[Search for users] [Overall Top Noters] [List of all Conferences] [Download this site]

Conference bulova::decw_jan-89_to_nov-90

Title:DECWINDOWS 26-JAN-89 to 29-NOV-90
Notice:See 1639.0 for VMS V5.3 kit; 2043.0 for 5.4 IFT kit
Moderator:STAR::VATNE
Created:Mon Oct 30 1989
Last Modified:Mon Dec 31 1990
Last Successful Update:Fri Jun 06 1997
Number of topics:3726
Total number of notes:19516

1374.0. "SYSTEM LOGS IN, BUT NOT USERS." by WORDS::HANNAFIN () Tue Sep 05 1989 17:00

    HELP!!!!
    
    Sorry if this topic is already under discussion, (I looked
    around but didn't see anything about it).
    
    Our system is an 11/780 running VMS 5.2 and DECWindows 5.2.
    We have 5 satellite nodes, (VAXStation 2000's).  I left
    here Saturday and all was well.  I came in today to find
    I cannot log into my 2000 as myself.  I can log in under
    the SYSTEM account, but not my own.  This is the way it
    is for all 5 satellites, (weird).  We did install DECWrite
    on Friday, but as I say Saturday I was here running RAGS
    and having a ball....  
    
    What happened???
    
    Thanks in advance for any help....
    
    
    Dan
    

T.RTitleUserPersonal
Name
DateLines
1374.1Another user shut outTECUN::BRADFORDDe Guatemala a guatepeorTue Sep 05 1989 17:5819
    I have the same problem on my LAVc (a VS3600 serving several VS2000s
    and two MicroVAXIIs): I just upgraded from VMS 5.1 to 5.2.  This
    problem did not occur until I ran AUTOGEN FEEDBACK.  Since then,
    I cannot log into my user account on a DECwindows terminal.  I can,
    however, log in remotely on a non-DECwindows terminal!
    
    I have gotten some help from the VMS notes conference, but to no
    avail.  Since this seems to have something to do with DECwindows,
    I thought I'd try this conference.
    
    I've tried upping the GLBLPAGES and GBLSECTIONS paramaters as
    recommended (to 30000 and 400) and even started from scratch by
    removing the node using CLUSTER_CONFIG, then adding it back in.
    
    Any ideas?
    
    Denis
    

1374.2Re: .1 - False alarm, problem solved!TECUN::BRADFORDDe Guatemala a guatepeorWed Sep 06 1989 15:5410
The login problem I described was not caused by AUTOGEN FEEDBACK or DECwindows 
as I suspected.  It was caused by an internal program, SECURITY.COM, that we
installed on our system.  The program set protection on a number of system
files that prevented user accounts from accessing when logging in.

It was an unfortunate coincedence that I discovered the problem immediately
after running AUTOGEN FEEDBACK.  Sorry for the false alarm.

Denis

1374.3KONING::KONINGNI1D @FN42eqThu Sep 07 1989 13:295
I think there is a VMS rule that says: "don't change the protection on any
system files".  So the obvious answer is to trash that program.

	paul

1374.4LESLIE::LESLIEFat was then - thinner is nowThu Sep 07 1989 18:06121
    This command procedure implements the ZK Security recommendations. I
    run it every time the system boots. I've had no problems.
    
    Hope it's of use
    
    - ���
    ---< CUT HERE >----
$ ! make_system_secure.com - andy leslie, 30 jan 1989
$ ! protect the mfd
$ sa="set acl/log"
$ Set NoOn
$ set file/log/prot=(w:e) sys$sysdevice:[000000]000000.dir
$ ! .sys files must also be protected
$ set file/log/prot=(w:e) sys$sysdevice:[000000]*.sys
$ ! add default ace to the mfd
$ sa sys$sysdevice:[000000]000000.dir -
/acl=(default_protection,options=nopropagate+protected,s:rewd,o:wred,g,w)
$ ! all new files created in the mfd will have to be altered to allow access
$
$ set file/log/prot=(w:e) sys$sysdevice:[000000]sys*.dir
$ set file/log/prot=(w:e) sys$sysdevice:[000000]vms$common.dir
$ sa sys$sysdevice:[000000]*.dir -
/acl=(default_protection,options=nopropagate+protected,s:rewd,o:wred,g,w)
$
$ set file/log/prot=(w) sys$sysdevice:[000000]sysexe.dir
$ set file/log/prot=(g,w) sys$sysdevice:[sys*]mom$system.dir,sys$ldr.dir,sys$startup.dir, -
sysmaint.dir,systest.dir,syserr.dir
$ set file/log/prot=(g,w) sys$sysdevice:[vms$common]mom$system.dir,sys$ldr.dir,sys$startup.dir, -
sysmaint.dir,systest.dir,syserr.dir                  
$
$ sa sys$sysdevice:[000000]sysexe.dir /acl=(default_protection,options=nopropagate+protected,s:rewd,
$ sa sys$sysdevice:[sys*]mom$system.dir /acl=(default_protection,options=nopropagate+protected,s:rew
$ sa sys$sysdevice:[sys*]sys$ldr.dir    /acl=(default_protection,options=nopropagate+protected,s:rew
$ sa sys$sysdevice:[sys*]sys$startup.dir/acl=(default_protection,options=nopropagate+protected,s:rew
$ sa sys$sysdevice:[sys*]sysmaint.dir   /acl=(default_protection,options=nopropagate+protected,s:rew
$ sa sys$sysdevice:[sys*]systest.dir    /acl=(default_protection,options=nopropagate+protected,s:rew
$ sa sys$sysdevice:[sys*]syserr.dir     /acl=(default_protection,options=nopropagate+protected,s:rew
$
$ sa sys$sysdevice:[vms$common]sysexe.dir /acl=(default_protection,options=nopropagate+protected,s:r
$ sa sys$sysdevice:[vms$common]mom$system.dir /acl=(default_protection,options=nopropagate+protected
$ sa sys$sysdevice:[vms$common]sys$ldr.dir    /acl=(default_protection,options=nopropagate+protected
$ sa sys$sysdevice:[vms$common]sys$startup.dir/acl=(default_protection,options=nopropagate+protected
$ sa sys$sysdevice:[vms$common]sysmaint.dir   /acl=(default_protection,options=nopropagate+protected
$ sa sys$sysdevice:[vms$common]systest.dir    /acl=(default_protection,options=nopropagate+protected
$ sa sys$sysdevice:[vms$common]syserr.dir     /acl=(default_protection,options=nopropagate+protected
$
$
$ set file/log/prot=(s:rew,o:wre,g:re,w:re) -
sys$sysdevice:[sys*]syscbi.dir,sysexe.dir,sysfont.dir,syshlp,syslib.dir, -
sysmsg.dir,sysupd.dir
$ set file/log/prot=(s:rew,o:wre,g:re,w:re) -
sys$sysdevice:[vms$common]syscbi.dir,sysexe.dir,sysfont.dir,syshlp,syslib.dir, -
sysmsg.dir,sysupd.dir   
$ sa sys$sysdevice:[sys*]syscbi.dir -
/acl=(default_protection,options=nopropagate+protected,s:rewd,o:wred,g,w:re) 
$ sa sys$sysdevice:[sys*]sysexe.dir -
/acl=(default_protection,options=nopropagate+protected,s:rewd,o:wred,g,w:re)
$ sa sys$sysdevice:[sys*]sysfont.dir -
/acl=(default_protection,options=nopropagate+protected,s:rewd,o:wred,g,w:re) 
$ sa sys$sysdevice:[sys*]syshlp.dir -
/acl=(default_protection,options=nopropagate+protected,s:rewd,o:wred,g,w:re) 
$ sa sys$sysdevice:[sys*]syslib.dir -
/acl=(default_protection,options=nopropagate+protected,s:rewd,o:wred,g,w:re) 
$ sa sys$sysdevice:[sys*]sysmsg.dir -
/acl=(default_protection,options=nopropagate+protected,s:rewd,o:wred,g,w:re) 
$ sa sys$sysdevice:[sys*]sysupd.dir -
/acl=(default_protection,options=nopropagate+protected,s:rewd,o:wred,g,w:re) 
$
$ sa sys$sysdevice:[vms$common]syscbi.dir -
/acl=(default_protection,options=nopropagate+protected,s:rewd,o:wred,g,w:re) 
$ sa sys$sysdevice:[vms$common]sysexe.dir -
/acl=(default_protection,options=nopropagate+protected,s:rewd,o:wred,g,w:re) 
$ sa sys$sysdevice:[vms$common]sysfont.dir -
/acl=(default_protection,options=nopropagate+protected,s:rewd,o:wred,g,w:re) 
$ sa sys$sysdevice:[vms$common]syshlp.dir -
/acl=(default_protection,options=nopropagate+protected,s:rewd,o:wred,g,w:re) 
$ sa sys$sysdevice:[vms$common]syslib.dir -
/acl=(default_protection,options=nopropagate+protected,s:rewd,o:wred,g,w:re) 
$ sa sys$sysdevice:[vms$common]sysmsg.dir -
/acl=(default_protection,options=nopropagate+protected,s:rewd,o:wred,g,w:re) 
$ sa sys$sysdevice:[vms$common]sysupd.dir -
/acl=(default_protection,options=nopropagate+protected,s:rewd,o:wred,g,w:re) 
$
$ set file/log/prot=(w:e,g:e,o:wred,s:wred) sys$sysdevice:[sys*]sysmgr.dir
$ set file/log/prot=(w:e,g:e,o:wred,s:wred) sys$sysdevice:[vms$common]sysmgr.dir
$ sa sys$sysdevice:[sys*]sysmgr.dir -
/acl=(default_protection,options=nopropagate+protected,s:rewd,o:wred,g,w:re) 
$
$ sa sys$sysdevice:[vms$common]sysmgr.dir -
/acl=(default_protection,options=nopropagate+protected,s:rewd,o:wred,g,w:re) 
$
$ set file/log/prot=(o:wred,s:wred,g:re,w:re) -
sys$sysdevice:[vms$common.sysmgr]sylogin.com,announce.txt,welcome.txt 
$ set file/log/prot=(o:wred,s:wred,g:re,w:re) -
sys$sysdevice:[sys*.sysmgr]sylogin.com,announce.txt,welcome.txt
$ set file/log/prot=(o:wred,s:wred,g,w:re) -
sys$sysdevice:[vms$common.sysmgr]decw$*.com
$ set file/log/prot=(o:wred,s:wred,g,w:re) -
sys$sysdevice:[sys*.sysmgr]decw$*.com 
$
$ set file/log/prot=(s:wred,o:wred,g,w) -
sys$system:net*.dat,pagefile.sys,swapfile.sys, -
sysdump.dmp,sysuaf*.*,jbcsysque.dat,modparams.dat,vmsparams.dat,*.par, -
vmsmail_profile.data
$
$ sa sys$system:sysuafalt.dat;* -
/acl=(alarm_jour=security,access=write+delete+control+success)
$ sa sys$system:sysalf.dat;* -
/acl=(alarm_jour=security,access=write+delete+control+success)
$ sa sys$system:rightslist.dat;* -
/acl=(alarm_jour=security,access=write+delete+control+success)
$ sa sys$system:net*.dat;* -
/acl=(alarm_jour=security,access=write+delete+control+success)
$ 
$ sa sys$system:loginout.exe -
/acl=(alarm_jour=security,access=write+delete+control+success)
$
$Exit:
$ Exit
    

1374.5Please dissseminateYUPPY::CONNOLLYFri Sep 08 1989 10:434
    re .4
    
    Have you posted this in the SYSMGR and Securepack conferences