- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Re: Why you would need to set password to adm use...
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-27-2004 10:25 AM
02-27-2004 10:25 AM
Regards.
Hector Hdez.
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-27-2004 10:32 AM
02-27-2004 10:32 AM
Re: Why you would need to set password to adm user ?
A * in the password field against a login in /etc/passwd indicates that the password is locked (if this system is not trusted). On trusted system, it will be under /tcb/files/auth/
I don't know why one would want to set a password for these accounts. Setting a password will only open a chance for anyone to hack these accounts. That's how it affects the system.
-Sri
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-27-2004 10:33 AM
02-27-2004 10:33 AM
Re: Why you would need to set password to adm user ?
Ask your auditor WHY they want you to set a password on these accounts. They may be under the mistaken impression that the * means that anyone can log in. That is NOT true. The * is essentially an invalid password which would force someone to 'su - adm' to the account from the root user. No one else can log in to those accounts in any other fashion (unless you happen to set up sudo).
You COULD set passwords on those accounts without any major impact (as far as I know), but in my mind that would make your system LESS secure as there is now a password that could potentially be guessed. With the * there, there is NO password to guess, but you still can't log into the account directly.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-27-2004 01:49 PM
02-27-2004 01:49 PM
Re: Why you would need to set password to adm user ?
My question might be..How qualified is the person they hired as a Security Auditor for an HPUX system that doesn't know this? How well can they be doing their job, since they are asking you to make these accounts LESS secure?
Hmmmmmmm,
Rita
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-28-2004 01:37 AM
02-28-2004 01:37 AM
Re: Why you would need to set password to adm user ?
Get this 'auditor' out of Your building, away from keyboards etc.
He obviously doesn't know what he's talking about, at least with respect to HP-UX.
OTOH, install the /etc/shadow patches for 11i, check that accounts have an invalid shell (i.e. /bin/false suits well) and nonexistand homedir to do what a better auditor might ask You for.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-28-2004 02:08 AM
02-28-2004 02:08 AM
Re: Why you would need to set password to adm user ?
Your security auditor is asking you to weaken the security on these accounts and I would therefore look seriously at any other requests he/she makes on the unix systems.
AS said "*" means that these accounts cannot be logged into.
Paula
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-29-2004 08:15 AM
02-29-2004 08:15 AM
Re: Why you would need to set password to adm user ?
it could be utilized as back door.
Regards,
Sharif
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-29-2004 08:34 AM
02-29-2004 08:34 AM
SolutionCheck this doc for building a bastion host, section number 9 is about removing/securing uneeded pdeudo-accounts.
Building a Bastion Host Using HP-UX 11
DocId:USECKBAN00000800
Europe
http://www4.itrc.hp.com/service/cki/docDisplay.do?docLocale=en_US&docId=200000066258828
US
http://www1.itrc.hp.com/service/cki/docDisplay.do?docLocale=en_US&docId=200000066258828
Regards,
Robert-Jan