<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Access Control Violation in Operating System - OpenVMS</title>
    <link>https://community.hpe.com/t5/operating-system-openvms/access-control-violation/m-p/4303705#M57233</link>
    <description>That intrusion automatically cleared and it is coming again and again.&lt;BR /&gt;&lt;BR /&gt;can anyone tell me what is the exact cmd to add a proxy? &lt;BR /&gt;&lt;BR /&gt;I have to add in both ends?&lt;BR /&gt;&lt;BR /&gt;I have already added with the following cmd but &lt;BR /&gt;errors still coming...&lt;BR /&gt;&lt;BR /&gt;$mc authorize&lt;BR /&gt;UAF&amp;gt; add/proxy sahara::test test/default</description>
    <pubDate>Wed, 12 Nov 2008 08:05:31 GMT</pubDate>
    <dc:creator>Accullise</dc:creator>
    <dc:date>2008-11-12T08:05:31Z</dc:date>
    <item>
      <title>Access Control Violation</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/access-control-violation/m-p/4303696#M57224</link>
      <description>Hi friends,&lt;BR /&gt;&lt;BR /&gt;we have four alpha servers in cluster and last week we have upgraded our systems from openVMS7.3-2 to 8.3.After upgradation one of my server has been giving a following error in operator log continuously. &lt;BR /&gt;&lt;BR /&gt;Message from user SYSTEM on xxxx&lt;BR /&gt;Event: Access Control Violation from: Node LOCAL:.xxxx Session Control,&lt;BR /&gt;        at: 2008-11-10-09:05:42.840+00:00Iinf&lt;BR /&gt;        NSAP Address=49::00-28:AA-00-04-00-66-A0:20,&lt;BR /&gt;        Source=UIC = [0,0]yyyy,&lt;BR /&gt;        Destination=number = 17,&lt;BR /&gt;        Destination User="yyyy",&lt;BR /&gt;        Destination Account="",&lt;BR /&gt;        Node Name=LOCAL:.zzzz&lt;BR /&gt;        eventUid   C0AFD1EC-AF06-11DD-A972-00062B02953D&lt;BR /&gt;        entityUid  2E368BEA-A947-11DD-832F-AA000400062C&lt;BR /&gt;        streamUid  3F93EA8B-A947-11DD-848C-AA000400062C&lt;BR /&gt;&lt;BR /&gt;Can anyone tell me how to stop these errors and &lt;BR /&gt;what are the next steps i have to do?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Regds,&lt;BR /&gt;Acullise&lt;BR /&gt;</description>
      <pubDate>Tue, 11 Nov 2008 05:23:38 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/access-control-violation/m-p/4303696#M57224</guid>
      <dc:creator>Accullise</dc:creator>
      <dc:date>2008-11-11T05:23:38Z</dc:date>
    </item>
    <item>
      <title>Re: Access Control Violation</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/access-control-violation/m-p/4303697#M57225</link>
      <description>Acculise,&lt;BR /&gt;&lt;BR /&gt;this event is associated with an attempted DECnet file access. Find out, from which node and user the access is happening, check the DECnet proxies for that user on the local node:&lt;BR /&gt;&lt;BR /&gt;$ MC AUTHORIZE SHOW/PROXY remote-node::remote-user&lt;BR /&gt;&lt;BR /&gt;Volker.</description>
      <pubDate>Tue, 11 Nov 2008 07:01:47 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/access-control-violation/m-p/4303697#M57225</guid>
      <dc:creator>Volker Halle</dc:creator>
      <dc:date>2008-11-11T07:01:47Z</dc:date>
    </item>
    <item>
      <title>Re: Access Control Violation</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/access-control-violation/m-p/4303698#M57226</link>
      <description>thanks volker...&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Actually i have added that user in proxy database today morning...&lt;BR /&gt;but still errors are coming...&lt;BR /&gt;&lt;BR /&gt;i have added to proxy by the following commands...&lt;BR /&gt;&lt;BR /&gt;UAF&amp;gt; add/proxy zzzz::yyyy&lt;BR /&gt;_local user(s): YYYY&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;UAF&amp;gt; sh/proxy&lt;BR /&gt;_remote user: *&lt;BR /&gt;&lt;BR /&gt; Default proxies are flagged with (D)&lt;BR /&gt;&lt;BR /&gt;LOCAL:.xxxx::yyyy&lt;BR /&gt;    yyyy&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 11 Nov 2008 07:51:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/access-control-violation/m-p/4303698#M57226</guid>
      <dc:creator>Accullise</dc:creator>
      <dc:date>2008-11-11T07:51:21Z</dc:date>
    </item>
    <item>
      <title>Re: Access Control Violation</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/access-control-violation/m-p/4303699#M57227</link>
      <description>when that user accesses this system do they specify the local username &lt;BR /&gt;&lt;BR /&gt;node"username"::&lt;BR /&gt;&lt;BR /&gt;As its not a default proxy perhaps they should or you make it a default proxy</description>
      <pubDate>Tue, 11 Nov 2008 13:29:43 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/access-control-violation/m-p/4303699#M57227</guid>
      <dc:creator>Ian Miller.</dc:creator>
      <dc:date>2008-11-11T13:29:43Z</dc:date>
    </item>
    <item>
      <title>Re: Access Control Violation</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/access-control-violation/m-p/4303700#M57228</link>
      <description>The specified target username (or proxy) doesn't exist, or the target proxy isn't marked /DEFAULT.&lt;BR /&gt;&lt;BR /&gt;Check security auditing for the same time, too.&lt;BR /&gt;&lt;BR /&gt;Flush the caches  (if you can't upgrade to Phase IV, then one of the first attempts to fix Phase IV is to flush the Phase V cache), and check that the back-translation values are such that the proxies are triggered.  Here, you'd need a proxy or /DEFAULT proxy for the incoming DECnet connection.&lt;BR /&gt;&lt;BR /&gt;As a general recommendation when these sorts of errors show, work through all of the shared files for this cluster (SYLOGICALS.TEMPLATE) and make sure all are configured appropriately on all hosts in the cluster.&lt;BR /&gt;&lt;BR /&gt;AFAIK, this "access control violation" has little or nothing to do with an OpenVMS ACCVIO access violation.  Yes; a bad choice of errors.  The ACCVIO case is a memory management.  This case is usually some sort of proxy or authentication boo-boo.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 11 Nov 2008 14:30:45 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/access-control-violation/m-p/4303700#M57228</guid>
      <dc:creator>Hoff</dc:creator>
      <dc:date>2008-11-11T14:30:45Z</dc:date>
    </item>
    <item>
      <title>Re: Access Control Violation</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/access-control-violation/m-p/4303701#M57229</link>
      <description>Acullise,&lt;BR /&gt;&lt;BR /&gt;what Ian was meant to say: you did not specify the /DEFAULT qualifier when adding that proxy, so the remote user must specify the local username, if that proxy is to be used.&lt;BR /&gt;&lt;BR /&gt;If you have an account on that remote system, try a DIR xxxx:: yourself. Have another session opened on node xxx with REPLY/ENABLE. Then watch the messages in real-time and try to understand and fix the problem. Once you've fixed the problem for your account, apply the same fix to the yyyy user account. &lt;BR /&gt;&lt;BR /&gt;Volker.</description>
      <pubDate>Tue, 11 Nov 2008 15:45:03 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/access-control-violation/m-p/4303701#M57229</guid>
      <dc:creator>Volker Halle</dc:creator>
      <dc:date>2008-11-11T15:45:03Z</dc:date>
    </item>
    <item>
      <title>Re: Access Control Violation</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/access-control-violation/m-p/4303702#M57230</link>
      <description>Thanks  frds,&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;I have added that in proxy with /default but again same errors are coming. Instrsion also increased.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Intrusion       Type       Count        Expiration         Source&lt;BR /&gt;---------       ----       -----        ----------         ------&lt;BR /&gt;   NETWORK      INTRUDER     50   12-NOV-2008 10:58:35.44  LOCAL:.sahara::test&lt;BR /&gt;&lt;BR /&gt;please tell me what is the exact cmd and what is the next step?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 12 Nov 2008 05:28:22 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/access-control-violation/m-p/4303702#M57230</guid>
      <dc:creator>Accullise</dc:creator>
      <dc:date>2008-11-12T05:28:22Z</dc:date>
    </item>
    <item>
      <title>Re: Access Control Violation</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/access-control-violation/m-p/4303703#M57231</link>
      <description>Acullise,&lt;BR /&gt;&lt;BR /&gt;did you try to delete the intrusion record first ?&lt;BR /&gt;&lt;BR /&gt;$ DELETE/intrusion local:.sahara::test&lt;BR /&gt;&lt;BR /&gt;Volker.</description>
      <pubDate>Wed, 12 Nov 2008 07:09:51 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/access-control-violation/m-p/4303703#M57231</guid>
      <dc:creator>Volker Halle</dc:creator>
      <dc:date>2008-11-12T07:09:51Z</dc:date>
    </item>
    <item>
      <title>Re: Access Control Violation</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/access-control-violation/m-p/4303704#M57232</link>
      <description>I HAVE DONE THAT. WHATEVER I HAVE DELETE THE INTRUSIONS, IT IS COMING AGAIN AND AGAIN....&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;IF I WANT TO ADD THE PROXY IN BOTH NODES?&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 12 Nov 2008 07:56:17 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/access-control-violation/m-p/4303704#M57232</guid>
      <dc:creator>Accullise</dc:creator>
      <dc:date>2008-11-12T07:56:17Z</dc:date>
    </item>
    <item>
      <title>Re: Access Control Violation</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/access-control-violation/m-p/4303705#M57233</link>
      <description>That intrusion automatically cleared and it is coming again and again.&lt;BR /&gt;&lt;BR /&gt;can anyone tell me what is the exact cmd to add a proxy? &lt;BR /&gt;&lt;BR /&gt;I have to add in both ends?&lt;BR /&gt;&lt;BR /&gt;I have already added with the following cmd but &lt;BR /&gt;errors still coming...&lt;BR /&gt;&lt;BR /&gt;$mc authorize&lt;BR /&gt;UAF&amp;gt; add/proxy sahara::test test/default</description>
      <pubDate>Wed, 12 Nov 2008 08:05:31 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/access-control-violation/m-p/4303705#M57233</guid>
      <dc:creator>Accullise</dc:creator>
      <dc:date>2008-11-12T08:05:31Z</dc:date>
    </item>
    <item>
      <title>Re: Access Control Violation</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/access-control-violation/m-p/4303706#M57234</link>
      <description>Aculisse,&lt;BR /&gt;&lt;BR /&gt;in your first entry, you said that this problem is only happening on one of your 4 nodes in the same cluster. Do these system share a common OpenVMS environment, like same system disk or at least all common files set up correctly ? Does the proxy access work to any of the 4 nodes ?&lt;BR /&gt;&lt;BR /&gt;You need to add the proxy only on the destination system. Be aware that the various session control applications can have attributes set to disable outgoing or incoming proxy access. Check with MC NCL SHO SESS CONTROL APP FAL ALL&lt;BR /&gt;&lt;BR /&gt;The correct statement to add your porxy for a DECnet connection would be:&lt;BR /&gt;&lt;BR /&gt;UAF&amp;gt; add/proxy local:.sahara::test test/def&lt;BR /&gt;&lt;BR /&gt;but just using sahara::test might work as well.&lt;BR /&gt;&lt;BR /&gt;Does access work, if you explicitly specify username and password for your test account, i.e.&lt;BR /&gt;&lt;BR /&gt;$ dir node"username password"::&lt;BR /&gt;&lt;BR /&gt;Volker.</description>
      <pubDate>Wed, 12 Nov 2008 09:23:58 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/access-control-violation/m-p/4303706#M57234</guid>
      <dc:creator>Volker Halle</dc:creator>
      <dc:date>2008-11-12T09:23:58Z</dc:date>
    </item>
    <item>
      <title>Re: Access Control Violation</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/access-control-violation/m-p/4303707#M57235</link>
      <description>thanks volker...&lt;BR /&gt;&lt;BR /&gt;i have checked with MC NCL, it is in true state &lt;BR /&gt;for all.&lt;BR /&gt;&lt;BR /&gt;actually we have four different openvms cluster&lt;BR /&gt;but each cluster in different place. In my cluster having 4 alpha nodes. one of my alpha nodes having this problem but SAHARA is the another clusters node.&lt;BR /&gt;&lt;BR /&gt;SAHARA::TEST user only trying to access my node.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 12 Nov 2008 09:56:17 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/access-control-violation/m-p/4303707#M57235</guid>
      <dc:creator>Accullise</dc:creator>
      <dc:date>2008-11-12T09:56:17Z</dc:date>
    </item>
    <item>
      <title>Re: Access Control Violation</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/access-control-violation/m-p/4303708#M57236</link>
      <description>Acullise,&lt;BR /&gt;&lt;BR /&gt;discussing and troubleshooting such a problem requires precise configuration information - otherwise it becomes more of a guesswork.&lt;BR /&gt;&lt;BR /&gt;You need to supply information about the source node or cluster from which the access originates and also information about the destination node or cluster. And provide information about what exactly has been changed.&lt;BR /&gt;&lt;BR /&gt;If the access is only happening from one explicit node in the source cluster to one explicit node in the destination cluster, then try from another node or to another node in those clusters. If access is to a DECnet cluster alias, things may just be wrong on node node. First try access by explicitly specifying the correct username and password. Find out whether that works as expected. Then look at NET$SERVER.LOG in the default directory of the destination account and find out the source node information from there. Is it like what you expect ?&lt;BR /&gt;&lt;BR /&gt;Volker.</description>
      <pubDate>Wed, 12 Nov 2008 10:55:50 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/access-control-violation/m-p/4303708#M57236</guid>
      <dc:creator>Volker Halle</dc:creator>
      <dc:date>2008-11-12T10:55:50Z</dc:date>
    </item>
  </channel>
</rss>

