<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Paranoid security, bypass resetting password expiry in Secure OS Software for Linux</title>
    <link>https://community.hpe.com/t5/secure-os-software-for-linux/paranoid-security-bypass-resetting-password-expiry/m-p/3062678#M284</link>
    <description>The real answer is to get rid of paranoid security and become active in setting security yourself. Its harder, but the process will improve your skills and allow you to avoid circumstances like this.&lt;BR /&gt;&lt;BR /&gt;You might find using Bastille gives you better control.&lt;BR /&gt;&lt;BR /&gt;With regards to this issue, it may take another password cycle for your change to kick in.&lt;BR /&gt;&lt;BR /&gt;If the password life cycle is 30 days and you extend it, it probably requires a passwd command against that user.&lt;BR /&gt;&lt;BR /&gt;The GUI interface that comes with Mandrake should do that for you.&lt;BR /&gt;&lt;BR /&gt;In the end, there is a price for security, you have to balance that against your sanity.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
    <pubDate>Wed, 03 Sep 2003 14:41:41 GMT</pubDate>
    <dc:creator>Steven E. Protter</dc:creator>
    <dc:date>2003-09-03T14:41:41Z</dc:date>
    <item>
      <title>Paranoid security, bypass resetting password expiry</title>
      <link>https://community.hpe.com/t5/secure-os-software-for-linux/paranoid-security-bypass-resetting-password-expiry/m-p/3062677#M283</link>
      <description>Hello again,&lt;BR /&gt;&lt;BR /&gt;"msec", I assume, is again giving me grief.&lt;BR /&gt;We are running Mandrake 9 with paranoid security (level 5).&lt;BR /&gt;The passwprd expiry period gets reset to default (30 days) even after I have extended it for selected users.&lt;BR /&gt;&lt;BR /&gt;This is really annoying as some users may not log on for extended periods and therefore never get the warning and become unable to log on (me included).&lt;BR /&gt;&lt;BR /&gt;Does anyone know how to overide this feature?&lt;BR /&gt;&lt;BR /&gt;Thanks</description>
      <pubDate>Wed, 03 Sep 2003 14:34:29 GMT</pubDate>
      <guid>https://community.hpe.com/t5/secure-os-software-for-linux/paranoid-security-bypass-resetting-password-expiry/m-p/3062677#M283</guid>
      <dc:creator>Raynald Boucher</dc:creator>
      <dc:date>2003-09-03T14:34:29Z</dc:date>
    </item>
    <item>
      <title>Re: Paranoid security, bypass resetting password expiry</title>
      <link>https://community.hpe.com/t5/secure-os-software-for-linux/paranoid-security-bypass-resetting-password-expiry/m-p/3062678#M284</link>
      <description>The real answer is to get rid of paranoid security and become active in setting security yourself. Its harder, but the process will improve your skills and allow you to avoid circumstances like this.&lt;BR /&gt;&lt;BR /&gt;You might find using Bastille gives you better control.&lt;BR /&gt;&lt;BR /&gt;With regards to this issue, it may take another password cycle for your change to kick in.&lt;BR /&gt;&lt;BR /&gt;If the password life cycle is 30 days and you extend it, it probably requires a passwd command against that user.&lt;BR /&gt;&lt;BR /&gt;The GUI interface that comes with Mandrake should do that for you.&lt;BR /&gt;&lt;BR /&gt;In the end, there is a price for security, you have to balance that against your sanity.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Wed, 03 Sep 2003 14:41:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/secure-os-software-for-linux/paranoid-security-bypass-resetting-password-expiry/m-p/3062678#M284</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2003-09-03T14:41:41Z</dc:date>
    </item>
    <item>
      <title>Re: Paranoid security, bypass resetting password expiry</title>
      <link>https://community.hpe.com/t5/secure-os-software-for-linux/paranoid-security-bypass-resetting-password-expiry/m-p/3062679#M285</link>
      <description>Thanks Steve&lt;BR /&gt;&lt;BR /&gt;I'm told we are using this security scheme for this application due to the sensitivity of the information and to use a mixture of security setups so that if one is breached, the others will remain unknown...&lt;BR /&gt;&lt;BR /&gt;Anyway, I found a reference to "no_password_aging_for(name)" in the msec directories.  This tells me there is a bypass process and that it's probly driven by a control file. &lt;BR /&gt;&lt;BR /&gt;I'm looking for which one, and the format of the control entry.  The source is there but I don't know how to interpret Python code.&lt;BR /&gt;&lt;BR /&gt;Take care.</description>
      <pubDate>Wed, 03 Sep 2003 15:49:53 GMT</pubDate>
      <guid>https://community.hpe.com/t5/secure-os-software-for-linux/paranoid-security-bypass-resetting-password-expiry/m-p/3062679#M285</guid>
      <dc:creator>Raynald Boucher</dc:creator>
      <dc:date>2003-09-03T15:49:53Z</dc:date>
    </item>
    <item>
      <title>Re: Paranoid security, bypass resetting password expiry</title>
      <link>https://community.hpe.com/t5/secure-os-software-for-linux/paranoid-security-bypass-resetting-password-expiry/m-p/3062680#M286</link>
      <description>Hello&lt;BR /&gt;&lt;BR /&gt;I dont use msec, I did a search from google and ended up in mandrake, there I found the following&lt;BR /&gt;&lt;BR /&gt;I am passing it on perhaps, this could proof usefull !?&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.google.com/search?hl=en&amp;amp;lr=lang_en&amp;amp;ie=ISO-8859-1&amp;amp;oe=ISO-8859-1&amp;amp;q=no_password_aging_for&amp;amp;btnG=Google+Search&amp;amp;lr=lang_en" target="_blank"&gt;http://www.google.com/search?hl=en&amp;amp;lr=lang_en&amp;amp;ie=ISO-8859-1&amp;amp;oe=ISO-8859-1&amp;amp;q=no_password_aging_for&amp;amp;btnG=Google+Search&amp;amp;lr=lang_en&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Jean-Pierre</description>
      <pubDate>Thu, 04 Sep 2003 07:53:05 GMT</pubDate>
      <guid>https://community.hpe.com/t5/secure-os-software-for-linux/paranoid-security-bypass-resetting-password-expiry/m-p/3062680#M286</guid>
      <dc:creator>Huc_1</dc:creator>
      <dc:date>2003-09-04T07:53:05Z</dc:date>
    </item>
    <item>
      <title>Re: Paranoid security, bypass resetting password expiry</title>
      <link>https://community.hpe.com/t5/secure-os-software-for-linux/paranoid-security-bypass-resetting-password-expiry/m-p/3062681#M287</link>
      <description>Hi me , again ! ... I had a bite of time to read the links ....I mention here above !&lt;BR /&gt;&lt;BR /&gt;In one of them I found &lt;BR /&gt;&lt;BR /&gt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt; cut from link" &amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&lt;BR /&gt;&lt;BR /&gt;no_password_aging_for('toto') in level.local ineffective&lt;BR /&gt;&lt;BR /&gt;    * From: [bret]&lt;BR /&gt;    * Subject: [Cooker] [Bug 1629] [msec] msec no_password_aging_for('toto') in level.local ineffective&lt;BR /&gt;    * Date: Mon, 28 Jul 2003 07:06:33 -0700 &lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://qa.mandrakesoft.com/show_bug.cgi?id=1629" target="_blank"&gt;http://qa.mandrakesoft.com/show_bug.cgi?id=1629&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;------- Additional Comments From [EMAIL PROTECTED]  2003-28-07 17:37 -------&lt;BR /&gt;One thing to keep in mind with password aging is if you disabled the password  &lt;BR /&gt;aging after you set up the user, the shadow file will still have the setting &lt;BR /&gt;in it.  &lt;BR /&gt;  &lt;BR /&gt;To disable the aging after you setup your level.local run this command:  &lt;BR /&gt;"chage -M 99999 'username'".  &lt;BR /&gt;  &lt;BR /&gt;That should fix your aging and it will not be re-enabled again by msec.  &lt;BR /&gt;  &lt;BR /&gt;Now I have now idea if msec should do this if you add the entries above to &lt;BR /&gt;your level.local or not.  &lt;BR /&gt;  &lt;BR /&gt;  &lt;BR /&gt;Bret. &lt;BR /&gt;&lt;BR /&gt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt; end_of_cut &amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&lt;BR /&gt;&lt;BR /&gt;I had a look at this tool ... not bad, But I am  more inclined to checking/reading lock and using standart iptables, bastille, find it is the best way for me to know what's going on , Having said' this I am lucky to be able to decide this myself.&lt;BR /&gt;&lt;BR /&gt;Hope this will help you with this problem.&lt;BR /&gt;&lt;BR /&gt;Jean-Pierre or J-P (shorter version).&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 04 Sep 2003 11:47:20 GMT</pubDate>
      <guid>https://community.hpe.com/t5/secure-os-software-for-linux/paranoid-security-bypass-resetting-password-expiry/m-p/3062681#M287</guid>
      <dc:creator>Huc_1</dc:creator>
      <dc:date>2003-09-04T11:47:20Z</dc:date>
    </item>
  </channel>
</rss>

