1847000 Members
4024 Online
110257 Solutions
New Discussion

Re: Restricted SAM

 
SOLVED
Go to solution
Charles Legge
Occasional Contributor

Restricted SAM

Hello, I'm on 'D' class servers running HPUX 10.20. Are there safeguards in Restricted SAM that would not allow changes to key system accounts like ROOT, specified System Administration accounts,
etc. even though they can be viewed? It appears that changes could be made to these key accounts through restricted SAM? I'm familiar with the /etc/sam/rmuser.excl file which disables deletion of
specified accounts. My concern is someone making changes to ROOT and other key System Administration accounts (without authorization)?
Thanks
4 REPLIES 4
Helen French
Honored Contributor
Solution

Re: Restricted SAM

Even through restricted SAM, you cannot restrict the actual functionality of SAM. The only control you have is to allow or deny users access to areas within SAM. If you are concerned about the admin area security, then deny access to those areas.
Life is a promise, fulfill it!
Helen French
Honored Contributor

Re: Restricted SAM

Again, you don't need to worry about somebody changing the root password through restricted SAM. Becuase in restricted SAM, it will not allow to change the root password or the passwd of any user with a UID of 0.
Life is a promise, fulfill it!
S.K. Chan
Honored Contributor

Re: Restricted SAM

When you got a restricted SAM setup for say a normal user, you're basically allowing him to to use SAM as if he/she is root. To control what this user can do in restricted SAM, you got to configure which screen to allow or disallow. I think this is done in the restricted SAM builder. You can even configure say, you do not want the user to be able to change root's password (but he can change passwords of other users). It really depends on how you want to set it up and what funtionality you want to allow in the restricted SAM.
Charles Legge
Occasional Contributor

Re: Restricted SAM

Hello, Thanks for the answers. I believe you've answered my question and concerns. Charles.