- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Disabling rlogin will affect service guard?
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-14-2011 10:52 PM
тАО02-14-2011 10:52 PM
Disabling rlogin will affect service guard?
I have 2 node cluster running ServiceGuard A.11.16.00 on hpux11.23.
I need to disable rlogin on both nodes for fixing security vulnerability suggested by auditors.
I can see .rhost file present on both nodes that will accept rlogin for root user from any nodes.
# cat .rhosts
+
#
there is no /etc/cmcluster/cmnodelist on both nodes
will it make any impact on service guard if i disable rlogin ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-14-2011 11:17 PM
тАО02-14-2011 11:17 PM
Re: Disabling rlogin will affect service guard?
The same case in our security team requested disable rlogin and remote shell exe.. etc ..last week i did its not affecting. before make changes plase take bakup of /etc/cmcluster/package file ..
Note : After i disabled the /etc/init.d services for rlogin.
Regards
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-14-2011 11:31 PM
тАО02-14-2011 11:31 PM
Re: Disabling rlogin will affect service guard?
Just make sure that the DNS names of all the interfaces on both systems are listed in cmclnodelist
So for example if you have 2 hosts called nodeA and nodeB, and they have additional interfaces called nodeA-hb, nodeB-hb (hearbeat LAN) , and interfaces called nodeA-bu and nodeB-bu (backup LAN), then you would want the following in cmclnodelist :
nodeA root
nodeA-hb root
nodeA-bu root
nodeB root
nodeB-hb root
nodeB-bu root
HTH
Duncan
I am an HPE Employee

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-15-2011 01:08 AM
тАО02-15-2011 01:08 AM
Re: Disabling rlogin will affect service guard?
I dont have /etc/cmcluster/cmnodelist file on both nodes.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-15-2011 01:32 AM
тАО02-15-2011 01:32 AM
Re: Disabling rlogin will affect service guard?
HTH
Duncan
I am an HPE Employee

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-15-2011 03:40 AM
тАО02-15-2011 03:40 AM
Re: Disabling rlogin will affect service guard?
I understand that /etc/cmcluster/cmnodelist or .rhost file is used only when we apply a clusture configuration. A running cluster or packages do not read /etc/cmcluster/cmnodelist or .rhost file to login to other cluster nodes...Please correct me if i am wrong..
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-15-2011 03:58 AM
тАО02-15-2011 03:58 AM
Re: Disabling rlogin will affect service guard?
HTH
Duncan
I am an HPE Employee

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-15-2011 03:46 PM
тАО02-15-2011 03:46 PM
Re: Disabling rlogin will affect service guard?
some of the serviceguard commands will not work without a cmclnodelist
create it. It should not be a problem.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-15-2011 04:28 PM
тАО02-15-2011 04:28 PM
Re: Disabling rlogin will affect service guard?
>> +
This is the worst possible content for root's .rhosts file on any system. It essentially says:
Trash my system, there is no security here!
If you need rlogin/remsh/rcp between two computers, put *only* those computer names and user login names in the .rhosts file. Putting + in there is the same as removing the password for root.
Bill Hassell, sysadmin