- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - OpenVMS
- >
- Re: limiting interactive logins
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-27-2009 10:28 AM
тАО02-27-2009 10:28 AM
limiting interactive logins
Local: ----- No access ------
could be set a such which prevented interactive logins, which remains true over decnet.
Username: jdoe
Password:
You are not authorized to login from this source
SSH appears to ignore this flag. I have also tried various lexical functions (getjpi) to no avail.
Anyone have any success limiting interactive logins to specific persons when the person is accessing via ssh?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-27-2009 10:56 AM
тАО02-27-2009 10:56 AM
Re: limiting interactive logins
in the sshd2_config file there is the allowusers/denyusers/allowgroups/denygroups options to use.
HTH
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-27-2009 11:03 AM
тАО02-27-2009 11:03 AM
Re: limiting interactive logins
Yes. The LOCAL setting is a rather crude bludgeon.
The OP does not mention which IP stack or which version of OpenVMS is involved.
Personally, what I have done in several cases is to make a change to either SYS$MANAGER:SYLOGIN.COM (or a group login file invoked by SYLOGIN.COM) to check the device name against a Rights List Identifier.
If the user holds the Identifier, the login is permitted, if not, output the appropriate message and LOGOUT.
Using this approach, it is important to disable CNTRL-Y etc by default (else an enterprising user could just keep hitting the keys to bypass the check).
- Bob Gezelter, http://www.rlgsc.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-27-2009 11:51 AM
тАО02-27-2009 11:51 AM
Re: limiting interactive logins
this rule would apply for sftp as well?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-27-2009 12:22 PM
тАО02-27-2009 12:22 PM
Re: limiting interactive logins
yes, it uses ssh as well.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-27-2009 12:33 PM
тАО02-27-2009 12:33 PM
Re: limiting interactive logins
hth
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО02-27-2009 02:04 PM
тАО02-27-2009 02:04 PM
Re: limiting interactive logins
If you have a support contract, send along a bug report to HP.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО03-01-2009 11:40 PM
тАО03-01-2009 11:40 PM
Re: limiting interactive logins
$ uaf modify user /nonetwork
then login through ssh will be disabled.
Also (s)ftp and similar by the way.