<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: File Trasnfer read only output in Operating System - OpenVMS</title>
    <link>https://community.hpe.com/t5/operating-system-openvms/file-trasnfer-read-only-output/m-p/4062416#M13244</link>
    <description>Graham,&lt;BR /&gt;&lt;BR /&gt;If (and ONLY IF) the "Windows PC" is running Windows NT or a derivative (e.g., Windows 2000, Windows XP, Windows 2003, or Vista), then it is possible, but more care must be exercised than is common.&lt;BR /&gt;&lt;BR /&gt;First, Ian's comment about running a cryptographic checksum (e.g., MD-5, SHA-1, or similar) is a good one. Maintaining a full copy of the file in a non-PC archive is also a requirement.&lt;BR /&gt;&lt;BR /&gt;On the PC, the Administrator accounts must be secured and not used for non-Administrative access. The file must be downloaded using FTP from one account, and the protection attributes need to be set so that no one but the file owner can modify the file (or the directories leading to it). &lt;BR /&gt;&lt;BR /&gt;Then the "normal" user must access the file from a different account, one that does not have the permissions to alter the file.&lt;BR /&gt;&lt;BR /&gt;It is possible to "lock-down" a PC platform in this way, but many, if not most, environments do not bother.&lt;BR /&gt;&lt;BR /&gt;I hope that the preceding is helpful.&lt;BR /&gt;&lt;BR /&gt;- Bob Gezelter, &lt;A href="http://www.rlgsc.com" target="_blank"&gt;http://www.rlgsc.com&lt;/A&gt;</description>
    <pubDate>Wed, 29 Aug 2007 10:17:09 GMT</pubDate>
    <dc:creator>Robert Gezelter</dc:creator>
    <dc:date>2007-08-29T10:17:09Z</dc:date>
    <item>
      <title>File Trasnfer read only output</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/file-trasnfer-read-only-output/m-p/4062414#M13242</link>
      <description>We currently run the MANMAN MRP system and sue the above to generate an EFT BACS payment file in pain text. We need to be able to transfer the above file to a Windows PC in a read only format so that it cannot be changed from the time that is saved to the PC local hard drive</description>
      <pubDate>Wed, 29 Aug 2007 09:49:35 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/file-trasnfer-read-only-output/m-p/4062414#M13242</guid>
      <dc:creator>Graham Moss</dc:creator>
      <dc:date>2007-08-29T09:49:35Z</dc:date>
    </item>
    <item>
      <title>Re: File Trasnfer read only output</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/file-trasnfer-read-only-output/m-p/4062415#M13243</link>
      <description>I think you will need some sort of checksum (e.g. md5) to ensure the file has not been changed. Any file format on the PC could be changed even if you set the protection.</description>
      <pubDate>Wed, 29 Aug 2007 10:10:55 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/file-trasnfer-read-only-output/m-p/4062415#M13243</guid>
      <dc:creator>Ian Miller.</dc:creator>
      <dc:date>2007-08-29T10:10:55Z</dc:date>
    </item>
    <item>
      <title>Re: File Trasnfer read only output</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/file-trasnfer-read-only-output/m-p/4062416#M13244</link>
      <description>Graham,&lt;BR /&gt;&lt;BR /&gt;If (and ONLY IF) the "Windows PC" is running Windows NT or a derivative (e.g., Windows 2000, Windows XP, Windows 2003, or Vista), then it is possible, but more care must be exercised than is common.&lt;BR /&gt;&lt;BR /&gt;First, Ian's comment about running a cryptographic checksum (e.g., MD-5, SHA-1, or similar) is a good one. Maintaining a full copy of the file in a non-PC archive is also a requirement.&lt;BR /&gt;&lt;BR /&gt;On the PC, the Administrator accounts must be secured and not used for non-Administrative access. The file must be downloaded using FTP from one account, and the protection attributes need to be set so that no one but the file owner can modify the file (or the directories leading to it). &lt;BR /&gt;&lt;BR /&gt;Then the "normal" user must access the file from a different account, one that does not have the permissions to alter the file.&lt;BR /&gt;&lt;BR /&gt;It is possible to "lock-down" a PC platform in this way, but many, if not most, environments do not bother.&lt;BR /&gt;&lt;BR /&gt;I hope that the preceding is helpful.&lt;BR /&gt;&lt;BR /&gt;- Bob Gezelter, &lt;A href="http://www.rlgsc.com" target="_blank"&gt;http://www.rlgsc.com&lt;/A&gt;</description>
      <pubDate>Wed, 29 Aug 2007 10:17:09 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/file-trasnfer-read-only-output/m-p/4062416#M13244</guid>
      <dc:creator>Robert Gezelter</dc:creator>
      <dc:date>2007-08-29T10:17:09Z</dc:date>
    </item>
    <item>
      <title>Re: File Trasnfer read only output</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/file-trasnfer-read-only-output/m-p/4062417#M13245</link>
      <description>I might well be reading too much into this, but then most folks I've met that are running an EFT tend to be at least somewhat paranoid.&lt;BR /&gt;&lt;BR /&gt;What or who are you protecting against?  &lt;BR /&gt;&lt;BR /&gt;How serious are the potential attacks?&lt;BR /&gt;&lt;BR /&gt;What happens if the data gets changed; how is this (mis)information to be fed back into the system?&lt;BR /&gt;&lt;BR /&gt;You can detect changes (using MD5), but viewable exporting data with security requirements -- with content protection -- is a difficult task, at best.  This can include up to the level of difficulty that the ACS and AACS content protection systems are encountering.&lt;BR /&gt;&lt;BR /&gt;I'd probably look to use a password-protected encrypted PDF here for the general case, but that's probably not going to operate all that well with whatever is planning to read this EFT BACS format.&lt;BR /&gt;&lt;BR /&gt;I might well also look to transfer the file over using https transfer, possibly with an encrypted zip.&lt;BR /&gt;&lt;BR /&gt;I'd probably reverse this, and determine the attacks, and what might be the appropriate storage on Windows, and see if I could figure out how to get there from OpenVMS.  If it is straight ASCII text file with Windows file protections, for instance...  Or if a read-only PDF or content-protection is required, etc...&lt;BR /&gt;&lt;BR /&gt;And if you're looking for help securing a data file on a Windows system, you're probably not in the best available forum.&lt;BR /&gt;</description>
      <pubDate>Wed, 29 Aug 2007 10:48:22 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/file-trasnfer-read-only-output/m-p/4062417#M13245</guid>
      <dc:creator>Hoff</dc:creator>
      <dc:date>2007-08-29T10:48:22Z</dc:date>
    </item>
    <item>
      <title>Re: File Trasnfer read only output</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/file-trasnfer-read-only-output/m-p/4062418#M13246</link>
      <description>Rather than transfer the EFT file to a PC, we always place the file in a shared VMS directory (folder.) Using access restrictions, no PC user can change the file and the only user allowed access to the share (other than the administrator) is the responsible person who uploads or transmits the file.&lt;BR /&gt;&lt;BR /&gt;Since the EFT file probably has a standard format requirement, adding any embedded checksum data might not be feasible (depending on the format, you might have a user-defined field available in a header or trailer record) and adding an embedded checksum or even a secondary checksum file won't help unless all of the programs use it.&lt;BR /&gt;</description>
      <pubDate>Wed, 29 Aug 2007 14:09:17 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/file-trasnfer-read-only-output/m-p/4062418#M13246</guid>
      <dc:creator>Doug Phillips</dc:creator>
      <dc:date>2007-08-29T14:09:17Z</dc:date>
    </item>
    <item>
      <title>Re: File Trasnfer read only output</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/file-trasnfer-read-only-output/m-p/4062419#M13247</link>
      <description>Had the auditors in again?&lt;BR /&gt;About the only method that cannot be subverted is to burn to cd &lt;BR /&gt;Phil</description>
      <pubDate>Thu, 30 Aug 2007 03:32:34 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/file-trasnfer-read-only-output/m-p/4062419#M13247</guid>
      <dc:creator>Phil.Howell</dc:creator>
      <dc:date>2007-08-30T03:32:34Z</dc:date>
    </item>
    <item>
      <title>Re: File Trasnfer read only output</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/file-trasnfer-read-only-output/m-p/4062420#M13248</link>
      <description>Have you considered converting the file into a read-only format like recent PDF versions?&lt;BR /&gt;IIRC, we've done that on OpenVMS but I cannot recall the tooling. Otherwise, you could think of a program to receive the file and do teh conversion.</description>
      <pubDate>Fri, 31 Aug 2007 01:27:01 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/file-trasnfer-read-only-output/m-p/4062420#M13248</guid>
      <dc:creator>Willem Grooters</dc:creator>
      <dc:date>2007-08-31T01:27:01Z</dc:date>
    </item>
    <item>
      <title>Re: File Trasnfer read only output</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/file-trasnfer-read-only-output/m-p/4062421#M13249</link>
      <description>EFT files usually have a format specified by some standard; I'm familiar with ACH, but there are others. The format is dictated by whatever intermediary is receiving and processing the file. Because the file's subject is the transfer of money, and the intermediary is usually a bank, the format is understandably very strict. Most that I know of require ASCII text.&lt;BR /&gt;</description>
      <pubDate>Fri, 31 Aug 2007 12:51:25 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/file-trasnfer-read-only-output/m-p/4062421#M13249</guid>
      <dc:creator>Doug Phillips</dc:creator>
      <dc:date>2007-08-31T12:51:25Z</dc:date>
    </item>
    <item>
      <title>Re: File Trasnfer read only output</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/file-trasnfer-read-only-output/m-p/4062422#M13250</link>
      <description>The format is dictated by whatever intermediary is receiving and processing the file, in this case BACS. I'm more familiar with ACH requirements but I suspect they're similar because they communicate with the same organizations.&lt;BR /&gt;&lt;BR /&gt;Because the file's subject is the transfer of money, and the communication is usually routed to a bank, the format is understandably very strict. Most that I know of use ASCII text.&lt;BR /&gt;</description>
      <pubDate>Fri, 31 Aug 2007 13:05:23 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/file-trasnfer-read-only-output/m-p/4062422#M13250</guid>
      <dc:creator>Doug Phillips</dc:creator>
      <dc:date>2007-08-31T13:05:23Z</dc:date>
    </item>
    <item>
      <title>Re: File Trasnfer read only output</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/file-trasnfer-read-only-output/m-p/4062423#M13251</link>
      <description>Darn ITRC. The first post hung and didn't show up so I tried again. Please ignore the first post.&lt;BR /&gt;</description>
      <pubDate>Fri, 31 Aug 2007 13:08:20 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/file-trasnfer-read-only-output/m-p/4062423#M13251</guid>
      <dc:creator>Doug Phillips</dc:creator>
      <dc:date>2007-08-31T13:08:20Z</dc:date>
    </item>
    <item>
      <title>Re: File Trasnfer read only output</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/file-trasnfer-read-only-output/m-p/4062424#M13252</link>
      <description>formats like PDF are not read only if you use a binary file editor :-)&lt;BR /&gt;&lt;BR /&gt;A sha1 checksum and/or write once media are needed.</description>
      <pubDate>Fri, 31 Aug 2007 14:45:14 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/file-trasnfer-read-only-output/m-p/4062424#M13252</guid>
      <dc:creator>Ian Miller.</dc:creator>
      <dc:date>2007-08-31T14:45:14Z</dc:date>
    </item>
    <item>
      <title>Re: File Trasnfer read only output</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/file-trasnfer-read-only-output/m-p/4062425#M13253</link>
      <description>Even a read-only file (or anything that can be displayed on a PC's screen) can be copied, changed and sent instead of the original.&lt;BR /&gt;&lt;BR /&gt;It really comes down to making sure only trusted persons can access the file at all, and implementing procedures that insure that trust is maintained. &lt;BR /&gt;&lt;BR /&gt;Religiously monitoring your bank-account balance, and/or using a special bank account for EFT's are common methods.&lt;BR /&gt;</description>
      <pubDate>Fri, 31 Aug 2007 15:31:59 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/file-trasnfer-read-only-output/m-p/4062425#M13253</guid>
      <dc:creator>Doug Phillips</dc:creator>
      <dc:date>2007-08-31T15:31:59Z</dc:date>
    </item>
    <item>
      <title>Re: File Trasnfer read only output</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/file-trasnfer-read-only-output/m-p/4062426#M13254</link>
      <description>formats like PDF are not read only if you use the right editor :-)&lt;BR /&gt;&lt;BR /&gt;A sha1 checksum and/or write once media are needed.</description>
      <pubDate>Fri, 31 Aug 2007 15:50:56 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/file-trasnfer-read-only-output/m-p/4062426#M13254</guid>
      <dc:creator>Ian Miller.</dc:creator>
      <dc:date>2007-08-31T15:50:56Z</dc:date>
    </item>
  </channel>
</rss>

