<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TCPIP command line question in Operating System - OpenVMS</title>
    <link>https://community.hpe.com/t5/operating-system-openvms/tcpip-command-line-question/m-p/3868577#M79078</link>
    <description>Good morning!&lt;BR /&gt;&lt;BR /&gt;As of now, you guys are going way over my head with all these good ideas.  Without making any mistakes or ???, I am auditing their login so that I can have enough evidence to remove their privileges.  Worst of all, these folks are within the IS dept but never been a systems, systems person.&lt;BR /&gt;&lt;BR /&gt;Please don't get me wrong, but these ideas are great and please keep it coming.&lt;BR /&gt;&lt;BR /&gt;Have a great day!&lt;BR /&gt;&lt;BR /&gt;Jorge</description>
    <pubDate>Tue, 26 Sep 2006 08:46:11 GMT</pubDate>
    <dc:creator>Jorge Cocomess</dc:creator>
    <dc:date>2006-09-26T08:46:11Z</dc:date>
    <item>
      <title>TCPIP command line question</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/tcpip-command-line-question/m-p/3868567#M79068</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;Currently, with some users that has more than standard VMS privs and know their way around VMS.  I am trying to maintain a trouble free environment or just get a handle by keeping non VMS system personel from playing with the TCPIP, such as adding to routes, etc.  I am currently running VMS 7.3-2  and I would like to know how I can make it more difficult for a non system personel to access TCPIP protocol?  I'd at least a long command string before they can access the TCPIP prompt.&lt;BR /&gt;&lt;BR /&gt;Is there anything I can do since the previous System Manager created these simple access privs for all these people and thought them way too much before he left the company??&lt;BR /&gt;&lt;BR /&gt;Please help!!&lt;BR /&gt;&lt;BR /&gt;Jorge</description>
      <pubDate>Sun, 24 Sep 2006 17:35:08 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/tcpip-command-line-question/m-p/3868567#M79068</guid>
      <dc:creator>Jorge Cocomess</dc:creator>
      <dc:date>2006-09-24T17:35:08Z</dc:date>
    </item>
    <item>
      <title>Re: TCPIP command line question</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/tcpip-command-line-question/m-p/3868568#M79069</link>
      <description>Hi Jorge&lt;BR /&gt;&lt;BR /&gt;You could simple set a ACL to the TCPIP Control Programms, like TCPIP$UCP or TCPIP$IFCONFIG (all TCPIP exe files in Sys$system). With the acl you can arrange, that only user System and other well selected users can execute those programms. &lt;BR /&gt;&lt;BR /&gt;Regards&lt;BR /&gt;&lt;BR /&gt;Heinz</description>
      <pubDate>Mon, 25 Sep 2006 01:24:09 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/tcpip-command-line-question/m-p/3868568#M79069</guid>
      <dc:creator>Heinz W Genhart</dc:creator>
      <dc:date>2006-09-25T01:24:09Z</dc:date>
    </item>
    <item>
      <title>Re: TCPIP command line question</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/tcpip-command-line-question/m-p/3868569#M79070</link>
      <description>ACLs will work unless the lUsers in question have BYPASS priv. You can ensure use of BYPASS to access something is recorded in the VMS audit log (to be used as evidence in the witchhunt that takes place after a major outage). &lt;BR /&gt;&lt;BR /&gt;Managing privs is a people problem not a really a technical problem. Can you find some excuse for reviewing (downgrading) their privs?</description>
      <pubDate>Mon, 25 Sep 2006 03:41:25 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/tcpip-command-line-question/m-p/3868569#M79070</guid>
      <dc:creator>Ian Miller.</dc:creator>
      <dc:date>2006-09-25T03:41:25Z</dc:date>
    </item>
    <item>
      <title>Re: TCPIP command line question</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/tcpip-command-line-question/m-p/3868570#M79071</link>
      <description>As of now, I would look into the ACL option.  I will also set an audit log on their user's account for audit trail, this should be good enough reason to down grade their privs.&lt;BR /&gt;&lt;BR /&gt;Does any know how I can set the ACL parameter on the TCIP services?&lt;BR /&gt;&lt;BR /&gt;Thanks much!&lt;BR /&gt;&lt;BR /&gt;Jorge</description>
      <pubDate>Mon, 25 Sep 2006 07:37:10 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/tcpip-command-line-question/m-p/3868570#M79071</guid>
      <dc:creator>Jorge Cocomess</dc:creator>
      <dc:date>2006-09-25T07:37:10Z</dc:date>
    </item>
    <item>
      <title>Re: TCPIP command line question</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/tcpip-command-line-question/m-p/3868571#M79072</link>
      <description>&lt;!--!*#--&gt;first add a id to use in the ACLs&lt;BR /&gt;$ MCR AUTHORIZE ADD/ID TCPIP_MANAGE&lt;BR /&gt;&lt;BR /&gt;then add the ACL e.g.&lt;BR /&gt;$ set security/acl=((id=tcpip_manage,access=r+e),(id=[*,*],access=none)) sys$system:tcpip$ucp.exe                                                          &lt;BR /&gt;&lt;BR /&gt;Add also to TCPIP$IFCONFIG.EXE and TCPIP$SYSCONFIG.EXE&lt;BR /&gt;&lt;BR /&gt;Grant the identifier to appropriate people&lt;BR /&gt;&lt;BR /&gt;$ MCR AUTHORIZE GRANT/ID TCPIP_MANAGE SYSTEM&lt;BR /&gt;$ MCR AUTHORIZE GRANT/ID TCPIP_MANAGE trusteduser&lt;BR /&gt;&lt;BR /&gt;etc&lt;BR /&gt;&lt;BR /&gt;ensure use of BYPASS gets recorded&lt;BR /&gt;$ SET AUDIT/AUDIT/ENABLE=(ACCESS=EXECUTE+BYPASS)&lt;BR /&gt;</description>
      <pubDate>Mon, 25 Sep 2006 07:57:03 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/tcpip-command-line-question/m-p/3868571#M79072</guid>
      <dc:creator>Ian Miller.</dc:creator>
      <dc:date>2006-09-25T07:57:03Z</dc:date>
    </item>
    <item>
      <title>Re: TCPIP command line question</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/tcpip-command-line-question/m-p/3868572#M79073</link>
      <description>Jorge, Ian,&lt;BR /&gt;&lt;BR /&gt;I am not convinced that monitoring of BYPASS is enough. &lt;BR /&gt;I would suggest that any mention of BYPASS in Ian's solutions entails SYSPRV as well.&lt;BR /&gt;&lt;BR /&gt;Just my EUR 0.02&lt;BR /&gt;&lt;BR /&gt;Proost.&lt;BR /&gt;&lt;BR /&gt;Have one on me.&lt;BR /&gt;&lt;BR /&gt;jpe</description>
      <pubDate>Mon, 25 Sep 2006 14:04:44 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/tcpip-command-line-question/m-p/3868572#M79073</guid>
      <dc:creator>Jan van den Ende</dc:creator>
      <dc:date>2006-09-25T14:04:44Z</dc:date>
    </item>
    <item>
      <title>Re: TCPIP command line question</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/tcpip-command-line-question/m-p/3868573#M79074</link>
      <description>Sorry, just an afterthought (that is, after hitting Submit).&lt;BR /&gt;&lt;BR /&gt;This may or may not apply:&lt;BR /&gt;What are the group-UICs of the potentially malignant users?&lt;BR /&gt;Should they be within MAXSYSGROUP, consider changing their UICs, or, if they are not as low as 1, maybe lower MAXSYSGROUP sufficiently.&lt;BR /&gt;&lt;BR /&gt;Proost.&lt;BR /&gt;&lt;BR /&gt;Have one on me.&lt;BR /&gt;&lt;BR /&gt;jpe</description>
      <pubDate>Mon, 25 Sep 2006 14:09:03 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/tcpip-command-line-question/m-p/3868573#M79074</guid>
      <dc:creator>Jan van den Ende</dc:creator>
      <dc:date>2006-09-25T14:09:03Z</dc:date>
    </item>
    <item>
      <title>Re: TCPIP command line question</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/tcpip-command-line-question/m-p/3868574#M79075</link>
      <description>Jan, yes parhaps this would be better&lt;BR /&gt;$ SET AUDIT/AUDIT/ENABLE=(ACCESS=EXECUTE+SUCCESS+BYPASS+SYSPRV+GRPPRV)&lt;BR /&gt;&lt;BR /&gt;essentially this is about collecting enough evidence to be allowed to remove privileges from some people.</description>
      <pubDate>Tue, 26 Sep 2006 03:59:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/tcpip-command-line-question/m-p/3868574#M79075</guid>
      <dc:creator>Ian Miller.</dc:creator>
      <dc:date>2006-09-26T03:59:41Z</dc:date>
    </item>
    <item>
      <title>Re: TCPIP command line question</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/tcpip-command-line-question/m-p/3868575#M79076</link>
      <description>But if they are clever they might copy an unprotected exe to the system (e.g. downloaded from the internet or from another VMS system).&lt;BR /&gt;&lt;BR /&gt;Or they can stop audit and restart it after they are finished.&lt;BR /&gt;&lt;BR /&gt;Or simply create a new version instead of modifiying the config file.&lt;BR /&gt;&lt;BR /&gt;Also tcpip$etc:syscconfigtab.dat should be protected (config of tcp params). Never understood why it has its own place (instead of in tcpip$configuration).&lt;BR /&gt;&lt;BR /&gt;Wim&lt;BR /&gt;</description>
      <pubDate>Tue, 26 Sep 2006 07:12:32 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/tcpip-command-line-question/m-p/3868575#M79076</guid>
      <dc:creator>Wim Van den Wyngaert</dc:creator>
      <dc:date>2006-09-26T07:12:32Z</dc:date>
    </item>
    <item>
      <title>Re: TCPIP command line question</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/tcpip-command-line-question/m-p/3868576#M79077</link>
      <description>a audit ACL on tcpip$etc:syscconfigtab.dat would be appropriate (along with the usual ones on OPERATOR.LOG etc). Stopping and starting auditing is recorded.</description>
      <pubDate>Tue, 26 Sep 2006 08:28:36 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/tcpip-command-line-question/m-p/3868576#M79077</guid>
      <dc:creator>Ian Miller.</dc:creator>
      <dc:date>2006-09-26T08:28:36Z</dc:date>
    </item>
    <item>
      <title>Re: TCPIP command line question</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/tcpip-command-line-question/m-p/3868577#M79078</link>
      <description>Good morning!&lt;BR /&gt;&lt;BR /&gt;As of now, you guys are going way over my head with all these good ideas.  Without making any mistakes or ???, I am auditing their login so that I can have enough evidence to remove their privileges.  Worst of all, these folks are within the IS dept but never been a systems, systems person.&lt;BR /&gt;&lt;BR /&gt;Please don't get me wrong, but these ideas are great and please keep it coming.&lt;BR /&gt;&lt;BR /&gt;Have a great day!&lt;BR /&gt;&lt;BR /&gt;Jorge</description>
      <pubDate>Tue, 26 Sep 2006 08:46:11 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/tcpip-command-line-question/m-p/3868577#M79078</guid>
      <dc:creator>Jorge Cocomess</dc:creator>
      <dc:date>2006-09-26T08:46:11Z</dc:date>
    </item>
  </channel>
</rss>

