Operating System - HP-UX
1833701 Members
4084 Online
110062 Solutions
New Discussion

password shadow for hp-ux 10.10

 
Eduardo Andrade
Occasional Advisor

password shadow for hp-ux 10.10

Hi
Im have configure /etc/default/security on server D390 with hp-ux 10.0 and two L1000 with hpux11.0 but the shadow password find only for hp-ux 11.11.

Help me to validate and find this depot for this versions.

Best Regards
5 REPLIES 5
Pete Randall
Outstanding Contributor

Re: password shadow for hp-ux 10.10

Shadow password was a recently developed feature (well after 10.x became obsoleted) and therefore was not built for those earlier releases, only 11i.


Pete

Pete
Michal Toth
Regular Advisor

Re: password shadow for hp-ux 10.10

hmm, sorry to say, but 10.20 is not supported since June 2003. Therefore securing 10.20 is just plain waste of time (would you care for security if you'd run windows 95 today?)
Eduardo Andrade
Occasional Advisor

Re: password shadow for hp-ux 10.10

Thanks Pete , exist other way to enable password policies on this systems?
OldSchool
Honored Contributor

Re: password shadow for hp-ux 10.10

I don't have a 10.x system around to check, but I think you're out of luck. Do a "man passwd" and read throughly. At 11.0, you can get support for *some* features w/ patching. These were noted in the man page. Don't know if 10.x is similar in this regard. Even if it is, I don't believe your going to be able to get patches for that version of the OS.

10.10 is way out of date - even 11.0, it successor is scheduled for end of life at the end of the year. not sure what, if any, OS upgrade options you have on that platform
Bill Hassell
Honored Contributor

Re: password shadow for hp-ux 10.10

10.10 is very, very obsolete and because of it's age, a big security risk. The world has changed dramatically in the last 10 years but your version of HP-UX has not (and never will be). So there is no shadow password for 10.10.

However, you can convert to a Trusted system using SAM and set policies using SAM. The /etc/default/security is meaningless on 10.10 so ignore the man pages from more modern systems. It sounds like there is a concern for the security of this system -- which means you need to migrate to a modern version of HP-UX, 11.11 will run on your D390. I know that there is probably some legacy application that can't be converted -- you just have to weigh the danger of poor security with the value of the data and the application.


Bill Hassell, sysadmin