- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- How to disable direct login access to some users o...
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-24-2006 06:33 PM
07-24-2006 06:33 PM
How to disable direct login access to some users on HP-UX 11i v2? Is there any file in which the user entries can be added?
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-24-2006 06:45 PM
07-24-2006 06:45 PM
Re: How to disable direct login access to some users on HP-UX 11i v2
You can not restrict telnet using userid but yes you can restrict ftp
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-24-2006 07:10 PM
07-24-2006 07:10 PM
Re: How to disable direct login access to some users on HP-UX 11i v2
you can give them /usr/bin/false as login shell or disable the password; scripting in /etc/profile is another way.
The method depends on what these users are allowed to do.
mfG Peter
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-24-2006 07:34 PM
07-24-2006 07:34 PM
Re: How to disable direct login access to some users on HP-UX 11i v2
1. make user shell to /dev/false
2. Put an "exit" in users .profile
3. Deactivate the account
-wip
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-24-2006 07:52 PM
07-24-2006 07:52 PM
Re: How to disable direct login access to some users on HP-UX 11i v2
Take away their user accounts.
You will need a strict office policy that prevents user id sharing.
SEP
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-24-2006 09:42 PM
07-24-2006 09:42 PM
Re: How to disable direct login access to some users on HP-UX 11i v2
We have an application which runs through appl user But the support guys have to login with their user id's(unique) and then su to that appl user and have to do the support work. We have to restrict direct user access to appl user only. By changing the user shell to /usr/bin/false i am unable to su to that appl user (infact it is logging in and logging out at the same time).
Regards,
Satish
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-24-2006 10:06 PM
07-24-2006 10:06 PM
Solutionfor the application login I suggest to setup that id with an invalid password entry but create ssh-keys for these users and put them to
~applusr/.ssh/authorized_keys
So they will be able to switch to that user via ssh only without the need of a password but a normal login to that userid will not be possible:
ssh appluser@hostname
Next I would change the loginshell of that appluser (preferred) to the application program or do some scripting in ~/.profile so that there is a direct start of the application at login time.
mfG Peter