- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Removing direct root access
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-02-2003 01:02 AM
10-02-2003 01:02 AM
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-02-2003 01:05 AM
10-02-2003 01:05 AM
Solution/etc/securetty
If the /etc/securetty file exits, root user is only allowed to login in the tty's listed in this file.
Normally, you allow root logins ONLY at
the console. On all other logins must be logged in using user's own id's. If they are needing root priviledge, they will have to su -.
Now, that user needs to do su's to become root, all su's are logged in
/var/adm/sulog.
To do this, create /etc/securetty with only the console entry.
Hope this helps,
Francis DERDEYN - HP-UX ASCE.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-02-2003 01:06 AM
10-02-2003 01:06 AM
Re: Removing direct root access
You do this by creating the following file
/etc/securetty
and placing one word in it
console
Then set perms to 400 (-r--------) & ownership to root:sys
HTH,
Jeff
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-02-2003 01:07 AM
10-02-2003 01:07 AM
Re: Removing direct root access
Then root will only be allowed to login directly via the console.
HTH.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-02-2003 01:09 AM
10-02-2003 01:09 AM
Re: Removing direct root access
add:
console
This prevents rlogins of form:
rlogin host -l root
but still allows root logins from other hosts with entries in $ROOT_HOME/.rhosts
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-02-2003 01:18 AM
10-02-2003 01:18 AM
Re: Removing direct root access
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-02-2003 01:20 AM
10-02-2003 01:20 AM
Re: Removing direct root access
There is still something missing here :-)
/etc/securetty is not checked if your users are going to try to log in via CDE. The reason is that /etc/securetty "lists the valid ttys for root login". Since CDE does not use a tty to login the /etc/securetty
has no effect !!
To bypass that limitation, you will need to modify the /etc/dt/config/Xstartup to disable
root console login via CDE.
You might also be interested to use the file /usr/dt/config/Xaccess which restricts external CDE access based on host(IP).
Hope this helps, Bye.
Francis DERDEYN - HP-UX ASCE.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-02-2003 02:10 AM
10-02-2003 02:10 AM
Re: Removing direct root access
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-02-2003 02:19 AM
10-02-2003 02:19 AM
Re: Removing direct root access
To secure FTP, go here :
http://www.newfdawg.com/SHP-FTP-ftpaccess.htm
and here :
http://www.newfdawg.com/SHP-FTP-ftphosts.htm
Hope this helps, Bye.
Francis DERDEYN - HP-UX ASCE.