SUMMARY: Synchronizing passwd file with Enhanced Security password database

From: Maglinger, Paul (PMAGLINGER_at_scvl.com)
Date: 11/23/05

  • Next message: Dave Sill: "Administrivia: Tru64-UNIX-Managers information and policy statement"
    Date: Wed, 23 Nov 2005 10:30:19 -0600
    To: Tru64 Unix Managers list <tru64-unix-managers@ornl.gov>
    
    

    No firm responses on this. It looks like it may be something to do with
    C2 security whereby accounts are never deleted to prevent reuse of UIDs,
    and thus inadvertantly give a new user and old user's privs. So,
    instead of renaming the account it looks like I have to delete it and
    recreate it using the same UID and groups that it had previously, and
    renaming the home directory.

    Thanks to all.

    Paul

    -----Original Message-----
    From: Maglinger, Paul
    Sent: Thursday, November 17, 2005 11:35
    To: Maglinger, Paul
    Subject: ADDENDUM: Synchronizing passwd file with Enhanced Security
    password database

     Thanks to Ann Majeske, Chris Wincentsen, Richard Jackson, J.A.
    Guteirrez, John Lanier, and Chris Adams for their responses.

    Numerous mentions of using authck and edauth. The deleted account is
    not showing up using either command, so I'm going to let that issue go
    for now. The renamed account shows the new username in the passwd file
    and the enhanced security database, but the old username is in the
    enhanced security database too. I would assume that the rename would
    have changed both, but it appears that it actually a new entry and
    retains the old one as well. The old username does not appear in the
    Account Manager gui, and you can't log in using the old username, so why
    does it still exist in the database? Is this normal for Enhanced
    Security? It appears that I can use edauth to remove the old username,
    but why would such housekeeping be necessary?

    -----Original Message-----
    From: tru64-unix-managers-owner@ornl.gov
    [mailto:tru64-unix-managers-owner@ornl.gov] On Behalf Of Maglinger, Paul
    Sent: Monday, November 14, 2005 14:04
    To: Tru64 Unix Managers list
    Subject: Synchronizing passwd file with Enhanced Security password
    database

    I'm doing some housecleaning on our Tru64 5.1B servers because good ol'
    SekChek shows that there are two usernames that show up in the shadow
    passwd file and are not in the passwd file. One of these accounts was
    deleted, the other account was renamed due to a name change. I'm trying
    to find information on synchronizing these two files, but most of what
    I'm finding refers to a /etc/shadow file that doesn't exist. We are
    running Enhanced Security so what would be the shadow file is actually
    the auth.db, right? I can't find anything on synchronizing the two.
    Can someone point me in the right direction?
     
    Paul Maglinger, A+, CA, CCA, CET, MCSE

    Systems Administrator
    Shoe Carnival Inc.
    (812)867-4674
    pmaglinger@scvl.com

    ________________________________

     


  • Next message: Dave Sill: "Administrivia: Tru64-UNIX-Managers information and policy statement"

    Relevant Pages

    • Re: WSE 2.0 - The security token could not be authenticated or authorized
      ... When use the admin account to login, select the first invoice in the grid ... event viewer (Security log) I dont see a failure audit entry in the log (as ... > username and password are being sent. ... >> lope envelope) ...
      (microsoft.public.dotnet.framework.webservices.enhancements)
    • Re: WSE 2.0 - The security token could not be authenticated or authori
      ... And of course you have to restart IIS afterward. ... >> security token could not be authenticated or authorized ... The input shows the correct username ... >> The account I'm using is a local account and the group is local as well. ...
      (microsoft.public.dotnet.framework.aspnet.webservices)
    • Re: xp home connectivity
      ... And make sure the account isn't getting locked out on the computer ... There's also an XP security newsgroup here where you might get more answers ... > pc_name is name of computer that you are trying to connect to and username ... >> one xp pc can connect to other, but second pc requests user name and ...
      (microsoft.public.security)
    • Disk quota
      ... The account with the username 'security', is running out of disk space. ...
      (microsoft.public.windowsxp.general)
    • Risks Digest 25.73
      ... German electronic health card system failure ... Risks of the Cloud: Liquid Motors ... Oakland 2010, IEEE Symposium on Security and Privacy, CFP ... A friend's facebook account was hacked recently (a neat little short-term ...
      (comp.risks)