[Search for users] [Overall Top Noters] [List of all Conferences] [Download this site]

Conference turris::digital_unix

Title:DIGITAL UNIX(FORMERLY KNOWN AS DEC OSF/1)
Notice:Welcome to the Digital UNIX Conference
Moderator:SMURF::DENHAM
Created:Thu Mar 16 1995
Last Modified:Fri Jun 06 1997
Last Successful Update:Fri Jun 06 1997
Number of topics:10068
Total number of notes:35879

9001.0. "V4.0-C2 Sec.& Root Passwd Disappeared" by ATHINA::TSAKALOS () Fri Feb 28 1997 11:47

    
    
     Hello all,
    
    We have a customer under DIGITAL UNIX V4.0 . He enabled C2
    Security and now he is reporting to us that during last
    two weeks the root passwd suddenly disappeared without any
    message.
    Setting back the passwd system has no problem but he does not
    feel secure at all if this will happened again.
    
    Any hints or ideas ?
    
    Thanking you in advance
    Thanos
T.RTitleUserPersonal
Name
DateLines
9001.1please explainNETRIX::"[email protected]"markSat Mar 01 1997 01:415
Please explain what you/they mean by root password "disappearing"
my crystal ball is a little fogged over at the moment :)

	
[Posted by WWW Notes gateway]
9001.2System doesn't prompt for passwdATHINA::TSAKALOSMon Mar 03 1997 02:188
     Ok,
    
    System doesn't ask for password, after the input of the root you
    just go in to the system, so simple !!!
    
    Thanks for your reply
    Best Regards
    Thanos
9001.3ZEKE::ranger.zko.dec.com::dilsworthKeith DilsworthMon Mar 03 1997 14:046
I can't tell you what made it go away but I can tell you how to look 
at the entry in the shadow passwd file:

/usr/tcb/bin/edauth -g root


9001.4NETRIX::"[email protected]"Ann MajeskeTue Mar 04 1997 11:2612
Please post the results of the command described in .3 here (if they
haven't already "fixed" the root account.

I can't say that what you are describing is impossible, but it is nearly
impossible for it to happen unless the customer made changes to the
protected password database.  What changes did they make before this 
starting happening?  You should look for changes in any of the following:
	the protected password database (auth.db or /tcb/files/auth/*)
	the enhanced security defaults database (/etc/auth/system/default)
	the enhanced security ttys database (/etc/auth/system/ttys.db)
you can look at all of these databases using the /usr/tcb/bin/edauth tool.
[Posted by WWW Notes gateway]