[HPADM] Alternate to Trusted

From: Joe Crawford (abjcrawford@yahoo.com)
Date: Mon Aug 28 2006 - 08:44:13 EDT


Our security Admin has suggested the following
approach as alternate to trusted mode(not a full
solution but atleast for passwd etc). we use a
security software which generates lots of reds for
passwd problems(history, depth, chars etc)

Note: The techniques below should only be applied to
HP-UX operating systems.

To make Invalid Mimimum Password History reds go away,
create a file called /etc/default/security. Configure
it as follows:

PASSWORD_HISTORY_DEPTH=4
MIN_PASSWORD_LENGTH=6
PASSWORD_MIN_DIGIT_CHARS=1
PASSWORD_MIN_SPECIAL_CHARS=2

To remove Invalid Maximum Password Age reds without
Trusted Mode, for each login that exhibits the red,
type (as root):

passwd -x 84 <login ID>

My question is our systems run HP-UX 11.0. does this
support this feature? i thought i read somewhere that
the /etc/default/security file can be created only on
11.11? Also since we run NIS, we cannot go trusted.
Please Clarify.

Thanks

Joe.

__________________________________________________
Do You Yahoo!?
Tired of spam? Yahoo! Mail has the best spam protection around
http://mail.yahoo.com

--
             ---> Please post QUESTIONS and SUMMARIES only!! <---
        To subscribe/unsubscribe to this list, contact majordomo@dutchworks.nl
       Name: hpux-admin@dutchworks.nl     Owner: owner-hpux-admin@dutchworks.nl
 
 Archives:  ftp.dutchworks.nl:/pub/digests/hpux-admin       (FTP, browse only)
            http://www.dutchworks.nl/htbin/hpsysadmin   (Web, browse & search)


This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 11:02:54 EDT