- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Direct Root Login
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-23-2010 05:06 AM
тАО02-23-2010 05:06 AM
Direct Root Login
Please tell me the steps to enable direct root login access in HP Unix 11i v3.
I have made the parameter PermitRootLogin yes in /etc/opt/ssh/sshd_config file.
Have restarted the sshd also.. But still am unable to login directly with root.
Could you please help me.
Many Thanks!
Pauline
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-23-2010 05:12 AM
тАО02-23-2010 05:12 AM
Re: Direct Root Login
cat /etc/securetty
and see if thrd "console" is there in the file . if yes than comment out that console but this is not recommended due to security reasons because root can only login from the console. os the best practice is
login as a simple user and do su to root.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-23-2010 05:12 AM
тАО02-23-2010 05:12 AM
Re: Direct Root Login
Kindly send the o/p of ps -ef |grep -i ssh command.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-23-2010 05:13 AM
тАО02-23-2010 05:13 AM
Re: Direct Root Login
You should check your log files in order to find more informations about this issue.
Check /var/adm/syslog/syslog.conf)
Horia.
Horia.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-23-2010 05:16 AM
тАО02-23-2010 05:16 AM
Re: Direct Root Login
/etc/securetty file is not available in my server.
Here is the o/p of ps -ef |grep sshd
wfapp:root-/>ps -ef |grep sshd
root 8623 1 0 Feb 22 ? 0:00 sshd: dr199476 [priv]
dr199480 14567 14565 0 18:43:25 ? 0:00 sshd: dr199480@pts/6
root 14565 8876 0 18:43:20 ? 0:00 sshd: dr199480 [priv]
root 8876 1 0 Feb 22 ? 0:00 /opt/ssh/sbin/sshd
root 14609 14581 0 18:44:16 pts/6 0:00 grep sshd
dr199476 8625 8623 0 Feb 22 ? 0:00 sshd: dr199476@pts/5
wfapp:root-/>
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-23-2010 05:18 AM
тАО02-23-2010 05:18 AM
Re: Direct Root Login
you need to change the parameter
PermitRootLogin yes in the following file
/opt/ssh/etc/sshd_config.
& then restart the daemon.
Rgds.,
Sachin Kumbla
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-23-2010 05:22 AM
тАО02-23-2010 05:22 AM
Re: Direct Root Login
As I mentioned earlier I have done changes in sshd_config file as well restarted the sshd daemon.
Dear Horia,
I could not find any file syslog.conf under /var/adm/syslog/ directory.
This server is hardened with Bastille Hardening Tool.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-23-2010 05:25 AM
тАО02-23-2010 05:25 AM
Re: Direct Root Login
Check /etc/syslog.conf in order to find out where the syslogd daemon writes the logs.
Horia.
Horia.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-23-2010 05:27 AM
тАО02-23-2010 05:27 AM
Re: Direct Root Login
Bastille does not have any customization to disallow root logins from remote? You should check this.
Horia.
Horia.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-23-2010 05:59 AM
тАО02-23-2010 05:59 AM
Re: Direct Root Login
try placing # in all Permit from ssh config file.
# grep -i Permit /opt/ssh/etc/sshd_config
#PermitRootLogin forced-commands-only
#PermitEmptyPasswords no
# PasswordAuthentication, PermitEmptyPasswords, and
# "PermitRootLogin without-password". If you just want the PAM account and
#PermitUserEnvironment no
#PermitTunnel no
HTH,
Johnson
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-23-2010 06:03 AM
тАО02-23-2010 06:03 AM
Re: Direct Root Login
Hoping that bastille configuration does not come into picture.
Since this server is running HP 11i v3, is there any other changes need to be done??
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-23-2010 06:07 AM
тАО02-23-2010 06:07 AM
Re: Direct Root Login
What happens when you attempt to login as root? What command do you run? What error do you get? Commands run and actual errors received would be a very big help in trying to solve this.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-23-2010 06:11 AM
тАО02-23-2010 06:11 AM
Re: Direct Root Login
http://docs.hp.com/en/B2355-90950/apbs01.html
"Q: Should Bastille disallow root logins from network tty's? [N] [N]
Level: Account Security
Bastille can restrict root from logging into a tty over the network.
This will force administrators to log in first as a non-root user, then
su to become root. Root logins will still be permitted on the console and
through services that do not use tty's ( e.g. HP-UX Secure Shell ).
This can stop an attacker who has only been able to steal the root password
from logging in directly to a tty. The attacker has to steal a second account's
password to make use of the root password via the network, or gain access to a
non-tty login mechanism.
MAKE SURE that you can login using a non-root account before you do this,
or you will obviously need access to the console or a non-tty remote login
mechanism, e.g. Secure Shell, to login."
Horia.
Horia.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-23-2010 06:17 AM
тАО02-23-2010 06:17 AM
Re: Direct Root Login
Am just trying to login to my server via ssh through putty with root login.
Its just giving "Access Denied".
Dear Horiam
I checked this parameter in bastille configuration file.
# Q: Should Bastille disallow root logins from network TTYs? [N]
AccountSecurity.create_securetty="N"
Its not enabled..
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-23-2010 06:24 AM
тАО02-23-2010 06:24 AM
Re: Direct Root Login
Just enable telnet (if not allready enabled) on the server and try to actually telnet into this server from a remote location.
Also, you should try to find out if
ssh localhost
is working on the server (in order to find out if you have a global issue or only a network related problem).
Horia.
Horia.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-23-2010 06:35 AM
тАО02-23-2010 06:35 AM
Re: Direct Root Login
I tried to ssh localhost...Prompted for root password.. after giving the password it says "Permission denied, please try again.
"
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-23-2010 06:39 AM
тАО02-23-2010 06:39 AM
Re: Direct Root Login
Horia.
Horia.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-23-2010 06:43 AM
тАО02-23-2010 06:43 AM
Re: Direct Root Login
/etc/securetty
Which is his content?
cat /etc/securetty
Horia.
Horia.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-23-2010 06:45 AM
тАО02-23-2010 06:45 AM
Re: Direct Root Login
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-25-2010 04:16 AM
тАО02-25-2010 04:16 AM
Re: Direct Root Login
login to the console and check #ssh 0 or #telnet 0. if it is not working then revert back the bastille and try it...
Thanks,
Shanmugam.B
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО03-04-2010 06:25 AM
тАО03-04-2010 06:25 AM
Re: Direct Root Login
Though I made PermitRootLogin yes in sshd_config file..I missed to do a proper restart of ssh.
#/sbin/init.d/secsh stop
#/sbin/init.d/secsh start
I used to kill the sshd process and restart /opt/ssh/sbin/sshd which actually didnt work.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО03-04-2010 06:31 AM
тАО03-04-2010 06:31 AM
Re: Direct Root Login
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО03-04-2010 09:35 AM
тАО03-04-2010 09:35 AM