- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - Linux
- >
- I need help finding a way to search for disabled a...
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Forums
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-26-2007 08:26 AM
тАО10-26-2007 08:26 AM
I need help finding a way to search for disabled account in linux
I need help finding a way to search for disabled account in linux..
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-26-2007 08:28 AM
тАО10-26-2007 08:28 AM
Re: I need help finding a way to search for disabled account in linux
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-26-2007 11:03 AM
тАО10-26-2007 11:03 AM
Re: I need help finding a way to search for disabled account in linux
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-26-2007 11:14 AM
тАО10-26-2007 11:14 AM
Re: I need help finding a way to search for disabled account in linux
# /sbin/pam_tally --user kumarts
User kumarts (19806) has 0
the last field 0 tell the account is NOT locked.
May be i am confused with account deactivated and locked. What is the diffrence between deactivated and locked.
My intention is to delete the deactivated accounts. But i DONT want the accounts to be deleted whihc are locked (example due to 5 login failures; a needed account can be in locked state at that point of time).
So i want to identify only deactivated accounts?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-26-2007 11:57 AM
тАО10-26-2007 11:57 AM
Re: I need help finding a way to search for disabled account in linux
i.e.
awk -F':' '{ if ($2 == "") { printf ("%s is disabled\n", $1) } }' /etc/shadow
But I guess this will depend on how the user was 'disabled'.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-27-2007 02:00 AM
тАО10-27-2007 02:00 AM
Re: I need help finding a way to search for disabled account in linux
What kind of authentication are u using? LDAP,PAM,Kerberos?
A simple way to disable an account login is to put the last field in /etc/passwd as /sbin/false or in some systems /sbin/nologin.
They act like /dev/null (blackhole)
Hope this help you out.
Regards
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-27-2007 01:00 PM
тАО10-27-2007 01:00 PM
Re: I need help finding a way to search for disabled account in linux
able to root only.
that says "disable a password for an account".i am loking for disabled account/id.
I use pam authentication.I am not looking for "how to prevent login for an account".
below is an example for three different(only) entries in shadow file. the last one is an active account. But not sure what that * and !! means
# egrep -i "kumarts|adm|rpc" /etc/shadow
adm:*:13738:0:99999:7:::
rpc:!!:13738:0:99999:7:::
kumarts:$1$dSKpkrZZ$C/oJlIsnzij8R0Kb.d1MA0:13801:7:60:20:30::
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-27-2007 07:05 PM
тАО10-27-2007 07:05 PM
Re: I need help finding a way to search for disabled account in linux
That flag removes the passwored entirely from the shadow file.
!! in the shadow file is impossible to match a password, and is considered 'locked'.
As for '*', on it's own it is also unmatchable.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-28-2007 11:44 AM
тАО10-28-2007 11:44 AM
Re: I need help finding a way to search for disabled account in linux
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-28-2007 06:29 PM
тАО10-28-2007 06:29 PM
Re: I need help finding a way to search for disabled account in linux
Entries in the shadow file with '!!' or '*' in the password file are usualy system users that services use, but never log in. It is impossible to log in as these users usually by means other than the 'su' command.
Entries with '!
So, it all comes down to what is in place on your system for disabling users. If you are only using the expiration of passwords to disable users, none of this discussion takes it into account. See 'chage' and the 'passwd' tools for more details on that.