05-25-2008
Root account - disable expiry
I couldnt find this in any other post - so hoping someone can help out.
I want to set password expiry (or rather I have to) for a number of users on my solaris 9 system. I know i can set the following options in the /etc/default/passwd file to do it and then just type a passwd -f <username> to force the user to change password next login and therefore get the new settings...
MAXWEEKS=8
PASSLENGTH=8
WARNWEEKS=1
HISTORY=5
But... I want to exclude some users from password expiry - such as the root user and a few other user accounts...
Some of these accounts are vital for access and also have some vital cron jobs running so I would never want someone to go on holiday for weeks and the account to expire and cause a service issue etc...
Can I do this and if so how?
10 More Discussions You Might Find Interesting
1. UNIX for Dummies Questions & Answers
After Configuring a brand new netraT1, It appears, the only way you can log in as root is throught the Serial Port (console). I believe there is a file in /etc which can be edited to allow root to access login via other methods
eg: telnet, ssh, etc.
My Question:
Which file contains... (2 Replies)
Discussion started by: SmartJuniorUnix
2 Replies
2. UNIX for Dummies Questions & Answers
I have this unix version 3.0
"UNIX_SV server 4.0 3.0 3425 Pentium II(TM)-ISA/PCI"
can i delete or disable the system generated account as "daemon";"uucp";"sys";"adm";"listen";"bin"
and if yes how can i do it?
Regards (1 Reply)
Discussion started by: sak900354
1 Replies
3. HP-UX
I want to temporarily disable a user account on HP-UX at the start of a script and renable the account at the end of the script. What would be the best method on HP-UX to temporarily disable a user account? I know of the passwd -l option that will lock the account, but I do not see a flag for... (4 Replies)
Discussion started by: scotbuff
4 Replies
4. AIX
Hi, yesterday, I changed root's shell in /etc/passwd, cause a mistake then I can not log in root account (can't find correct shell). I attempted to log in single-mode, however, it prompted for single-mode's password then I type root's password but still can not log in.
I'm using AIX 5L version 5.2... (2 Replies)
Discussion started by: neikel
2 Replies
5. UNIX for Dummies Questions & Answers
I am able to disable direct root login through telnet. But when I add the rlogin = false into the /etc/security/user file. I am unable to log in as root from ssh. I uncommented the "PermitRootLogin yes" in the sshd_config file. Still can't log in. Can anyone help? (0 Replies)
Discussion started by: james0125
0 Replies
6. SuSE
Hi,
We are going to create the new user, using that user we are automate the work, but every 90 days password get expired how can i create or avoid the expiry the password. (1 Reply)
Discussion started by: kingganesh04
1 Replies
7. Solaris
Hi
How do i disable password expiration on ldap?
It runs on Solaris 10 machine. Thanks in advance. (3 Replies)
Discussion started by: hrist
3 Replies
8. Solaris
HI i am trying to give su access to some users say X Y and Z to a account AB . I am able to give them su access to root with the help of sudoers file but i want to give them password less access to AB account which i am not able to do .
I want to this
when user X fires "su - AB" he is not... (9 Replies)
Discussion started by: rishiraaz
9 Replies
9. Solaris
can an user see the expiry date of its own account,also can the user know whether it is having peer access or not.
Thanks,
Megh (2 Replies)
Discussion started by: megh
2 Replies
10. Red Hat
Hi Guys
In red hat linux server is there a way to alert via email when the root password is about to expire ?
As per security policy in our environment root password will expire in 90 days.
Example : It would be better if we receive a email on 7th november stating that the root password... (1 Reply)
Discussion started by: newtoaixos
1 Replies
CHAGE(1) General Commands Manual CHAGE(1)
NAME
chage - change user password expiry information
SYNOPSIS
chage [-m mindays] [-M maxdays] [-d lastday] [-I inactive]
[-E expiredate] [-W warndays] user
chage -l user
DESCRIPTION
chage changes the number of days between password changes and the date of the last password change. This information is used by the system
to determine when a user must change her password. The chage command is restricted to the root user, except for the -l option, which may
be used by an unprivileged user to determine when her password or account is due to expire.
With the -m option, the value of mindays is the minimum number of days between password changes. A value of zero for this field indicates
that the user may change her password at any time.
With the -M option, the value of maxdays is the maximum number of days during which a password is valid. When maxdays plus lastday is less
than the current day, the user will be required to change her password before being able to use her account. This occurance can be planned
for in advance by use of the -W option, which provides the user with advance warning.
With the -d option, the value of lastday is the number of days since January 1st, 1970 when the password was last changed. The date may
also be expressed in the format YYYY-MM-DD (or the format more commonly used in your area).
The -E option is used to set a date on which the user's account will no longer be accessible. The expiredate option is the number of days
since January 1, 1970 on which the accounted is locked. The date may also be expressed in the format YYYY-MM-DD (or the format more com-
monly used in your area). A user whose account is locked must contact the system administrator before being able to use the system again.
The -I option is used to set the number of days of inactivity after a password has expired before the account is locked. The inactive
option is the number of days of inactivity. A value of 0 disables this feature. A user whose account is locked must contact the system
administrator before being able to use the system again.
The -W option is used to set the number of days of warning before a password change is required. The warndays option is the number of days
prior to the password expiring that a user will be warned her password is about to expire.
If none of the options are selected, chage operates in an interactive fashion, prompting the user with the current values for all of the
fields. Enter the new value to change the field, or leave the line blank to use the current value. The current value is displayed between
a pair of [ ] marks.
NOTE
The chage program requires shadow password file to be available. Its functionality is not available when passwords are stored in the
passwd file.
FILES
/etc/passwd - user account information
/etc/shadow - shadow user account information
SEE ALSO
passwd(5), shadow(5)
AUTHOR
Julianne Frances Haugh <jockgrrl@ix.netcom.com>
CHAGE(1)