<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSH and ACME in Operating System - OpenVMS</title>
    <link>https://community.hpe.com/t5/operating-system-openvms/ssh-and-acme/m-p/5098921#M56259</link>
    <description>Volker,&lt;BR /&gt;Many thanks. That's exactly the entry I was after. Somehow I missed it with whatever keywords I was trying.&lt;BR /&gt;&lt;BR /&gt;Art,&lt;BR /&gt;I don't see how this can help me if SSH does not use the right hooks.&lt;BR /&gt;&lt;BR /&gt;Edwin</description>
    <pubDate>Thu, 20 Mar 2008 12:04:09 GMT</pubDate>
    <dc:creator>Edwin Gersbach_2</dc:creator>
    <dc:date>2008-03-20T12:04:09Z</dc:date>
    <item>
      <title>SSH and ACME</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/ssh-and-acme/m-p/5098918#M56256</link>
      <description>I've got the task to analyze the efford required and the impact of a change from UAF authentication to ACME authentication against our AD domain. With about 100 UAF's on clusters and single systems this seems to make sense.&lt;BR /&gt;&lt;BR /&gt;However, I found a Document somewhere in HP saying:&lt;BR /&gt;&amp;gt;&amp;gt; SSH 5.5 ECO1 and prior versions do not&lt;BR /&gt;&amp;gt;&amp;gt; support external password authentication.&lt;BR /&gt;&lt;BR /&gt;(&lt;A href="http://www11.itrc.hp.com/service/cki/docDisplay.do?docLocale=en&amp;amp;docId=emr_na-c00639632-2)" target="_blank"&gt;http://www11.itrc.hp.com/service/cki/docDisplay.do?docLocale=en&amp;amp;docId=emr_na-c00639632-2)&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Now, I cannot find any hint that this has changed for the current versions (VMS V8.3, TCP/IP V5.6-9ECO2). I even think to remember having seen a more recent mentioning of this problem in this forum, but I'm not able to locate it.&lt;BR /&gt;&lt;BR /&gt;Does anyone have some more information about this?&lt;BR /&gt;&lt;BR /&gt;Edwin</description>
      <pubDate>Thu, 20 Mar 2008 10:23:34 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/ssh-and-acme/m-p/5098918#M56256</guid>
      <dc:creator>Edwin Gersbach_2</dc:creator>
      <dc:date>2008-03-20T10:23:34Z</dc:date>
    </item>
    <item>
      <title>Re: SSH and ACME</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/ssh-and-acme/m-p/5098919#M56257</link>
      <description>Edwin,&lt;BR /&gt;&lt;BR /&gt;see this entry from about 2 months ago:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://forums11.itrc.hp.com/service/forums/questionanswer.do?threadId=1197550" target="_blank"&gt;http://forums11.itrc.hp.com/service/forums/questionanswer.do?threadId=1197550&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;QUOTE&gt;&lt;BR /&gt;Converting various TCP/IP Services components (IMAP, POP, PCNFS, XDM, and yes, SSH) to use the $ACM system service for password authentication is on the worklist for a future release&lt;BR /&gt;&lt;/QUOTE&gt;&lt;BR /&gt;&lt;BR /&gt;Volker.</description>
      <pubDate>Thu, 20 Mar 2008 11:23:27 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/ssh-and-acme/m-p/5098919#M56257</guid>
      <dc:creator>Volker Halle</dc:creator>
      <dc:date>2008-03-20T11:23:27Z</dc:date>
    </item>
    <item>
      <title>Re: SSH and ACME</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/ssh-and-acme/m-p/5098920#M56258</link>
      <description>Have a look at Process's product:&lt;BR /&gt;&lt;BR /&gt;VMS Authentication Module&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.process.com/VMSauth/index.html" target="_blank"&gt;http://www.process.com/VMSauth/index.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;From the SPD:&lt;BR /&gt;&lt;BR /&gt;VAM supports the following operating&lt;BR /&gt;system versions:&lt;BR /&gt;* OpenVMS VAX V7.3&lt;BR /&gt;* OpenVMS Alpha V6.2 and higher&lt;BR /&gt;* OpenVMS I64 V8.2 and higher&lt;BR /&gt;&lt;BR /&gt;VAM supports the following TCP/IP&lt;BR /&gt;stacks and versions:&lt;BR /&gt;* MultiNet V4.4 and later&lt;BR /&gt;* TCPware V5.6-2 and later&lt;BR /&gt;* TCP/IP Services v4.0 (plus ECO v5)&lt;BR /&gt;or later&lt;BR /&gt;&lt;BR /&gt;Cheers,&lt;BR /&gt;Art</description>
      <pubDate>Thu, 20 Mar 2008 11:36:52 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/ssh-and-acme/m-p/5098920#M56258</guid>
      <dc:creator>Art Wiens</dc:creator>
      <dc:date>2008-03-20T11:36:52Z</dc:date>
    </item>
    <item>
      <title>Re: SSH and ACME</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/ssh-and-acme/m-p/5098921#M56259</link>
      <description>Volker,&lt;BR /&gt;Many thanks. That's exactly the entry I was after. Somehow I missed it with whatever keywords I was trying.&lt;BR /&gt;&lt;BR /&gt;Art,&lt;BR /&gt;I don't see how this can help me if SSH does not use the right hooks.&lt;BR /&gt;&lt;BR /&gt;Edwin</description>
      <pubDate>Thu, 20 Mar 2008 12:04:09 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/ssh-and-acme/m-p/5098921#M56259</guid>
      <dc:creator>Edwin Gersbach_2</dc:creator>
      <dc:date>2008-03-20T12:04:09Z</dc:date>
    </item>
    <item>
      <title>Re: SSH and ACME</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/ssh-and-acme/m-p/5098922#M56260</link>
      <description>The combination of Process Software's SSH for VMS and VMS Authentication Module can be used to do external authentication for SSH.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 20 Mar 2008 12:22:56 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/ssh-and-acme/m-p/5098922#M56260</guid>
      <dc:creator>Richard Whalen</dc:creator>
      <dc:date>2008-03-20T12:22:56Z</dc:date>
    </item>
    <item>
      <title>Re: SSH and ACME</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/ssh-and-acme/m-p/5098923#M56261</link>
      <description>So without a third-party solution, you cannot use AD Authentication?</description>
      <pubDate>Fri, 21 Mar 2008 11:09:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/ssh-and-acme/m-p/5098923#M56261</guid>
      <dc:creator>James T Horn</dc:creator>
      <dc:date>2008-03-21T11:09:21Z</dc:date>
    </item>
    <item>
      <title>Re: SSH and ACME</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/ssh-and-acme/m-p/5098924#M56262</link>
      <description>Regarding James' question:&lt;BR /&gt;&lt;BR /&gt;So without a third-party solution, you cannot use AD Authentication?&lt;BR /&gt;&lt;BR /&gt;HP offers several solutions:&lt;BR /&gt;&lt;BR /&gt;1.  Use Advanced Server for OpenVMS to provide NTLM authentication for ExtAuth users.  Using Advanced Server for ExtAuth involves no cost - it's absolutely free. But Advanced Server doesn't run on Itanium systems.   &lt;BR /&gt;&lt;BR /&gt;However, if an Itanium system is in a cluster with an Alpha running Advanced Server, the Itanium system can send the ExtAuth requests to the Alpha for processing (the necessary IA64 ACME modules are in sys$library: on the Alpha and the command procedure to load the acme modules on the itanium is in sys$startup: on the Alpha; these need to be copied to the Itanium and then the logical name PWRK$ACME_SERVER needs to be defined on the Itanium to the SCSNODE name of the Alpha(s)).  See the release notes for Advanced Server v7.3B for more information.&lt;BR /&gt;&lt;BR /&gt;2.  Use LDAP.  OpenVMS 8.3 (Alpha and Itanium) and later provide the ability (with the right kits installed ;o), to use LDAP for ExtAuth.  Authentication can be directed to an Active Directory server or an HP Enterprise Directory server (and possible any of the Linux LDAP adaptations, though I'm not sure that's officially supported yet). See: &lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://h71000.www7.hp.com/openvms/security.html#ldap" target="_blank"&gt;http://h71000.www7.hp.com/openvms/security.html#ldap&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;3. Use Kerberos.  See:&lt;BR /&gt; &lt;A href="http://h71000.www7.hp.com/doc/83final/BA554_90008/ch02s09.html?jumpid=reg_R1002_USEN" target="_blank"&gt;http://h71000.www7.hp.com/doc/83final/BA554_90008/ch02s09.html?jumpid=reg_R1002_USEN&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 21 Mar 2008 12:34:25 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/ssh-and-acme/m-p/5098924#M56262</guid>
      <dc:creator>Paul Nunez</dc:creator>
      <dc:date>2008-03-21T12:34:25Z</dc:date>
    </item>
    <item>
      <title>Re: SSH and ACME</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/ssh-and-acme/m-p/5098925#M56263</link>
      <description>Paul,&lt;BR /&gt;&lt;BR /&gt;As mentioned by Volker, your second 'solution' does not really work - at least not with the heavily used SSH.&lt;BR /&gt;&lt;BR /&gt;Would be intresting to figure out wether SSH would work with the Advanced Server, but I doubt because it is said not to use the right entry points.&lt;BR /&gt;&lt;BR /&gt;Anyway, I will close this thread. For us there is not enough benefit to go for a costly third party solution.&lt;BR /&gt;&lt;BR /&gt;Edwin</description>
      <pubDate>Tue, 25 Mar 2008 05:59:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/ssh-and-acme/m-p/5098925#M56263</guid>
      <dc:creator>Edwin Gersbach_2</dc:creator>
      <dc:date>2008-03-25T05:59:21Z</dc:date>
    </item>
    <item>
      <title>Re: SSH and ACME</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/ssh-and-acme/m-p/5098926#M56264</link>
      <description>As explained above.&lt;BR /&gt;</description>
      <pubDate>Tue, 25 Mar 2008 06:00:43 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/ssh-and-acme/m-p/5098926#M56264</guid>
      <dc:creator>Edwin Gersbach_2</dc:creator>
      <dc:date>2008-03-25T06:00:43Z</dc:date>
    </item>
  </channel>
</rss>

