- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- users don't want to the account locked after unssu...
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Discussions
Forums
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-06-2008 06:06 AM
тАО10-06-2008 06:06 AM
Because they need to run some jobs by using this account, we have removed the password aging, and other policies from this account. The only restriction is that the account will get locked if unssuccessful login attpems reaches 10 times (used to be 3 times). It got locked again last week, because the maximum has been reached.
Now they are asking this restriction should be removed as well.
I don't feel this is right, because this is the least resposibility they should take. From security point of view, it is not right to remove such policy.
How and what I should respond to their request?
Thanks for your input.
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-06-2008 06:24 AM
тАО10-06-2008 06:24 AM
Re: users don't want to the account locked after unssucessful attempts
If the account is only used by some jobs/apps then no way the account get locked since you already disabled password aging and other policies.
>>>It got locked again last week, because the maximum has been reached.<<<<
if the unsuccessful login is 10 times continously, then the account will get locked. Not because of total attempts.
In some places, when you change the password, the same has to updated on applications also. If not updated on application then account get locked since the application will try with old password only. It may happen in some cases.
If the account is used by only jobs/apps then we can set this value to unlimited.
Ganesh.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-06-2008 06:30 AM
тАО10-06-2008 06:30 AM
SolutionIn these situations if I was concerned about removing security features, I'd raise it through my management. If they still want to go ahead we'd create a security policy exception statement and get those that requested it to sign the exception.
Then when the audit team come along you show them the exception and they go crucify the users, not you.
A bit slopey shouldered but its amazing how many of these requests go away when you ask someone to sign an audit exception document - suddenly they can live with the grief of the odd password reset
HTH
Duncan
I am an HPE Employee

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-06-2008 06:30 AM
тАО10-06-2008 06:30 AM
Re: users don't want to the account locked after unssucessful attempts
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-06-2008 06:47 AM
тАО10-06-2008 06:47 AM
Re: users don't want to the account locked after unssucessful attempts
So.....here you go for your question.
How and what I should respond to their request?
>>>>NO
>>>>No, what part of No don't you understand.
>>>>Yes sir - I said No. If you as my manager/director wish to counter that security measure, please put it in an email & I will be happy to comply with that & relinquish the reposibility of security for that system.
Cause that is what part of the job of being the Administrator includes. Standing up for what you know is the right thing. Let mgmt over-rule you to cover your behind.
Just my 2 cents,
Rgrds,
Rita
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-06-2008 07:26 AM
тАО10-06-2008 07:26 AM
Re: users don't want to the account locked after unssucessful attempts
I bet the mamagement would finally do whatever they ask for. But, I just don't feel that is right thing to do, because this is the least they should do, and we all should do something together to make the server secure. We don't have security team.
So, I need to write the email to them as Unix admin, management, as well as security team....
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-06-2008 07:34 AM
тАО10-06-2008 07:34 AM
Re: users don't want to the account locked after unssucessful attempts
some valuable piece of the security
apparatus, it would be nice to know the name
of the company involved, so we'd know with
whom _not_ to do business.
Unlimited password guessing with no warning?
Brilliant.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-06-2008 08:36 AM
тАО10-06-2008 08:36 AM
Re: users don't want to the account locked after unssucessful attempts
Part of the issue is going to be what regulations (if any) are you subject to and who is doing the audits.
As noted before:
Standards should be documented.
Any deviations from the standards need to be documented as well
If your management says to proceed, then ask for it in writing. also consider something like a restricted shell environment, or a menu only system for the account. Its not bullet proof, but better than nothing.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-06-2008 08:44 AM
тАО10-06-2008 08:44 AM
Re: users don't want to the account locked after unssucessful attempts
Nobody plays Admin, you are or you are not. So......tighten your belt, straighten your tie, or whatever makes you pull it together and make the decision.
If you are the Admin, then make the rule. If you are countered by someone higher (get it in writing). But until then............do the job.
Sorry if that sounded too "tuff", but it can be a tough job. Remember one thing, if some sort of security breach happens because all the security is ignored/off - guess who gets the blame for letting it happen!....Y-O-U. Guess who's job will be held responsible...Y-O-U-R-S.
Just my 2 cents,
Rgrds,
Rita
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-08-2008 07:27 AM
тАО10-08-2008 07:27 AM
Re: users don't want to the account locked after unssucessful attempts
Thanks all for excellent inputs!