- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- securetty functionality for non-root users
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-09-2003 09:05 AM
10-09-2003 09:05 AM
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-09-2003 09:25 AM
10-09-2003 09:25 AM
SolutionThink you are looking for this solution.
http://forums1.itrc.hp.com/service/forums/parseCurl.do?CURL=%2Fcm%2FQuestionAnswer%2F1%2C%2C0x7924cbaac6dcd5118ff40090279cd0f9%2C00.html&admit=716493758+1065734732126+28353475
Hope it helps,
Robert-Jan.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-09-2003 09:50 AM
10-09-2003 09:50 AM
Re: securetty functionality for non-root users
So securetty is used to restrict root access only and has no relation to other login accounts.
What you're describing is what the 'last' command is for.
# last account
# last -b account
# last -R account
You can also restrict 'rlogins', force all to use 'telnet' and track in syslog.log. Add -l to /etc/inetd.conf:
telnet stream tcp nowait root /usr/sbin/in.telnetd in.telnetd -l
You can also look into /sbin/init.d/acct, system accounting, but this is usually reserved for expense charging for time.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-10-2003 03:31 AM
10-10-2003 03:31 AM
Re: securetty functionality for non-root users
Typically the contents of this file would read :-
console
So the root account can only be logged in from the console.
Please note the /etc/securetty file does not prevent a user from using the root login if that user is using something call CDE (Common Desktop Environment). In this case you must edit the file /etc/dt/config/Xstartup to contain the following :-
if [ $USER = root ] ; then
exit 1
fi
The other option if using CDE is to cp the file usr/dt/config/Xstartup to /etc/dt/config/Xstartup.
An additional security measure is to setup an su group to allow only a certain number of people to su to root. This can be achieved by creating an entry in /etc/default/security :-
SU_ROOT_GROUP=groupname
where groupname corresponds to the name of the group in /etc/group file that should be allowed to use su to root. Root does not need to be a member of this group !
Hope this helps.
Keith
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-10-2003 03:42 AM
10-10-2003 03:42 AM