[Search for users] [Overall Top Noters] [List of all Conferences] [Download this site]

Conference bulova::decw_jan-89_to_nov-90

Title:DECWINDOWS 26-JAN-89 to 29-NOV-90
Notice:See 1639.0 for VMS V5.3 kit; 2043.0 for 5.4 IFT kit
Moderator:STAR::VATNE
Created:Mon Oct 30 1989
Last Modified:Mon Dec 31 1990
Last Successful Update:Fri Jun 06 1997
Number of topics:3726
Total number of notes:19516

3448.0. "Restricted account. DECwindows & cluster Env." by TAVHLT::DORON (Doing my BEST !!!) Tue Oct 09 1990 14:56

Hi,

 I have read all the previous notes about captive/restricted account but there
is one problem that rises from this disccussion. What happen is we are working
with work station in VAXCluster environment? Let's assume that a user can login
to a Cluster and not to a W.S. via a regular terminal (connected by DECserver)
or by a work station that is a member in the Cluster. If we resrict his account,
he will not be able to login from the W.S., & if we DO NOT restrict his account,
he might take advantage when logged in from a terminal. Did any one think about
a work around beyond managing 2 SYSAUF (Specific for work stations)?

			*-Doron-*
T.RTitleUserPersonal
Name
DateLines
3448.1Some tough questions...LNKUGL::BOWMANBob Bowman, CSC/CS SPACE TeamTue Oct 09 1990 17:566
Define "take advantage". What do you wish to prevent a user from doing if they
login from a CCT that you don't care about limiting them from doing if they
login from a WS? Why is it necessary to restrict the user at all?

Different customers will have different answers to these questions. Depending on
the answers, you may be able to formulate a solution. You may not...
3448.2Another $0.02 on the restricted accountsALEXWS::ALEXBugs are coming in triplets ...Wed Oct 10 1990 07:4319
	Another $0.02 on the issue.

	There are various SYSUAF process limits that should/may be different for
WS vs. VT user. It depends on the environment, of course, but for instance :
VT user uses the same application that allows other stuff to be run on WS screen
which is not appropriate for the VT.

	There are many solutions for it, but 2 SYSUAFs is not a good one. The
major caveat for 2 SYSUAF is password expiration. User should change TWO
passwords: one for VT and one for WS.

	And what we need is just restricted account for WS users. Let them run
only those applications, that system manager/application programmer wants them
to run.

	Cheers,
		Alex