<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Root password is disabling continuously in Operating System - Linux</title>
    <link>https://community.hpe.com/t5/operating-system-linux/root-password-is-disabling-continuously/m-p/4013247#M28596</link>
    <description>You may increase the the number of bad login atempt to 5. Check for any scripts whihc runs/executes from a remote server(me:-g main/infrastructer server  from where we push some thing to all other nodes.</description>
    <pubDate>Tue, 05 Jun 2007 20:07:50 GMT</pubDate>
    <dc:creator>skt_skt</dc:creator>
    <dc:date>2007-06-05T20:07:50Z</dc:date>
    <item>
      <title>Root password is disabling continuously</title>
      <link>https://community.hpe.com/t5/operating-system-linux/root-password-is-disabling-continuously/m-p/4013242#M28591</link>
      <description>When i tried to connect our server remotely it is showing the below message.&lt;BR /&gt;-------------------&lt;BR /&gt;login: root&lt;BR /&gt;Password:&lt;BR /&gt;Account is disabled - see Account Administrator&lt;BR /&gt;&lt;BR /&gt;Wait for login exit: ..&lt;BR /&gt;Connection closed by foreign host.&lt;BR /&gt;--------------------------------------------&lt;BR /&gt;When i tried to connect our server remotely it is showing the below message.&lt;BR /&gt;-------------------&lt;BR /&gt;login: root&lt;BR /&gt;Password:&lt;BR /&gt;Account is disabled - see Account Administrator&lt;BR /&gt;&lt;BR /&gt;Wait for login exit: ..&lt;BR /&gt;Connection closed by foreign host.&lt;BR /&gt;---------------------&lt;BR /&gt;&lt;BR /&gt;# /usr/lbin/modprpw -k root&lt;BR /&gt;&lt;BR /&gt;I am able to enable with the above command with rootb(same as root)but after next day its again disabled.The server is located at some other location.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Can you suggest me the permanent solution.&lt;BR /&gt;</description>
      <pubDate>Tue, 05 Jun 2007 05:49:02 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/root-password-is-disabling-continuously/m-p/4013242#M28591</guid>
      <dc:creator>csreenivas</dc:creator>
      <dc:date>2007-06-05T05:49:02Z</dc:date>
    </item>
    <item>
      <title>Re: Root password is disabling continuously</title>
      <link>https://community.hpe.com/t5/operating-system-linux/root-password-is-disabling-continuously/m-p/4013243#M28592</link>
      <description>Shalom,&lt;BR /&gt;&lt;BR /&gt;You have posted to Linux. oops. This is an HP-UX problem.&lt;BR /&gt;&lt;BR /&gt;I'm guessing because my crystal ball is working that you have a trusted system and the number of bad logins to disable the root account is the default, three.&lt;BR /&gt;&lt;BR /&gt;Your root account is being disabled due to bad logins.&lt;BR /&gt;&lt;BR /&gt;lastb&lt;BR /&gt;&lt;BR /&gt;Find the source of the bad logins and stop it.&lt;BR /&gt;&lt;BR /&gt;You may need to use a firewall to stop the bad logins. A console login will re-enable the root account.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Tue, 05 Jun 2007 08:37:32 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/root-password-is-disabling-continuously/m-p/4013243#M28592</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2007-06-05T08:37:32Z</dc:date>
    </item>
    <item>
      <title>Re: Root password is disabling continuously</title>
      <link>https://community.hpe.com/t5/operating-system-linux/root-password-is-disabling-continuously/m-p/4013244#M28593</link>
      <description>As usual, SEP is completely correct. HP-UX Trusted Mode et. al.&lt;BR /&gt;&lt;BR /&gt;I wanted to respond to make a suggestion. Since we are running all our HP-UX systems in Trusted Mode, I saw this event quite frequently. All though we tracked down various services and such attempting root login, it persisted and was becoming a real problem. If you can't log in as root, you could have a serious problem, especially with a headless system. Our biggest production systems all have consoles and all of our systems have network connected GSP's, so it may not seem like much of an issue. We gave the few administrators SUDO access to the 'modprpw' command, but we ended up turning the "lock after x attempts" off for root user. We have other security provisions in place (firewall (hard and soft), TCP Wrappers, etc.) to keep malicious users at bay. We felt the small risk is worth the larger risk of having root locked out of the system.</description>
      <pubDate>Tue, 05 Jun 2007 11:23:08 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/root-password-is-disabling-continuously/m-p/4013244#M28593</guid>
      <dc:creator>Tony Berry</dc:creator>
      <dc:date>2007-06-05T11:23:08Z</dc:date>
    </item>
    <item>
      <title>Re: Root password is disabling continuously</title>
      <link>https://community.hpe.com/t5/operating-system-linux/root-password-is-disabling-continuously/m-p/4013245#M28594</link>
      <description>Side note:&lt;BR /&gt;&lt;BR /&gt;Trusted systems is being weeded out by HP. You should look into installing SMSE. You need to be running 11iv2 or later in order to install/use the product. It's probably already installed by default on 11iv3. You can download it from &lt;A href="http://software.hp.com." target="_blank"&gt;http://software.hp.com.&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 05 Jun 2007 12:18:34 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/root-password-is-disabling-continuously/m-p/4013245#M28594</guid>
      <dc:creator>Court Campbell</dc:creator>
      <dc:date>2007-06-05T12:18:34Z</dc:date>
    </item>
    <item>
      <title>Re: Root password is disabling continuously</title>
      <link>https://community.hpe.com/t5/operating-system-linux/root-password-is-disabling-continuously/m-p/4013246#M28595</link>
      <description>Shalom,&lt;BR /&gt;&lt;BR /&gt;It is not unreasonable to set a limit of 3 logins before disabling root.&lt;BR /&gt;&lt;BR /&gt;If its an actual person, then you really don't want to give them extra chances to hack your system. True Trusted system is going away but that is no reason to lower security if you don't want to.&lt;BR /&gt;&lt;BR /&gt;Suspects:&lt;BR /&gt;1) Cron scripts from other systems. Should show up in /var/adm/syslog/syslog.log&lt;BR /&gt;2) cron scripts on this system from non-root users.&lt;BR /&gt;3) Actual users.&lt;BR /&gt;&lt;BR /&gt;Make sure inetd -l is run for enhanced logging.&lt;BR /&gt;&lt;BR /&gt;This commonly occurs in Internet exposed systems. Can you post your lastb output? That might help track this down.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Tue, 05 Jun 2007 12:23:16 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/root-password-is-disabling-continuously/m-p/4013246#M28595</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2007-06-05T12:23:16Z</dc:date>
    </item>
    <item>
      <title>Re: Root password is disabling continuously</title>
      <link>https://community.hpe.com/t5/operating-system-linux/root-password-is-disabling-continuously/m-p/4013247#M28596</link>
      <description>You may increase the the number of bad login atempt to 5. Check for any scripts whihc runs/executes from a remote server(me:-g main/infrastructer server  from where we push some thing to all other nodes.</description>
      <pubDate>Tue, 05 Jun 2007 20:07:50 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/root-password-is-disabling-continuously/m-p/4013247#M28596</guid>
      <dc:creator>skt_skt</dc:creator>
      <dc:date>2007-06-05T20:07:50Z</dc:date>
    </item>
    <item>
      <title>Re: Root password is disabling continuously</title>
      <link>https://community.hpe.com/t5/operating-system-linux/root-password-is-disabling-continuously/m-p/4013248#M28597</link>
      <description>Look at &lt;BR /&gt;&lt;BR /&gt;# lastb -R&lt;BR /&gt;&lt;BR /&gt;this should give you a good idea of where to start looking. You can then know if the logins are local or remote. Also look at /var/adm/sulog. You can see who is trying to su to root. Just a couple of places to start.</description>
      <pubDate>Wed, 06 Jun 2007 09:13:02 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/root-password-is-disabling-continuously/m-p/4013248#M28597</guid>
      <dc:creator>Court Campbell</dc:creator>
      <dc:date>2007-06-06T09:13:02Z</dc:date>
    </item>
    <item>
      <title>Re: Root password is disabling continuously</title>
      <link>https://community.hpe.com/t5/operating-system-linux/root-password-is-disabling-continuously/m-p/4013249#M28598</link>
      <description>I didnt see anything special in lastb -R and /var/adm/sulog.&lt;BR /&gt;I guess this is because of password expiry and I executed the below command.&lt;BR /&gt;&lt;BR /&gt;/usr/lbin/modprpw -m mintm=0 root</description>
      <pubDate>Thu, 07 Jun 2007 07:14:06 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/root-password-is-disabling-continuously/m-p/4013249#M28598</guid>
      <dc:creator>csreenivas</dc:creator>
      <dc:date>2007-06-07T07:14:06Z</dc:date>
    </item>
    <item>
      <title>Re: Root password is disabling continuously</title>
      <link>https://community.hpe.com/t5/operating-system-linux/root-password-is-disabling-continuously/m-p/4013250#M28599</link>
      <description>Again it is showing as Account disabled.&lt;BR /&gt;I didnt see anything in lastb -R&lt;BR /&gt;I guess it is not because of failure logins.&lt;BR /&gt;&lt;BR /&gt;Do we get something with the below information?&lt;BR /&gt;#/usr/lbin/getprpw root&lt;BR /&gt;uid=0, bootpw=YES, audid=0, audflg=1, mintm=0, maxpwln=-1, exptm=-1, lftm=-1, spwchg=Tue May 29 14:53:37 2007, upwchg=-1, acctexp=-1, llog=-1, expwarn=0, usrpick=DFT, syspnpw=DFT, rstrpw=DFT, nullpw=DFT, admnum=-1, syschpw=DFT, sysltpw=DFT, timeod=-1, slogint=Thu Jun  7 05:51:30 2007, ulogint=Thu Jun  7 05:50:44 2007, sloginy=pts/ta, culogin=-1, uloginy=-1, umaxlntr=-1, alock=NO, lockout=0000000&lt;BR /&gt;</description>
      <pubDate>Thu, 07 Jun 2007 07:57:10 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/root-password-is-disabling-continuously/m-p/4013250#M28599</guid>
      <dc:creator>csreenivas</dc:creator>
      <dc:date>2007-06-07T07:57:10Z</dc:date>
    </item>
    <item>
      <title>Re: Root password is disabling continuously</title>
      <link>https://community.hpe.com/t5/operating-system-linux/root-password-is-disabling-continuously/m-p/4013251#M28600</link>
      <description>Shalom,&lt;BR /&gt;&lt;BR /&gt;I think I have an idea. We had a user in Chicago, my department head whose user kept mysteriously expiring, well before the expiration date.&lt;BR /&gt;&lt;BR /&gt;Seems that the trusted system rules for this user and only this user were wrong.&lt;BR /&gt;&lt;BR /&gt;I had to use same to open up the user and found something stupid like the aging policy was set to 7 days or something like that. I've had similar stuff happen to root because there is a data conversion involving trusted systems and its very good, but not perfect.&lt;BR /&gt;&lt;BR /&gt;Take a look at the root user security setting in sam, you may find something.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Thu, 07 Jun 2007 08:23:19 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/root-password-is-disabling-continuously/m-p/4013251#M28600</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2007-06-07T08:23:19Z</dc:date>
    </item>
    <item>
      <title>Re: Root password is disabling continuously</title>
      <link>https://community.hpe.com/t5/operating-system-linux/root-password-is-disabling-continuously/m-p/4013252#M28601</link>
      <description>What are you using to connect to the box? SSH?&lt;BR /&gt;&lt;BR /&gt;The alock=NO, lockout=0000000 is telling me that the account is not locked. man getprpw to find out what the lockout fields mean.</description>
      <pubDate>Thu, 07 Jun 2007 08:55:02 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/root-password-is-disabling-continuously/m-p/4013252#M28601</guid>
      <dc:creator>Court Campbell</dc:creator>
      <dc:date>2007-06-07T08:55:02Z</dc:date>
    </item>
    <item>
      <title>Re: Root password is disabling continuously</title>
      <link>https://community.hpe.com/t5/operating-system-linux/root-password-is-disabling-continuously/m-p/4013253#M28602</link>
      <description>We used to connect through telnet.&lt;BR /&gt;&lt;BR /&gt;As of now its not locked but it is getting locked within few hours.</description>
      <pubDate>Thu, 07 Jun 2007 08:58:31 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/root-password-is-disabling-continuously/m-p/4013253#M28602</guid>
      <dc:creator>csreenivas</dc:creator>
      <dc:date>2007-06-07T08:58:31Z</dc:date>
    </item>
    <item>
      <title>Re: Root password is disabling continuously</title>
      <link>https://community.hpe.com/t5/operating-system-linux/root-password-is-disabling-continuously/m-p/4013254#M28603</link>
      <description>next time the account is locked, look at the getprpw command and see what the lockout fields are. What do you mean by you didn't anything with lastb -R? &lt;BR /&gt;&lt;BR /&gt;Also, what did you see in /var/adm/sulog? If the fourth filed is a - (minus sign) then that means someone had an su to a user.&lt;BR /&gt;&lt;BR /&gt;ex.&lt;BR /&gt;&lt;BR /&gt;SU 06/07 09:11 - 0 badboy-root&lt;BR /&gt;&lt;BR /&gt;this tells me that badboy was unsuccessful as su'ing to root at 9:11 today.</description>
      <pubDate>Thu, 07 Jun 2007 09:12:47 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/root-password-is-disabling-continuously/m-p/4013254#M28603</guid>
      <dc:creator>Court Campbell</dc:creator>
      <dc:date>2007-06-07T09:12:47Z</dc:date>
    </item>
    <item>
      <title>Re: Root password is disabling continuously</title>
      <link>https://community.hpe.com/t5/operating-system-linux/root-password-is-disabling-continuously/m-p/4013255#M28604</link>
      <description>Have you thought about setting up HIDS. It's rather easy to implement. It can be setup to log unsuccessful logins and much more. Pluses are that it is a freebie and it's supported by HP.</description>
      <pubDate>Thu, 07 Jun 2007 09:23:55 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/root-password-is-disabling-continuously/m-p/4013255#M28604</guid>
      <dc:creator>Court Campbell</dc:creator>
      <dc:date>2007-06-07T09:23:55Z</dc:date>
    </item>
    <item>
      <title>Re: Root password is disabling continuously</title>
      <link>https://community.hpe.com/t5/operating-system-linux/root-password-is-disabling-continuously/m-p/4013256#M28605</link>
      <description>Please find the information when the root password is locked&lt;BR /&gt;&lt;BR /&gt;# /usr/lbin/getprpw root&lt;BR /&gt;uid=0, bootpw=YES, audid=0, audflg=1, mintm=0, maxpwln=-1, exptm=-1, lftm=-1, spwchg=Tue May 29 14:53:37 2007, upwchg=-1, acctexp=-1, llog=-1, expwarn=0, usrpick=DFT, syspnpw=DFT, rstrpw=DFT, nullpw=DFT, admnum=-1, syschpw=DFT, sysltpw=DFT, timeod=-1, slogint=Thu Jun  7 05:51:30 2007, ulogint=Thu Jun  7 07:42:49 2007, sloginy=pts/ta, culogin=7, uloginy=-1, umaxlntr=-1, alock=NO, lockout=0001000&lt;BR /&gt;</description>
      <pubDate>Thu, 07 Jun 2007 09:44:52 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/root-password-is-disabling-continuously/m-p/4013256#M28605</guid>
      <dc:creator>csreenivas</dc:creator>
      <dc:date>2007-06-07T09:44:52Z</dc:date>
    </item>
    <item>
      <title>Re: Root password is disabling continuously</title>
      <link>https://community.hpe.com/t5/operating-system-linux/root-password-is-disabling-continuously/m-p/4013257#M28606</link>
      <description>Not that you didn't already know this, but that fourth field set to 1 in lockout means that root has exceeded unsuccessful login attempts. Again you need to look at the sulog and lastb, etc. to see who is causing the issue.</description>
      <pubDate>Thu, 07 Jun 2007 09:52:37 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/root-password-is-disabling-continuously/m-p/4013257#M28606</guid>
      <dc:creator>Court Campbell</dc:creator>
      <dc:date>2007-06-07T09:52:37Z</dc:date>
    </item>
    <item>
      <title>Re: Root password is disabling continuously</title>
      <link>https://community.hpe.com/t5/operating-system-linux/root-password-is-disabling-continuously/m-p/4013258#M28607</link>
      <description>please find lastb and sulog. srinu is my userid.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;# lastb&lt;BR /&gt;sybase   pts/ta       Fri Jun  1 05:32&lt;BR /&gt;sybase   pts/ta       Fri Jun  1 05:32&lt;BR /&gt;sybase   pts/ta       Fri Jun  1 03:34&lt;BR /&gt;&lt;BR /&gt;/var/adm/sulog&lt;BR /&gt;SU 06/05 03:13 - ta srinu-root&lt;BR /&gt;SU 06/05 03:13 + ta srinu-rootb&lt;BR /&gt;SU 06/05 03:15 + ta srinu-root&lt;BR /&gt;SU 06/06 02:59 - ta srinu-root&lt;BR /&gt;SU 06/06 02:59 + ta srinu-rootb&lt;BR /&gt;SU 06/06 03:00 + ta srinu-root&lt;BR /&gt;SU 06/06 05:18 + ta srinu-root&lt;BR /&gt;SU 06/07 02:21 - ta srinu-root&lt;BR /&gt;SU 06/07 02:22 + ta srinu-rootb&lt;BR /&gt;SU 06/07 02:26 + ta srinu-root&lt;BR /&gt;SU 06/07 05:50 - ta srinu-root&lt;BR /&gt;SU 06/07 05:51 + ta srinu-rootb&lt;BR /&gt;SU 06/07 05:51 + ta srinu-root&lt;BR /&gt;SU 06/07 07:42 - ta srinu-root&lt;BR /&gt;SU 06/07 07:43 + ta srinu-rootb&lt;BR /&gt;</description>
      <pubDate>Thu, 07 Jun 2007 10:03:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/root-password-is-disabling-continuously/m-p/4013258#M28607</guid>
      <dc:creator>csreenivas</dc:creator>
      <dc:date>2007-06-07T10:03:21Z</dc:date>
    </item>
    <item>
      <title>Re: Root password is disabling continuously</title>
      <link>https://community.hpe.com/t5/operating-system-linux/root-password-is-disabling-continuously/m-p/4013259#M28608</link>
      <description>Its getting enabled when I connect from rootb&lt;BR /&gt;(same as root) and switch to root</description>
      <pubDate>Thu, 07 Jun 2007 10:26:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/root-password-is-disabling-continuously/m-p/4013259#M28608</guid>
      <dc:creator>csreenivas</dc:creator>
      <dc:date>2007-06-07T10:26:21Z</dc:date>
    </item>
    <item>
      <title>Re: Root password is disabling continuously</title>
      <link>https://community.hpe.com/t5/operating-system-linux/root-password-is-disabling-continuously/m-p/4013260#M28609</link>
      <description>Do you have something like HP SIM set up trying to connect via wbem?  If you have that set up, and the wbem root pw is wrong, you would see this sort of thing.&lt;BR /&gt;&lt;BR /&gt;John</description>
      <pubDate>Thu, 07 Jun 2007 10:40:56 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/root-password-is-disabling-continuously/m-p/4013260#M28609</guid>
      <dc:creator>John Payne_2</dc:creator>
      <dc:date>2007-06-07T10:40:56Z</dc:date>
    </item>
    <item>
      <title>Re: Root password is disabling continuously</title>
      <link>https://community.hpe.com/t5/operating-system-linux/root-password-is-disabling-continuously/m-p/4013261#M28610</link>
      <description>Looks like you helped lock the account&lt;BR /&gt;&lt;BR /&gt;getprpw&lt;BR /&gt;ulogint=Thu Jun 7 07:42:49 2007&lt;BR /&gt;&lt;BR /&gt;sulog&lt;BR /&gt;SU 06/07 07:42 - ta srinu-root&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 07 Jun 2007 11:05:53 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/root-password-is-disabling-continuously/m-p/4013261#M28610</guid>
      <dc:creator>Court Campbell</dc:creator>
      <dc:date>2007-06-07T11:05:53Z</dc:date>
    </item>
  </channel>
</rss>

