- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Re: block telnet for root only ..
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-07-2002 01:51 PM
02-07-2002 01:51 PM
I am trying to block telnet for root only. But I have another user with an id of 0 that needs to be able to telnet. I did /etc/securetty but that blocks everything with the uid of 0. Is there another only the user name of root form telnet?
Richard
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-07-2002 01:59 PM
02-07-2002 01:59 PM
Re: block telnet for root only ..
You could try to set up a evaluation
of the user in the /etc/profile that
screens each user.
-Michael
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-07-2002 02:01 PM
02-07-2002 02:01 PM
Re: block telnet for root only ..
# cat /etc/securetty
console
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-07-2002 02:03 PM
02-07-2002 02:03 PM
Re: block telnet for root only ..
if [ $LOGNAME = 'badUser' ]
then
exit 1
fi
Richard
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-07-2002 02:04 PM
02-07-2002 02:04 PM
Re: block telnet for root only ..
yes
/etc/securetty
blocks all uids of 0.
Richard
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-07-2002 02:06 PM
02-07-2002 02:06 PM
Re: block telnet for root only ..
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-07-2002 02:11 PM
02-07-2002 02:11 PM
SolutionI should have thought of this before. I hope that this works.
Create /etc/nologin
Modify your /etc/profile with
if [ -f /etc/nologin && ${LOGNAME} != "root" ]
then
echo "Not allowed to login as UID 0"
exit 1
fi
This way you don't need to modify anything else on your system, if you want to get rid of it just remove the /etc/nologin file
HTH
-Michael
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-07-2002 03:08 PM
02-07-2002 03:08 PM
Re: block telnet for root only ..
richard
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-07-2002 03:20 PM
02-07-2002 03:20 PM
Re: block telnet for root only ..
Any account with a uid=0 *is* "root". It would seem that your trying to close the barn door after the horses have gotten out!
Regards!
...JRF...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-07-2002 03:27 PM
02-07-2002 03:27 PM
Re: block telnet for root only ..
That way you can use securetty and still get access.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-07-2002 04:25 PM
02-07-2002 04:25 PM
Re: block telnet for root only ..
One further thing... Why not have everything
but the console still locked down with /etc/securetty
and....set up sudo, so that you can control what user uses what. I'm not sure of the reasoning as to why you want a second account using the uid of 0.
-Michael
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-07-2002 04:33 PM
02-07-2002 04:33 PM
Re: block telnet for root only ..
Instead, assign root privileges explcitly by usinge SAM -r (restricted SAM) or by getting a copy of sudo.
Bill Hassell, sysadmin