<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: [1,1] vs [SYSTEM] ie. [1,4] in Operating System - OpenVMS</title>
    <link>https://community.hpe.com/t5/operating-system-openvms/1-1-vs-system-ie-1-4/m-p/4278394#M91489</link>
    <description>re: Richard&lt;BR /&gt;&lt;BR /&gt;&amp;gt; my auditors said either every file had a &lt;BR /&gt;&amp;gt; valid owner name&lt;BR /&gt;&lt;BR /&gt;  I'd have thought a much simpler, and more reliable way to comply with this demand would be to do as Art and Jan suggested -create a UAF record for [1,1] with a valid name in the Owner field.&lt;BR /&gt;&lt;BR /&gt;  That way you don't have to modify any files, and you don't need to concern yourself with missing anything. Everyone is happy and you solve the problem for all time with a single command (including upgrades, patches and other events that might introduce new files or devices with [1,1] ownership)</description>
    <pubDate>Tue, 21 Oct 2008 19:45:11 GMT</pubDate>
    <dc:creator>John Gillings</dc:creator>
    <dc:date>2008-10-21T19:45:11Z</dc:date>
    <item>
      <title>[1,1] vs [SYSTEM] ie. [1,4]</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/1-1-vs-system-ie-1-4/m-p/4278384#M91479</link>
      <description>What is the significance of many "things" being owned by the (non-existant) [1,1] account?  Lot's of audit talk around here and "inquiring minds" want to know why VMS installs this way.&lt;BR /&gt;&lt;BR /&gt;Would best practice be to set ownership of everything [1,1] to [1,4]?  Or actually create a [1,1] account?&lt;BR /&gt;&lt;BR /&gt;And as a bonus question, why does a group identifier ([1,177777]) not get created for the [1,*] group?&lt;BR /&gt;&lt;BR /&gt;Cheers,&lt;BR /&gt;Art</description>
      <pubDate>Tue, 30 Sep 2008 11:43:44 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/1-1-vs-system-ie-1-4/m-p/4278384#M91479</guid>
      <dc:creator>Art Wiens</dc:creator>
      <dc:date>2008-09-30T11:43:44Z</dc:date>
    </item>
    <item>
      <title>Re: [1,1] vs [SYSTEM] ie. [1,4]</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/1-1-vs-system-ie-1-4/m-p/4278385#M91480</link>
      <description>This issue was dicussed here some time ago, maybe have a look at:&lt;BR /&gt;  &lt;A href="https://forums11.itrc.hp.com/service/forums/questionanswer.do?threadId=1230665" target="_blank"&gt;https://forums11.itrc.hp.com/service/forums/questionanswer.do?threadId=1230665&lt;/A&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 30 Sep 2008 12:07:32 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/1-1-vs-system-ie-1-4/m-p/4278385#M91480</guid>
      <dc:creator>Joseph Huber_1</dc:creator>
      <dc:date>2008-09-30T12:07:32Z</dc:date>
    </item>
    <item>
      <title>Re: [1,1] vs [SYSTEM] ie. [1,4]</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/1-1-vs-system-ie-1-4/m-p/4278386#M91481</link>
      <description>"set ownership of everything [1,1] to [1,4]?"&lt;BR /&gt;&lt;BR /&gt;Or vice versa?  eg. the initial system root created is owned by [1,1], however when I added a second root to the disk with CLUSTER_CONFIG (logged in as user SYSTEM), it creates it with the owner of [1,4].&lt;BR /&gt;&lt;BR /&gt;Which is "correct"?&lt;BR /&gt;&lt;BR /&gt;I did read the quoted previous post ... I should just tell the auditors to accept it as a "historical fact"?  We have a whole list of those already that they're not happy with ;-)&lt;BR /&gt;&lt;BR /&gt;Cheers,&lt;BR /&gt;Art</description>
      <pubDate>Tue, 30 Sep 2008 12:51:24 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/1-1-vs-system-ie-1-4/m-p/4278386#M91481</guid>
      <dc:creator>Art Wiens</dc:creator>
      <dc:date>2008-09-30T12:51:24Z</dc:date>
    </item>
    <item>
      <title>Re: [1,1] vs [SYSTEM] ie. [1,4]</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/1-1-vs-system-ie-1-4/m-p/4278387#M91482</link>
      <description>Art,&lt;BR /&gt;&lt;BR /&gt;UAF&amp;gt; add/ident SYSTEMBUILD/VAL=UIC=[1,1]&lt;BR /&gt;would give the displays a "nice" human-friendly appearance. &lt;BR /&gt;-- and you can always "explain" that the original system was generated, hence "SYSTEMBUILD", and the next roots were "added" by "SYSTEM".  QED :-) &lt;BR /&gt;Worked for our editors, but then again, they had VERY little VMS knowledge, and VMS had relatively little to explain compared with Unix and M$.&lt;BR /&gt;(explanations were asked after an external party had been brought in to look for and report "suboptimal security points")&lt;BR /&gt;&lt;BR /&gt;hth&lt;BR /&gt;&lt;BR /&gt;Proost.&lt;BR /&gt;&lt;BR /&gt;Have one on me.&lt;BR /&gt;&lt;BR /&gt;jpe</description>
      <pubDate>Tue, 30 Sep 2008 13:37:07 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/1-1-vs-system-ie-1-4/m-p/4278387#M91482</guid>
      <dc:creator>Jan van den Ende</dc:creator>
      <dc:date>2008-09-30T13:37:07Z</dc:date>
    </item>
    <item>
      <title>Re: [1,1] vs [SYSTEM] ie. [1,4]</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/1-1-vs-system-ie-1-4/m-p/4278388#M91483</link>
      <description>If you want to know and research the undocumented and arcane history of UICs on OpenVMS, this whole area has its share of weirdnesses, bugs that have become features, and legacy behaviors.  Some go back into RSX-11.  Some are simply inexplicable.  Some appear to be old bugs that became set in concrete when they shipped.&lt;BR /&gt;&lt;BR /&gt;[1,2] was LIB.  [1,10] was Field.  [1,54] was one of the SYSEXE directories.  There are many others.   This was way more common prior to V4; back when parts of VAX/VMS itself needed RSX compatibility mode.&lt;BR /&gt;&lt;BR /&gt;Everything owned by [1,1] is a perfectly normal and correct and expected /SYSTEM volume.&lt;BR /&gt;&lt;BR /&gt;1: Best practices?  Ignore it.  This is normal.  (I'd not tend to stray off the rails here and tweak this to be "pretty", lest some future ECO or upgrade run into the tweaks and tip over.)  (BTW, it is likely that you will not be able to reset ownerships of everything over to [1,4] due to file locking - init and mount a scratch volume and try it.)&lt;BR /&gt;&lt;BR /&gt;2: because there's a collision with the username and the account name (for the first username created in the [1,*] group) when the system and its usernames are initially configured.  Longstanding bug/feature/oddity. &lt;BR /&gt;&lt;BR /&gt;This is a dark and dank and ancient and somewhat smelly corner of the whole environment, and (IMHO) best left alone and untouched.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 30 Sep 2008 14:36:37 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/1-1-vs-system-ie-1-4/m-p/4278388#M91483</guid>
      <dc:creator>Hoff</dc:creator>
      <dc:date>2008-09-30T14:36:37Z</dc:date>
    </item>
    <item>
      <title>Re: [1,1] vs [SYSTEM] ie. [1,4]</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/1-1-vs-system-ie-1-4/m-p/4278389#M91484</link>
      <description>Art,&lt;BR /&gt;&lt;BR /&gt;  "We have a whole list of those already that they're not happy with ;-)"&lt;BR /&gt;&lt;BR /&gt; What are they not happy about? This is the standard, out-of-the-box OpenVMS configuration that has passed C2 and even (for SEVMS) B1 security. If they're not happy, what would they like them changed to? Are they comfortable with the potential risks?&lt;BR /&gt;&lt;BR /&gt;  As Steve has pointed out, the group identifier SYSTEM cannot be created automatically as there is already a username identifier SYSTEM. I've seen people create group identifier "SYS", but I don't know if it was a help or hinderance.    &lt;BR /&gt;&lt;BR /&gt;  From an auditing perspective, there is no practical distinction between any UICs below MAXSYSGROUP, except to identifiy different users in audit logs (but then any of them has sufficient privilege to forge audit records...) Since there is no user [1,1] it can be thought of as indicating something owned by "the system", but not by the username "SYSTEM".&lt;BR /&gt;&lt;BR /&gt; Jan's suggestion of creating an identifier may help the uninitiated comprehend  it better, but it has no real impact on the security of the system. The risk is there may be (poorly written) software which assumes it will see ownership as the string "[1,1]" for system objects, which might be broken by such a change.&lt;BR /&gt;&lt;BR /&gt;  Remember, all this stuff dates back to V1.0 and beyond to prior operating systems. The broader security framework, including identifiers and ACLs was introduced in V4, WAY too late to change the historical baggage, so we're stuck with it.</description>
      <pubDate>Tue, 30 Sep 2008 23:17:54 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/1-1-vs-system-ie-1-4/m-p/4278389#M91484</guid>
      <dc:creator>John Gillings</dc:creator>
      <dc:date>2008-09-30T23:17:54Z</dc:date>
    </item>
    <item>
      <title>Re: [1,1] vs [SYSTEM] ie. [1,4]</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/1-1-vs-system-ie-1-4/m-p/4278390#M91485</link>
      <description>Less than or equal to MAXSYSGROUP.  &lt;BR /&gt;&lt;BR /&gt;Caution: UICs are shown in octal, MAXSYSGROUP is shown in decimal.&lt;BR /&gt;&lt;BR /&gt;--&lt;BR /&gt;&lt;BR /&gt;INITIALIZE&lt;BR /&gt;&lt;BR /&gt;  /SYSTEM&lt;BR /&gt;&lt;BR /&gt;     Requires a system UIC or SYSPRV (system privilege) privilege.&lt;BR /&gt;&lt;BR /&gt;     Defines a system volume. The owner UIC defaults to [1,1].&lt;BR /&gt;     Protection defaults to complete access by all ownership&lt;BR /&gt;     categories, except that only system processes can create top-&lt;BR /&gt;     level directories.&lt;BR /&gt;&lt;BR /&gt;--&lt;BR /&gt;&lt;BR /&gt;As for OpenVMS and auditors, the "Standard Ownership and Protection" appendix here tends to help:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://h71000.www7.hp.com/doc/732FINAL/aa-q2hlg-te/aa-q2hlg-te.HTMl" target="_blank"&gt;http://h71000.www7.hp.com/doc/732FINAL/aa-q2hlg-te/aa-q2hlg-te.HTMl&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;--&lt;BR /&gt;&lt;BR /&gt;(Yes, that file name is cap-HTM-lowercase-L.  Go figure.)</description>
      <pubDate>Wed, 01 Oct 2008 01:36:54 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/1-1-vs-system-ie-1-4/m-p/4278390#M91485</guid>
      <dc:creator>Hoff</dc:creator>
      <dc:date>2008-10-01T01:36:54Z</dc:date>
    </item>
    <item>
      <title>Re: [1,1] vs [SYSTEM] ie. [1,4]</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/1-1-vs-system-ie-1-4/m-p/4278391#M91486</link>
      <description>In my systems (several system disks) I can't see a single file or directory owned by [1,1].&lt;BR /&gt;The system disks started as version 1.5 factory installed in 1994, and never have been initialized since (except by image backup).&lt;BR /&gt;Maybe it had an initial SYS0.DIR owned by [1,1], but this has been removed since.&lt;BR /&gt;&lt;BR /&gt;So I think nothing in VMS requires [1,1] ownership, and changing from [1,1] to [system] should not be dangerous (just to satisfy the "auditors").</description>
      <pubDate>Wed, 01 Oct 2008 07:15:49 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/1-1-vs-system-ie-1-4/m-p/4278391#M91486</guid>
      <dc:creator>Joseph Huber_1</dc:creator>
      <dc:date>2008-10-01T07:15:49Z</dc:date>
    </item>
    <item>
      <title>Re: [1,1] vs [SYSTEM] ie. [1,4]</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/1-1-vs-system-ie-1-4/m-p/4278392#M91487</link>
      <description>Running on an OpenVMS 7.3-2 (for Alpha) I was able to change everything I found with 1,1 ownership to 1,4 (SYSTEM) ownership.  I had to... my auditors said either every file had a valid owner name OR they would shut me down.  (I am a government contractor, by the way.)&lt;BR /&gt;&lt;BR /&gt;So taking a laissez-faire attitude to [1,1] is not always possible.  The good news is that OpenVMS 7.x allows you to make the required changes, even to the volume itself.&lt;BR /&gt;&lt;BR /&gt;The only time this difference ever gave me fits was the weekend (many, many years ago) when our group transitioned from VMS 4.7 to 5.2 on a mixed-size VAXcluster.  The upgrade just would not fly.  Until we found that one of the commands was having trouble because the GROUP-level permissions for 1,1 didn't allow SYSTEM (at 1,4) to update or delete files.  Even though MAXSYSGROUP was set correctly at the time.  After a late-night call to Colorado and a bunch of detective work on our part, we found the booger that was set wrong and fixed it.  We have been using SYSTEM as owners of every resource except the stuff that a couple of third-party packages require.&lt;BR /&gt;&lt;BR /&gt;And thanks for the reminder of RSX-11M.  What a little workhorse that O/S turned out to be!&lt;BR /&gt;</description>
      <pubDate>Tue, 21 Oct 2008 16:27:16 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/1-1-vs-system-ie-1-4/m-p/4278392#M91487</guid>
      <dc:creator>Richard W Hunt</dc:creator>
      <dc:date>2008-10-21T16:27:16Z</dc:date>
    </item>
    <item>
      <title>Re: [1,1] vs [SYSTEM] ie. [1,4]</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/1-1-vs-system-ie-1-4/m-p/4278393#M91488</link>
      <description>Richard,&lt;BR /&gt;&lt;BR /&gt;I understand the auditor *issue*. That is why I would personally recommend that Art create an identifier (and a DISUSERed Username, if needed) without changing the file ownerships.&lt;BR /&gt;&lt;BR /&gt;The Identifier is a far safe alternative.&lt;BR /&gt;&lt;BR /&gt;- Bob Gezelter, &lt;A href="http://www.rlgsc.com" target="_blank"&gt;http://www.rlgsc.com&lt;/A&gt;</description>
      <pubDate>Tue, 21 Oct 2008 16:36:57 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/1-1-vs-system-ie-1-4/m-p/4278393#M91488</guid>
      <dc:creator>Robert Gezelter</dc:creator>
      <dc:date>2008-10-21T16:36:57Z</dc:date>
    </item>
    <item>
      <title>Re: [1,1] vs [SYSTEM] ie. [1,4]</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/1-1-vs-system-ie-1-4/m-p/4278394#M91489</link>
      <description>re: Richard&lt;BR /&gt;&lt;BR /&gt;&amp;gt; my auditors said either every file had a &lt;BR /&gt;&amp;gt; valid owner name&lt;BR /&gt;&lt;BR /&gt;  I'd have thought a much simpler, and more reliable way to comply with this demand would be to do as Art and Jan suggested -create a UAF record for [1,1] with a valid name in the Owner field.&lt;BR /&gt;&lt;BR /&gt;  That way you don't have to modify any files, and you don't need to concern yourself with missing anything. Everyone is happy and you solve the problem for all time with a single command (including upgrades, patches and other events that might introduce new files or devices with [1,1] ownership)</description>
      <pubDate>Tue, 21 Oct 2008 19:45:11 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/1-1-vs-system-ie-1-4/m-p/4278394#M91489</guid>
      <dc:creator>John Gillings</dc:creator>
      <dc:date>2008-10-21T19:45:11Z</dc:date>
    </item>
    <item>
      <title>Re: [1,1] vs [SYSTEM] ie. [1,4]</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/1-1-vs-system-ie-1-4/m-p/4278395#M91490</link>
      <description>Immaterial to create a [1,1] account now, I've long ago made the change to [1,4].&lt;BR /&gt;&lt;BR /&gt;But thanks for the diversity of opinions.&lt;BR /&gt;</description>
      <pubDate>Wed, 22 Oct 2008 21:57:58 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/1-1-vs-system-ie-1-4/m-p/4278395#M91490</guid>
      <dc:creator>Richard W Hunt</dc:creator>
      <dc:date>2008-10-22T21:57:58Z</dc:date>
    </item>
  </channel>
</rss>

