Script to change UNIX password


 
Thread Tools Search this Thread
Top Forums Shell Programming and Scripting Script to change UNIX password
# 8  
Old 04-23-2002
He wants to automate the change of his user password in many servers. And for that reason I suggested him the expect tool.

but, for security concerns, he need to consider the modification of the script to insert crypt; or use the "interact" an a loop into the expect program (to capture the old and new passwd.

Hugo.
# 9  
Old 04-23-2002
Security is foremost of all Policies...

Let me just say. I am an SA and currently manage 17 boxes and I am the backup SA for 10 other boxes.

I have no problem with maintaining multiple passwords as root on my 17 systems... and they all have different unique passwords.

I change my passwds every 60 days now. We used to have a policy to change passwds every 30 days, but that created too much havoc for the users.

Also, it is somewhat of a breech in security to maintain the SAME password, even for a user, on 15 different boxes. I don't think I need to mention what would happen if someone knew that and got this user's passwd.

I am not trying to point fingers at anyone, but I am just trying to be a voice of clarity here. Hopefully I have succeeded in that goal.

"Laxity breeds contempt... Perseverance breeds awareness..."





Smilie

Last edited by Kelam_Magnus; 04-23-2002 at 02:57 PM..
# 10  
Old 04-23-2002
I agree, but in some cases the uses of a single-sign on combined
with a token card like securID (RSA) avoids to have a privileged memory.

Regards. Hugo.
# 11  
Old 05-17-2006
Multiple passwords

In response to your comment "I am an SA and currently manage 17 boxes and I am the backup SA for 10 other boxes. I have no problem with maintaining multiple passwords as root on my 17 systems... and they all have different unique passwords. I change my passwds every 60 days now."

I have to disagree with you, I think there is more risk because most people would have to write down their passwords somewhere which is a larger risk for a breech.

I manage over 40 boxes and our passwords expire every 30 days. I dont have to tell you how much time it takes to change them on each one, especially with our busy schedules. In addition to the other 20 passwords we have for other systems and apps, there is no way for me to have different passwords for each box, change them every 30 days and not be able to reuse them except every 5th password change.

I think having my password in my head which would not make sence to anyone is alot more secure than having to write them down. I am also looking for a way to automate changing passwords on multiple boxes to save time.
# 12  
Old 05-17-2006
Quote:
Originally Posted by sagoffin
I am also looking for a way to automate changing passwords on multiple boxes to save time.
changepass automate password changes on multiple systems
# 13  
Old 05-17-2006
ha ha!

..at one point in my career, back in 1999 at a .com data center, I had 1273 servers under my administration (with 5 other guys). I would've loved to see users' faces after telling them "you have to learn 1200+ passwds"...


...anyway...

... first thing I'd ask is if ftp, telnet, rlogin, and/or rsh are enabled. If they are, I think it is a waste of time to be changing passwds.

As for automating passwd mgt without a tool like LDAP, well, there are many ways you can do that. I use expect extensively - together with ssh - and you only need one install of it.
Login or Register to Ask a Question

Previous Thread | Next Thread

10 More Discussions You Might Find Interesting

1. Forum Support Area for Unregistered Users & Account Problems

Password sent via reset password email is 'weak' and won't allow me to change my password

I was unable to login and so used the "Forgotten Password' process. I was sent a NEWLY-PROVIDED password and a link through which my password could be changed. The NEWLY-PROVIDED password allowed me to login. Following the provided link I attempted to update my password to one of my own... (1 Reply)
Discussion started by: Rich Marton
1 Replies

2. Shell Programming and Scripting

Shell script to change the password

Hi Folks, I am trying to change the password for the user "sysservice" Where my requirement is login to each server and exit from that and ssh to the next server.. I have enabled the password less auth for the user sysservice. for i in `cat /home/sysservice/servers.txt` do ssh... (1 Reply)
Discussion started by: gsiva
1 Replies

3. Shell Programming and Scripting

A script to change password for all other servers

Hey Gurus, I have this requirement to change the password for other servers remotely from one server. So, I installed public keys on all servers and wrote the following script to do the job. Something appears to be wrong with my loop, as it only changes one server and ignores the rest. I'm... (24 Replies)
Discussion started by: Hiroshi
24 Replies

4. Shell Programming and Scripting

Script to change password in UNIX

Hi Friends, Every morning i need to change the password, please advise how it can be automated. I am having pre planned password list for 4 months which can be used as input file for new passwords. Thanks (28 Replies)
Discussion started by: rajjev_saini123
28 Replies

5. HP-UX

Automatic script to change the UNIX Password

Hi, we have around 50 users and every month we need to change the password manually once its expire. do we have any script to change the password automatically. OS -HP-UX Thanks in advance.. (6 Replies)
Discussion started by: periyasamycse
6 Replies

6. Shell Programming and Scripting

Unix script to change password

Hello Gurus I have little challenge which I do not know how to address it. I have unix account on many servers (let's say over 25). These accounts expire every 60 days. Is there scripts that I can run from my "local computer" and pass a new password to it where it would change it for me on all... (7 Replies)
Discussion started by: nimo
7 Replies

7. UNIX for Dummies Questions & Answers

Where to change the UNIX password prompt?

Hi guys, I got these 3 servers: a, b and c which I ssh from a to b/c. a:$ ssh userid@b Password: a:$ ssh userid@c userid@c's password: Notice that the password prompt is different (highlighted in bold) on both servers even though their SUN Solaris version the same, OpenSSH version... (0 Replies)
Discussion started by: DrivesMeCrazy
0 Replies

8. Shell Programming and Scripting

how to change root password using shell script with standard password

Hi Friends. I am new to scripting now i want to change the root password using the script with standard password. which is the easy scripting to learn for the beginner, Thanks in advance. (2 Replies)
Discussion started by: kurva
2 Replies

9. Shell Programming and Scripting

script/program to change the password ?

hi, Somebody have or known where i can find a perl small perl program to change the password. The point: First it verify is the user exist, checking the old typed password and replace it with new. The passwords must be encoded. Thanks, very much! (0 Replies)
Discussion started by: kad
0 Replies

10. UNIX for Advanced & Expert Users

Change password script in Unix easily..

I have more than 50 server unix's password need to change, usually I assign one password for all hosts, for easy remember, but I need to change password every two months..it's very tried to change password every 2 months, is there any unix script that can change password easily? ie ' script... (4 Replies)
Discussion started by: zp523444
4 Replies
Login or Register to Ask a Question