Operating System - HP-UX
1826206 Members
2557 Online
109691 Solutions
New Discussion

rlogin but no remsh on 11.23

 
Steve Lewis
Honored Contributor

rlogin but no remsh on 11.23

Our new 11.23 Itanic vpar'd machine is bringing up some unexpected surprises.

For instance, one user who has specified his .rhosts files perfectly at both ends (from dev server on 11.11 to test_vpar on 11.23) can rlogin without password but when he tries to remsh hostname ls is says Login incorrect.

>rlogin vpsp
Please wait...checking for disk quotas

>remsh vpsp ls
remshd: Login incorrect.

Any ideas? We are pretty sure that we have set up our vpar just like all our other boxes.

Oh and the inetd.conf does have both services (rlogin and remsh) enabled - by default.

Our other problem is that we can ping the vpar and ping out, by hostname (nsquery and nslookup work fine without any delay), but we cannot traceroute from the vpar out of the local subnet. It just hangs. We are using traceroute -i lan0 hostname and it doesn't even print up the default router.
2 REPLIES 2
Steven E. Protter
Exalted Contributor

Re: rlogin but no remsh on 11.23

Shalom Steve,

Nice name.

I'd check the obvious suspects, the configuration of the vpars inetd.conf and the syslog.log files. There has to be a clue. I'm guessing there is a mistake on the remesh line in inetd.conf

Shame on HP for keeping these services enabled and Ignite depending on them in this security conscious day and age.

You might want to see if your remesh user can live with Secure Shell ssh. Normally they can.

SEP
Steven E Protter
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
Steve Lewis
Honored Contributor

Re: rlogin but no remsh on 11.23

Nice name also !

Anyway I finally fixed the problem using a combination of:
1. Running bastille to re-specify the security settings.
2. Implementing the IPv6 turn-off specified in this angry thread:
http://forums1.itrc.hp.com/service/forums/questionanswer.do?threadId=882565

11.23 comes with iptables and some other security settings pre-set, which stopped lots of things working such as remote CDE which starts with a remsh hostname dterm