<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Someone deleted the sysuaf.dat file. Is that logged anywhere? in Operating System - OpenVMS</title>
    <link>https://community.hpe.com/t5/operating-system-openvms/someone-deleted-the-sysuaf-dat-file-is-that-logged-anywhere/m-p/4971933#M75470</link>
    <description>I know a site that has had for long 8000 acccounts with all privileges...&lt;BR /&gt;&lt;BR /&gt;You are not alone :-)</description>
    <pubDate>Wed, 05 Apr 2006 11:00:42 GMT</pubDate>
    <dc:creator>labadie_1</dc:creator>
    <dc:date>2006-04-05T11:00:42Z</dc:date>
    <item>
      <title>Someone deleted the sysuaf.dat file. Is that logged anywhere?</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/someone-deleted-the-sysuaf-dat-file-is-that-logged-anywhere/m-p/4971930#M75467</link>
      <description>Despite warning management for years that too many users have system privileges, along with the associated risks, management will not allow tightening security. &lt;BR /&gt;&lt;BR /&gt;Well, it finally happened yesterday when someone deleted sysuaf.dat. While I recovered the file from the nightly backup, no one has taken responsibility for deleting the file.&lt;BR /&gt;&lt;BR /&gt;I support too many operating systems these days and have become a bit rusty with vms to recall all the accounting and security features. Question: Is the deletion of sysuaf.dat recorded anywhere on the system... assuming default installation settings for accounting and security? I have already scanned accounting and didn't find it there.</description>
      <pubDate>Wed, 05 Apr 2006 10:25:19 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/someone-deleted-the-sysuaf-dat-file-is-that-logged-anywhere/m-p/4971930#M75467</guid>
      <dc:creator>Steve Longenecker</dc:creator>
      <dc:date>2006-04-05T10:25:19Z</dc:date>
    </item>
    <item>
      <title>Re: Someone deleted the sysuaf.dat file. Is that logged anywhere?</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/someone-deleted-the-sysuaf-dat-file-is-that-logged-anywhere/m-p/4971931#M75468</link>
      <description>Probably not unless you had an alarm/audit ACL on the file (DIR/SECURITY SYS$SYSTEM:SYSUAF.DAT)&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Ensure the time and cost of recovering from this is visable to the mangagement - give them some beans to count.</description>
      <pubDate>Wed, 05 Apr 2006 10:39:13 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/someone-deleted-the-sysuaf-dat-file-is-that-logged-anywhere/m-p/4971931#M75468</guid>
      <dc:creator>Ian Miller.</dc:creator>
      <dc:date>2006-04-05T10:39:13Z</dc:date>
    </item>
    <item>
      <title>Re: Someone deleted the sysuaf.dat file. Is that logged anywhere?</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/someone-deleted-the-sysuaf-dat-file-is-that-logged-anywhere/m-p/4971932#M75469</link>
      <description>Steve,&lt;BR /&gt;&lt;BR /&gt;&lt;QUOTE&gt;&lt;BR /&gt;Question: Is the deletion of sysuaf.dat recorded anywhere on the system... assuming default installation settings for accounting and security? &lt;BR /&gt;&lt;/QUOTE&gt;&lt;BR /&gt;&lt;BR /&gt;No.&lt;BR /&gt;&lt;BR /&gt;But, if you fear for a repitition any time in the future, you CAN set an alarm ACE on it.&lt;BR /&gt;&lt;BR /&gt;And then I hope it will not be "SYSTEM" who did it, because that will bring you back to square 1.&lt;BR /&gt;&lt;BR /&gt;In that respect, did you really mean &lt;BR /&gt;"too many users have system privileges", (a relatively good thing)&lt;BR /&gt;or did you mean that many users have access to the SYSTEM account?&lt;BR /&gt;In the latter case, all you can do is hope to find out from which terminal/remote connection the faulty action was made, and be able to tie that to one individual.&lt;BR /&gt;&lt;BR /&gt;But really, you should try with all means at your disposal to convince your management that this is an unresponsible risk!&lt;BR /&gt;-- but you probably gave them the best argument to the contrary, by demonstrating how quickly you can recoverm by a simple restore.  :-(&lt;BR /&gt;&lt;BR /&gt;As so often: the technical problems are NOTHING compared to managents complete incompetence&lt;BS&gt;&lt;BS&gt;&lt;BS&gt;&lt;BS&gt;&lt;BS&gt;&lt;BS&gt;&lt;BS&gt;&lt;BS&gt;&lt;BS&gt;&lt;BS&gt;&lt;BS&gt;&lt;BS&gt; ignorance.&lt;BR /&gt;&lt;BR /&gt;Proost.&lt;BR /&gt;&lt;BR /&gt;Have one on me.&lt;BR /&gt;&lt;BR /&gt;jpe&lt;/BS&gt;&lt;/BS&gt;&lt;/BS&gt;&lt;/BS&gt;&lt;/BS&gt;&lt;/BS&gt;&lt;/BS&gt;&lt;/BS&gt;&lt;/BS&gt;&lt;/BS&gt;&lt;/BS&gt;&lt;/BS&gt;</description>
      <pubDate>Wed, 05 Apr 2006 10:48:14 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/someone-deleted-the-sysuaf-dat-file-is-that-logged-anywhere/m-p/4971932#M75469</guid>
      <dc:creator>Jan van den Ende</dc:creator>
      <dc:date>2006-04-05T10:48:14Z</dc:date>
    </item>
    <item>
      <title>Re: Someone deleted the sysuaf.dat file. Is that logged anywhere?</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/someone-deleted-the-sysuaf-dat-file-is-that-logged-anywhere/m-p/4971933#M75470</link>
      <description>I know a site that has had for long 8000 acccounts with all privileges...&lt;BR /&gt;&lt;BR /&gt;You are not alone :-)</description>
      <pubDate>Wed, 05 Apr 2006 11:00:42 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/someone-deleted-the-sysuaf-dat-file-is-that-logged-anywhere/m-p/4971933#M75470</guid>
      <dc:creator>labadie_1</dc:creator>
      <dc:date>2006-04-05T11:00:42Z</dc:date>
    </item>
    <item>
      <title>Re: Someone deleted the sysuaf.dat file. Is that logged anywhere?</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/someone-deleted-the-sysuaf-dat-file-is-that-logged-anywhere/m-p/4971934#M75471</link>
      <description>Thanks, I'll set an alarm ACE for the next time... assuming it works. Believe it or not, every DCL user in the IT department, regardless of position (System Manager, Operator, HelpDesk, Programmer, Application Support, etc.), has a copy of the system account, along with a UIC of [1,4]. The only user account differences from system are username and default directory.</description>
      <pubDate>Wed, 05 Apr 2006 11:14:57 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/someone-deleted-the-sysuaf-dat-file-is-that-logged-anywhere/m-p/4971934#M75471</guid>
      <dc:creator>Steve Longenecker</dc:creator>
      <dc:date>2006-04-05T11:14:57Z</dc:date>
    </item>
    <item>
      <title>Re: Someone deleted the sysuaf.dat file. Is that logged anywhere?</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/someone-deleted-the-sysuaf-dat-file-is-that-logged-anywhere/m-p/4971935#M75472</link>
      <description>Steve,&lt;BR /&gt;&lt;BR /&gt;Having large numbers of privileged accounts is a problem.&lt;BR /&gt;&lt;BR /&gt;OpenVMS DOES allow many management functions to be performed by users with suitable file access, not full privileges.&lt;BR /&gt;&lt;BR /&gt;At HP WORLD 2004, I gave a presentation on how to manage a large environment (measured in thousands of users), with a minimum of privileged users. The introductory slides for the presentation can be found at &lt;A href="http://www.rlgsc.com/hpworld/2004/N227.html" target="_blank"&gt;http://www.rlgsc.com/hpworld/2004/N227.html&lt;/A&gt; .&lt;BR /&gt;(My apologies, but the workbook is not publicly available, it represents a half-day seminar).&lt;BR /&gt;&lt;BR /&gt;Suffice it to say, particularly in these days of Sarbenes-Oxley and other accountability regulations, OpenVMS provides mechanisms to manage the system without requiring large numbers of privileged users.&lt;BR /&gt;&lt;BR /&gt;- Bob Gezelter, &lt;A href="http://www.rlgsc.com" target="_blank"&gt;http://www.rlgsc.com&lt;/A&gt;&lt;BR /&gt;  Contributor, OpenVMS Security, Handbook of Information Security</description>
      <pubDate>Wed, 05 Apr 2006 11:26:57 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/someone-deleted-the-sysuaf-dat-file-is-that-logged-anywhere/m-p/4971935#M75472</guid>
      <dc:creator>Robert Gezelter</dc:creator>
      <dc:date>2006-04-05T11:26:57Z</dc:date>
    </item>
    <item>
      <title>Re: Someone deleted the sysuaf.dat file. Is that logged anywhere?</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/someone-deleted-the-sysuaf-dat-file-is-that-logged-anywhere/m-p/4971936#M75473</link>
      <description>You are preaching to the choir... Yes, despite SARBOX and HIPAA (and yes, we are also a hospital), not properly configuring user accounts is a directive from the Director of IT. Even this scare is not enough to change his mind... the rational being "the hospital has been running VMS for over 20 years and this problem has only occurred once." Oh well, live and learn. I have documented my concerns and will drive on... Thanks.</description>
      <pubDate>Wed, 05 Apr 2006 11:34:06 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/someone-deleted-the-sysuaf-dat-file-is-that-logged-anywhere/m-p/4971936#M75473</guid>
      <dc:creator>Steve Longenecker</dc:creator>
      <dc:date>2006-04-05T11:34:06Z</dc:date>
    </item>
    <item>
      <title>Re: Someone deleted the sysuaf.dat file. Is that logged anywhere?</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/someone-deleted-the-sysuaf-dat-file-is-that-logged-anywhere/m-p/4971937#M75474</link>
      <description>Closed...</description>
      <pubDate>Wed, 05 Apr 2006 11:36:26 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/someone-deleted-the-sysuaf-dat-file-is-that-logged-anywhere/m-p/4971937#M75474</guid>
      <dc:creator>Steve Longenecker</dc:creator>
      <dc:date>2006-04-05T11:36:26Z</dc:date>
    </item>
    <item>
      <title>Re: Someone deleted the sysuaf.dat file. Is that logged anywhere?</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/someone-deleted-the-sysuaf-dat-file-is-that-logged-anywhere/m-p/4971938#M75475</link>
      <description>As you are in the USA then you can leverage Sarbenes-Oxley. You have to have individual accountability and minimum privilges to do the job. So thats unique UIC's and take away those privs.  &lt;BR /&gt;&lt;BR /&gt;Get your corporate auditor interested as they can wield a stick big enough for the management to take note of.&lt;BR /&gt;&lt;BR /&gt;There are other security standards which apply if you have any govt work.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 05 Apr 2006 11:37:35 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/someone-deleted-the-sysuaf-dat-file-is-that-logged-anywhere/m-p/4971938#M75475</guid>
      <dc:creator>Ian Miller.</dc:creator>
      <dc:date>2006-04-05T11:37:35Z</dc:date>
    </item>
    <item>
      <title>Re: Someone deleted the sysuaf.dat file. Is that logged anywhere?</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/someone-deleted-the-sysuaf-dat-file-is-that-logged-anywhere/m-p/4971939#M75476</link>
      <description>Steve,&lt;BR /&gt;&lt;BR /&gt;&lt;QUOTE&gt;&lt;BR /&gt; has a copy of the system account, along with a UIC of [1,4]. The only user account differences from system are username and default directory&lt;BR /&gt;&lt;/QUOTE&gt;&lt;BR /&gt;&lt;BR /&gt;In that case, I would not even like to THINK about what functionality you will break by taking away the privileges, &lt;BR /&gt;BUT,&lt;BR /&gt;the ONE important thing you CAN, (and should) do with little impact, but much gain, is assigning each user account a unique UIC.&lt;BR /&gt;To stay on the save side wrt breaking things, choose group-UICs .LE. SYSGENs MAXSYSGROUP, but then at least any activity that leaves a trace will in that trace show WHO did it.&lt;BR /&gt;&lt;BR /&gt;hth&lt;BR /&gt;&lt;BR /&gt;Proost.&lt;BR /&gt;&lt;BR /&gt;Have one on me.&lt;BR /&gt;&lt;BR /&gt;jpe&lt;BR /&gt;</description>
      <pubDate>Wed, 05 Apr 2006 11:41:38 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/someone-deleted-the-sysuaf-dat-file-is-that-logged-anywhere/m-p/4971939#M75476</guid>
      <dc:creator>Jan van den Ende</dc:creator>
      <dc:date>2006-04-05T11:41:38Z</dc:date>
    </item>
  </channel>
</rss>

