Operating System - HP-UX
1819684 Members
3499 Online
109605 Solutions
New Discussion юеВ

Trusted System advantages and disadvantages

 
bachi
Occasional Advisor

Trusted System advantages and disadvantages

Hi ,

if we will convert one standard system into trusted system, what are the advantages and disadvantages of its. if we will convert system into trusted mode is there ay services disable? and any users will effect?

could you please help some one to get this details.
Thanks,
Balaji.
5 REPLIES 5
Bill Hassell
Honored Contributor

Re: Trusted System advantages and disadvantages

A standard system has primitive security. Things like an 8 character password limit and a trivial password aging policy. That's it. Nothing else is secured. If your server is not important, stay with standard security.

Converting to Trusted will not affect any service. Users will be affected because if they forget their password, their login may be locked out. That also affects the system administrator who must unlock the login when users forget their password.

The main advantage is that proper controls for passwords and access can be set. You can set an automatic expiration for password renewal, prevent users from using the same passwords over and over, control the hours that a user may login, etc. Read the man page for security (man security) for some of the possible settings.

DO NOT convert your system using tsconvert. Use SAM and select the auditing line. This will convert your system without the all too common problem of having all the logins locked out.

The only disadvantage is with dubious software that does not understand a Trusted system. If this software doesn't work correctly, I would not put it on your system. For newer versions of HP-UX, you can use Shadow Password rather than Trusted which is more compatible with old software.


Bill Hassell, sysadmin
Dennis Handly
Acclaimed Contributor

Re: Trusted System advantages and disadvantages

>Bill: For newer versions of HP-UX, you can use Shadow Password rather than Trusted which is more compatible with old software.

Basically Trusted System is deprecated in 11.31. See:
http://forums.itrc.hp.com/service/forums/questionanswer.do?threadId=1267727
bachi
Occasional Advisor

Re: Trusted System advantages and disadvantages

Hi ,

thanks for you reply and answer. if user login will ocked , admiistrator should be unlock this. if administrator id also locked, in this case how come we retrive the password or reset the new password?
please advice on this.

Thanks,
Balaji
Bill Hassell
Honored Contributor

Re: Trusted System advantages and disadvantages

When the root user is locked, you can always login on the real console (not the network) and unlock the root user. That's why you must always have a way to connect to the console.


Bill Hassell, sysadmin
Jeeshan
Honored Contributor

Re: Trusted System advantages and disadvantages

if admin or root user is locked you can either reset password in single user mode.


BTW, you didn't yet assign any points in your recent or earlier posts. please assign points whoever epend their valuable time to give you quick and perfect solution or answer.

a warrior never quits