Does tsh require TCB ?



Hi,

I have an application run by a user with /bin/tsh as his shell. For those who are not familiar, With it, /etc/tsh_profile is automatically run at login for users whose shell is defined as /bin/tsh and the user may only run "trusted" programs. For example, if you wanted to have a restricted user run the command "my_command" you would first have to "chtcb my_command on".

My question is whether TCB must be installed to use chtcb or not. To remind, TCB can only be installed when installing AIX not later (or has that changed ?). If I will not install aix with TCB, will I have any limitations WRT the usage of tsh and chtcb to allow more programs to run under tsh ?

Thanks,
/Zvika


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Zvika Bar-Deroma

Systems and Network manager Phone: (+972)-4-829-2706 ; Fax : (+972)-4-829-2315
Faculty of Aerospace Engineering, Technion, Haifa 32000, Israel

e-mail : zvika@xxxxxxxxxxxxxxxxxxxxx
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~