<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic HP-UX 11.0 security problem in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/hp-ux-11-0-security-problem/m-p/2561242#M918541</link>
    <description>When I am trying to login to one of the servers (on which Medusa is installed), it gives the following error messages :&lt;BR /&gt;&lt;BR /&gt;---------------------------&lt;BR /&gt;[KQ#root]/root/home/root &amp;gt; su - testVN01&lt;BR /&gt;setgroups: Not owner&lt;BR /&gt;setgroups: Not owner&lt;BR /&gt;su: Unable to initialize group access list&lt;BR /&gt;[KQ#root]/root/home/root &amp;gt;&lt;BR /&gt;[KQ#root]/root/home/root &amp;gt; su - oracle&lt;BR /&gt;setgroups: Not owner&lt;BR /&gt;setgroups: Not owner&lt;BR /&gt;su: Unable to initialize group access list&lt;BR /&gt;[KQ#root]/root/home/root &amp;gt; su - testrv&lt;BR /&gt;su: Invalid ID&lt;BR /&gt;[KQ#root]/root/home/root &amp;gt; pwget |grep testrv&lt;BR /&gt;testrv:7d6kZH3vbpyvQ,O.9M:5905:205:SystemTester Ravi BH,TMD,x16497,:/home/testrv:/usr/bin/ksh&lt;BR /&gt;[KQ#root]/root/home/root &amp;gt; pwget |grep -E 'ora|test'&lt;BR /&gt;oracle:Mfw7In06a27s6:8801:101:,,,:/opt/app/oracle/product/8.0.6:/usr/bin/ksh&lt;BR /&gt;testrv:7d6kZH3vbpyvQ,O.9M:5905:205:SystemTester Ravi BH,TMD,x16497,:/home/testrv:/usr/bin/ksh&lt;BR /&gt;[KQ#root]/root/home/root &amp;gt; login oracle&lt;BR /&gt;Password:&lt;BR /&gt;Unable to set uid/gid&lt;BR /&gt;Connection closed by foreign host.&lt;BR /&gt;vinu-hpsgnru:/home/vinu&amp;gt;&lt;BR /&gt;------------------------------&lt;BR /&gt;Any clues as to the reason for this behaviour would be appreciated.&lt;BR /&gt;&lt;BR /&gt;</description>
    <pubDate>Fri, 03 Aug 2001 11:09:36 GMT</pubDate>
    <dc:creator>Vinu Neelakandhan</dc:creator>
    <dc:date>2001-08-03T11:09:36Z</dc:date>
    <item>
      <title>HP-UX 11.0 security problem</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/hp-ux-11-0-security-problem/m-p/2561242#M918541</link>
      <description>When I am trying to login to one of the servers (on which Medusa is installed), it gives the following error messages :&lt;BR /&gt;&lt;BR /&gt;---------------------------&lt;BR /&gt;[KQ#root]/root/home/root &amp;gt; su - testVN01&lt;BR /&gt;setgroups: Not owner&lt;BR /&gt;setgroups: Not owner&lt;BR /&gt;su: Unable to initialize group access list&lt;BR /&gt;[KQ#root]/root/home/root &amp;gt;&lt;BR /&gt;[KQ#root]/root/home/root &amp;gt; su - oracle&lt;BR /&gt;setgroups: Not owner&lt;BR /&gt;setgroups: Not owner&lt;BR /&gt;su: Unable to initialize group access list&lt;BR /&gt;[KQ#root]/root/home/root &amp;gt; su - testrv&lt;BR /&gt;su: Invalid ID&lt;BR /&gt;[KQ#root]/root/home/root &amp;gt; pwget |grep testrv&lt;BR /&gt;testrv:7d6kZH3vbpyvQ,O.9M:5905:205:SystemTester Ravi BH,TMD,x16497,:/home/testrv:/usr/bin/ksh&lt;BR /&gt;[KQ#root]/root/home/root &amp;gt; pwget |grep -E 'ora|test'&lt;BR /&gt;oracle:Mfw7In06a27s6:8801:101:,,,:/opt/app/oracle/product/8.0.6:/usr/bin/ksh&lt;BR /&gt;testrv:7d6kZH3vbpyvQ,O.9M:5905:205:SystemTester Ravi BH,TMD,x16497,:/home/testrv:/usr/bin/ksh&lt;BR /&gt;[KQ#root]/root/home/root &amp;gt; login oracle&lt;BR /&gt;Password:&lt;BR /&gt;Unable to set uid/gid&lt;BR /&gt;Connection closed by foreign host.&lt;BR /&gt;vinu-hpsgnru:/home/vinu&amp;gt;&lt;BR /&gt;------------------------------&lt;BR /&gt;Any clues as to the reason for this behaviour would be appreciated.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 03 Aug 2001 11:09:36 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/hp-ux-11-0-security-problem/m-p/2561242#M918541</guid>
      <dc:creator>Vinu Neelakandhan</dc:creator>
      <dc:date>2001-08-03T11:09:36Z</dc:date>
    </item>
    <item>
      <title>Re: HP-UX 11.0 security problem</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/hp-ux-11-0-security-problem/m-p/2561243#M918542</link>
      <description>Bastian:jjp /etc/default# man setgroups&lt;BR /&gt;Reformatting entry.  Wait... done&lt;BR /&gt;&lt;BR /&gt; setgroups(2)                                                   setgroups(2)&lt;BR /&gt;&lt;BR /&gt; NAME&lt;BR /&gt;      setgroups - set group access list&lt;BR /&gt;&lt;BR /&gt; SYNOPSIS&lt;BR /&gt;      #include &lt;UNISTD.H&gt;&lt;BR /&gt;&lt;BR /&gt;      int setgroups(int ngroups, const gid_t *gidset);&lt;BR /&gt;&lt;BR /&gt; DESCRIPTION&lt;BR /&gt;      setgroups() sets the group access list of the current user process&lt;BR /&gt;      according to the array gidset.  The parameter ngroups indicates the&lt;BR /&gt;      number of entries in the array and must be no more than NGROUPS_MAX,&lt;BR /&gt;      as defined in &lt;LIMITS.H&gt;.&lt;BR /&gt;&lt;BR /&gt;      Only super-user can set new groups by adding to the group access list&lt;BR /&gt;      of the current user process; any user can delete groups from it.&lt;BR /&gt; RETURN VALUE&lt;BR /&gt;      Upon successful completion, setgroups() returns 0; otherwise it&lt;BR /&gt;      returns -1 and sets errno to indicate the error.&lt;BR /&gt;&lt;BR /&gt; ERRORS&lt;BR /&gt;      setgroups() fails if any of the following conditions are encountered:&lt;BR /&gt;&lt;BR /&gt;           [EPERM]        The caller is not super-user and has attempted to&lt;BR /&gt;                          set new groups.&lt;BR /&gt;&lt;BR /&gt;           [EFAULT]       The address specified for gidset is outside the&lt;BR /&gt;                          process address space.  The reliable detection of&lt;BR /&gt;                          this error is implementation dependent.&lt;BR /&gt;&lt;BR /&gt;           [EINVAL]       ngroups is greater than NGROUPS_MAX or not&lt;BR /&gt;                          positive.&lt;BR /&gt;&lt;BR /&gt;           [EINVAL]       An entry in gidset is not a valid group ID.&lt;BR /&gt;&lt;BR /&gt; AUTHOR&lt;BR /&gt;      setgroups() was developed by the University of California, Berkeley.&lt;BR /&gt;&lt;BR /&gt;I have never had this problem or tried this, but here is a post in the tech. knowledge base:&lt;BR /&gt;PROBLEM&lt;BR /&gt;su command as non root user returns:&lt;BR /&gt;setgroups: Not owner&lt;BR /&gt;su: unable to initialize group access list. &lt;BR /&gt;RESOLUTION&lt;BR /&gt;/etc/passwd, /usr/bin/login, &amp;amp; /usr/bin/su are 755&lt;BR /&gt;Changed them to 4555 to get the suid bit set.&lt;BR /&gt;/etc/group is  bin  bin, should be  root  sys&lt;BR /&gt;&lt;BR /&gt;Hope it helps...&lt;/LIMITS.H&gt;&lt;/UNISTD.H&gt;</description>
      <pubDate>Fri, 03 Aug 2001 13:48:39 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/hp-ux-11-0-security-problem/m-p/2561243#M918542</guid>
      <dc:creator>John Payne_2</dc:creator>
      <dc:date>2001-08-03T13:48:39Z</dc:date>
    </item>
    <item>
      <title>Re: HP-UX 11.0 security problem</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/hp-ux-11-0-security-problem/m-p/2561244#M918543</link>
      <description>Hi Vinu,&lt;BR /&gt;&lt;BR /&gt;The errors your are seeing of "setgroups: Not owner" are being seen because of incorrect permission for the /usr/bin/su and /usr/bin/login executables. Make sure /usr/bin/su and /usr/bin/login are owned by user "root" and group "bin" and permissions are -r-sr-xr-x (4555).&lt;BR /&gt;To change the permissions do a (as root)&lt;BR /&gt;chmod 4555 /usr/bin/su&lt;BR /&gt;chmod 4555 /usr/bin/login&lt;BR /&gt;&lt;BR /&gt;-HTH&lt;BR /&gt;I am RU</description>
      <pubDate>Fri, 03 Aug 2001 15:23:28 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/hp-ux-11-0-security-problem/m-p/2561244#M918543</guid>
      <dc:creator>linuxfan</dc:creator>
      <dc:date>2001-08-03T15:23:28Z</dc:date>
    </item>
  </channel>
</rss>

