowed-to-login/m-p/2573077#M857514</guid>
      <dc:creator>Patrick Wallek</dc:creator>
      <dc:date>2001-08-30T19:11:16Z</dc:date>
    </item>
    <item>
      <title>Re: user with root access, but is not allowed to login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/user-with-root-access-but-is-not-allowed-to-login/m-p/2573078#M857515</link>
      <description>Sorry for one more mail. I am very young to this forum.&lt;BR /&gt;&lt;BR /&gt;I think I didn't explain the process well in my previous mail. Let's take the following as examples.&lt;BR /&gt;&lt;BR /&gt;SYSTEM=your_system&lt;BR /&gt;ROOTACCOUNT=super_user&lt;BR /&gt;ORDINARYUSER=your_user&lt;BR /&gt;&lt;BR /&gt;Edit .rhosts under the home directory of super_user and place the entry&lt;BR /&gt;&lt;BR /&gt;your_system your_user&lt;BR /&gt;&lt;BR /&gt;Now your_user will login to your_system using the normal way as an ordinary user.&lt;BR /&gt;&lt;BR /&gt;Once gets onto the system, he does an rlogin to the SAME system&lt;BR /&gt;&lt;BR /&gt;your_user@your_system$ rlogin your_system -l super_user&lt;BR /&gt;&lt;PROFILE executes=""&gt;&lt;BR /&gt;super_user@your_system#&lt;BR /&gt;&lt;BR /&gt;-Sri&lt;BR /&gt;&lt;/PROFILE&gt;</description>
      <pubDate>Thu, 30 Aug 2001 19:16:20 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/user-with-root-access-but-is-not-allowed-to-login/m-p/2573078#M857515</guid>
      <dc:creator>Sridhar Bhaskarla</dc:creator>
      <dc:date>2001-08-30T19:16:20Z</dc:date>
    </item>
    <item>
      <title>Re: user with root access, but is not allowed to login</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/user-with-root-access-but-is-not-allowed-to-login/m-p/2573079#M857516</link>
      <description>Hi Shawn,&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;How about trying something like this,&lt;BR /&gt;say you add a new user rroot with a uid of 0.&lt;BR /&gt;&lt;BR /&gt;modify your /etc/profile by adding these&lt;BR /&gt;&lt;BR /&gt;/Begin/&lt;BR /&gt;&lt;BR /&gt;shellchk=$(ps -p $PPID | sed -n 2p | cut -c23 - | sed s/^-//)&lt;BR /&gt;&lt;BR /&gt;if [[ $LOGNAME = "rroot" ]]&lt;BR /&gt;then&lt;BR /&gt;   if [[ $shellchk = "telnetd" || $shellchk = "rlogind" ]]&lt;BR /&gt;   then &lt;BR /&gt;        echo "Sorry direct logging in as rroot is not allowed"&lt;BR /&gt;        exit 1&lt;BR /&gt;    fi&lt;BR /&gt;fi&lt;BR /&gt;&lt;BR /&gt;/End/&lt;BR /&gt;&lt;BR /&gt;what this would do is prevent rroot from directly logging in either by telnet or rlogind, if you use ssh, then you can probably add ssh as well.&lt;BR /&gt;&lt;BR /&gt;I am sure there are lots of fine tuning you can do to this, but this seems to be working.&lt;BR /&gt;&lt;BR /&gt;-Regards&lt;BR /&gt;Ramesh</description>
      <pubDate>Thu, 30 Aug 2001 19:43:06 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/user-with-root-access-but-is-not-allowed-to-login/m-p/2573079#M857516</guid>
      <dc:creator>linuxfan</dc:creator>
      <dc:date>2001-08-30T19:43:06Z</dc:date>
    </item>
  </channel>
</rss>

