<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VMS Proxy in Operating System - OpenVMS</title>
    <link>https://community.hpe.com/t5/operating-system-openvms/vms-proxy/m-p/3677275#M72842</link>
    <description>Hi, all thanks a lot.</description>
    <pubDate>Thu, 24 Nov 2005 08:57:05 GMT</pubDate>
    <dc:creator>Sk Noorul  Hassan</dc:creator>
    <dc:date>2005-11-24T08:57:05Z</dc:date>
    <item>
      <title>VMS Proxy</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/vms-proxy/m-p/3677268#M72835</link>
      <description>hi,&lt;BR /&gt;&lt;BR /&gt;It seems somebody has modified the proxy setting in my system, so remote user is unable to execute some options from his computer which is suppose to execute from host computer through poxy. &lt;BR /&gt;&lt;BR /&gt;Is there any way to find out the changes made to proxy database.</description>
      <pubDate>Wed, 23 Nov 2005 04:34:33 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/vms-proxy/m-p/3677268#M72835</guid>
      <dc:creator>Sk Noorul  Hassan</dc:creator>
      <dc:date>2005-11-23T04:34:33Z</dc:date>
    </item>
    <item>
      <title>Re: VMS Proxy</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/vms-proxy/m-p/3677269#M72836</link>
      <description>If you have AUDITing enabled for the class AUTHORIZATION, you may find it in the Auditlog.&lt;BR /&gt;Check with SHOW AUDIT and analyse with ANALYZE/AUDIT.&lt;BR /&gt;&lt;BR /&gt;regards Kalle</description>
      <pubDate>Wed, 23 Nov 2005 04:38:52 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/vms-proxy/m-p/3677269#M72836</guid>
      <dc:creator>Karl Rohwedder</dc:creator>
      <dc:date>2005-11-23T04:38:52Z</dc:date>
    </item>
    <item>
      <title>Re: VMS Proxy</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/vms-proxy/m-p/3677270#M72837</link>
      <description>DEcnet or TCPIP proxy?&lt;BR /&gt;&lt;BR /&gt;you may also find useful information in operator messsages in operator.log&lt;BR /&gt;</description>
      <pubDate>Wed, 23 Nov 2005 05:00:27 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/vms-proxy/m-p/3677270#M72837</guid>
      <dc:creator>Ian Miller.</dc:creator>
      <dc:date>2005-11-23T05:00:27Z</dc:date>
    </item>
    <item>
      <title>Re: VMS Proxy</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/vms-proxy/m-p/3677271#M72838</link>
      <description>It is a DECNET proxy.</description>
      <pubDate>Wed, 23 Nov 2005 05:03:12 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/vms-proxy/m-p/3677271#M72838</guid>
      <dc:creator>Sk Noorul  Hassan</dc:creator>
      <dc:date>2005-11-23T05:03:12Z</dc:date>
    </item>
    <item>
      <title>Re: VMS Proxy</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/vms-proxy/m-p/3677272#M72839</link>
      <description>Hi&lt;BR /&gt;As the used proxy is DECnet, then to analize use anal/audit/event=authorize (if audit authorize is enabled)&lt;BR /&gt;Saludos.&lt;BR /&gt;Daniel.</description>
      <pubDate>Wed, 23 Nov 2005 05:34:43 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/vms-proxy/m-p/3677272#M72839</guid>
      <dc:creator>Daniel Fernandez Illan</dc:creator>
      <dc:date>2005-11-23T05:34:43Z</dc:date>
    </item>
    <item>
      <title>Re: VMS Proxy</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/vms-proxy/m-p/3677273#M72840</link>
      <description>Sk,&lt;BR /&gt;&lt;BR /&gt;and if your site regularly or occasionally (like now, for instance) _IS_ interested in changes of authorisations, then make sure AUDITing of AUTHORISATION events IS enabled. &lt;BR /&gt;Maybe a good time to reviwe your audit settings anyway. Especially LOGFAIL can be very usefull if ever your site should be tried to login to from the outside world. &lt;BR /&gt;&lt;BR /&gt;Proost.&lt;BR /&gt;&lt;BR /&gt;Have one on me.&lt;BR /&gt;&lt;BR /&gt;jpe</description>
      <pubDate>Wed, 23 Nov 2005 09:47:11 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/vms-proxy/m-p/3677273#M72840</guid>
      <dc:creator>Jan van den Ende</dc:creator>
      <dc:date>2005-11-23T09:47:11Z</dc:date>
    </item>
    <item>
      <title>Re: VMS Proxy</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/vms-proxy/m-p/3677274#M72841</link>
      <description>Sk,&lt;BR /&gt;&lt;BR /&gt;  Another possibility... it could be the perceived name of the remote user has changed, rather than the proxy itself. This can depend on a DNS definition.&lt;BR /&gt;&lt;BR /&gt;  What you need to work out is the perceived name for the incoming node.&lt;BR /&gt;&lt;BR /&gt;  From a privileged session on the target node, make sure LOGFAIL audits are enabled and enable your terminal for SECURITY audits. Now SET HOST from the failing system and enter username/password TEST/TEST (assuming they don't exist!). In the resulting audit alarm, look at the "Remote node fullname:". You may find it listed as something like&lt;BR /&gt;&lt;BR /&gt;  "LOCAL:.NODE" for a name resolved from the local DNS, "DOMAIN:.NODE" if resolved from an external domain. Or, it could be an IP style address "NODE.DOMAIN.NET" or even as a raw numeric address "IP$12.34.56.7"&lt;BR /&gt;&lt;BR /&gt;  DECnet proxies are pretty dumb. They just take whatever string "Remote node fullname:" translates to and use that to look up the proxy data base - direct string comparison. You need to confirm that the *string* in the proxy record matches whatever the node translates to. The important thing to remember is the DNS name could change, but the *string* in the proxy data base won't change. &lt;BR /&gt;&lt;BR /&gt;  In some volatile environments it may be necessary to define several possible proxy records for a particular node. You can argue about how the implementation *might* have been done, but it's not going change, so learn to live with it!&lt;BR /&gt;&lt;BR /&gt; &lt;BR /&gt;&amp;gt;Is there any way to find out the changes made to proxy database.&lt;BR /&gt;&lt;BR /&gt;  Assuming you have AUTHORIZATION audits enabled, there will be events in your security journal "Network proxy record mofification", "Network proxy record deletion" and "Network proxy record addition", which should record exactly what was changed, when and by whom.&lt;BR /&gt;&lt;BR /&gt;  If you can't work out the ANALYZE/AUDIT syntax to extract just the UAF audits, use the big hammer:&lt;BR /&gt;&lt;BR /&gt;$ ANALYZE/AUDIT/FULL/SINCE=date-time/OUT=AUD.TXT SYS$MANAGER:SECURITY.AUDIT$JOURNAL&lt;BR /&gt;$ SEARCH AUD.TXT proxy/WINDOW=20&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 23 Nov 2005 16:10:16 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/vms-proxy/m-p/3677274#M72841</guid>
      <dc:creator>John Gillings</dc:creator>
      <dc:date>2005-11-23T16:10:16Z</dc:date>
    </item>
    <item>
      <title>Re: VMS Proxy</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/vms-proxy/m-p/3677275#M72842</link>
      <description>Hi, all thanks a lot.</description>
      <pubDate>Thu, 24 Nov 2005 08:57:05 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/vms-proxy/m-p/3677275#M72842</guid>
      <dc:creator>Sk Noorul  Hassan</dc:creator>
      <dc:date>2005-11-24T08:57:05Z</dc:date>
    </item>
  </channel>
</rss>

