- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Re: root access only from console
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-09-2002 09:06 AM
12-09-2002 09:06 AM
we are planning some security enhancment now, one proposal is to allow root access only from console, not through telnet.
can we do it by /var/adm/inetd.sec? not sure we can specify users in that file. or there are other ways to do it?
thanks,
Gary
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-09-2002 09:10 AM
12-09-2002 09:10 AM
SolutionHave a look at this link. This has been addressed quite a few times in this forum. You may also search on "root access console".
http://forums.itrc.hp.com/cm/QuestionAnswer/1,,0xb82706350fe2d61190050090279cd0f9,00.html
HTH,
Dave
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-09-2002 09:11 AM
12-09-2002 09:11 AM
Re: root access only from console
seen on http://docs.hp.com/hpux/onlinedocs/B2355-90742/B2355-90742.html
[system security]
[this is assuming you're using HP-UX 11.0]
Tracking Root
A useful method to keep track of system access and reduce security breaches on standard and trusted servers is to physically secure the system console and allow root to login only at the system console. Users logging in through other ports must first log in as themselves, then execute su to become root.
To limit root to logging in only through the system console, create the /etc/securetty file with the single entry, console, as follows:
# echo console > /etc/securetty
docs.hp.com is your friend...
Cheers,
Fran??ois-Xavier
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-09-2002 09:11 AM
12-09-2002 09:11 AM
Re: root access only from console
/etc/securetty
console
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-09-2002 09:14 AM
12-09-2002 09:14 AM
Re: root access only from console
HP can do it as well.
Someone will post the manual way of doing it.
You could be lazy like me and just install the Bastille security tool. For political reasons I declined, but it has a step that will disable root access from anywhere but the console.
Here is a link
https://payment.ecommerce.hp.com/cgi-bin/swdepot_parser.cgi/cgi/try.pl?productNumber=B6849AA&date=
Its off a search at software.hp.com for Bastille, btw.
If you are really concerned about security, Bastille is the way to go. It also enhances system performance, because it stops the use of some dated daemon's that run be default and nobody actually uses any more.
Don't forget to disable X-Windows root access.
I recommend the Practical Network Security class from HP. It's a five day class, it teaches you all of the above except Bastille(which was recently ported from Linux), and teaches you how hackers work and how to defeat them.
Regards,
Steve
Please assign points to people who spent timie, trying to help you.
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-09-2002 09:15 AM
12-09-2002 09:15 AM
Re: root access only from console
console
Owner of that file should be root:bin and permission 600. This is for security reason.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-09-2002 09:16 AM
12-09-2002 09:16 AM
Re: root access only from console
# cat /etc/securetty
console
#
Note that there is no '/dev/' in front of the word console.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-09-2002 09:22 AM
12-09-2002 09:22 AM
Re: root access only from console
Fran??ois is right, docs.hp.com is our friend, and I would also say this forum is our friend!
thanks again,
Gary
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-09-2002 09:44 AM
12-09-2002 09:44 AM
Re: root access only from console
console