- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- /etc/securetty file
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-02-2004 10:21 AM
03-02-2004 10:21 AM
I attempted to prevent people from accessing
the system w/ ('root' ID) remotely. I thought I could control this with the `securetty` file ? but it does not work. I also viewed the
'/var/adm/inetd.sec`, but found no help there.
Please advised. Thanks.
# ll /etc/securetty
-rw-r--r-- 1 root sys 8 Jan 29 15:12 /etc/securetty
cat /etc/securetty
console
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-02-2004 10:23 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-02-2004 10:27 AM
03-02-2004 10:27 AM
Re: /etc/securetty file
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-02-2004 10:28 AM
03-02-2004 10:28 AM
Re: /etc/securetty file
I believe you checked for any ghost characters in /etc/securetty file. It should work.
Are you saying "root" is able to login directly with telnet|rlogin even with this file?
-Sri
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-02-2004 10:30 AM
03-02-2004 10:30 AM
Re: /etc/securetty file
Folder .ssh on home directory of "root" has the files that allows people to ssh in.
-- Rod Hills
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-02-2004 10:32 AM
03-02-2004 10:32 AM
Re: /etc/securetty file
The /etc/inetd.conf has:
telnet
rlogin
login
rexec
and so on commented out.
Only "ssh & ftp" are allowed.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-02-2004 10:33 AM
03-02-2004 10:33 AM
Re: /etc/securetty file
You need to modify your sshd_config file so that the line with PermitRootLogin is uncommented and is set to "no".
Then restart your sshd daemon.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-02-2004 01:42 PM
03-02-2004 01:42 PM
Re: /etc/securetty file
All you'd have to do is "echo root>/etc/ftpd/ftpusers" and root should be denied access immediately. The ownership of the file should be "bin:bin" and the permissions 664.
Check out the man page for ftpusers for a little more info.
Regards,
Seth
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-02-2004 09:32 PM
03-02-2004 09:32 PM
Re: /etc/securetty file
file /etc/securetty must contain:
console
/dev/console
then remote access as root would be disabled
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-02-2004 09:37 PM
03-02-2004 09:37 PM
Re: /etc/securetty file
If you have SSH implemented on your systems then you need to set permitrootlogin to NO in the ssh config file.
If you don't have SSH implemented then look at making changes to inetd.conf file
rgds
Mobeen
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-03-2004 04:15 AM
03-03-2004 04:15 AM
Re: /etc/securetty file
The "PermitRoot" modification in "sshd_config" works. Thanks....... :>)