10-30-2008
possible to lock accounts (passwd -l) and still allow acct to ssh to other server?
My scenario is as follows:
We have a handful of batch accounts that run our production jobs. Our users are able to use sudo to become that account. Also, because of other reasons, the passwords are also listed in an encrypted file that each team can see their batch ID. So, I have some users that feel it is ok to su - $ID. Then, what happens is that they forget the password an lock out the account therefore causing production processing to stop. Our servers are HPUX, and my thought was that I could put an administrative lock on the accounts (passwd -l). That works and will prevent anybody from logging into via a new shell session or from a command prompt typing su - $ID. We are working towards a situation that will allow that the users not know the password...however they could still su - $ID 3 times and lock the acct out. My catch 22 is that these batch accounts need to ssh (using shared ssh keys) between servers. doing the admin lock prevents that. Any ideas?
10 More Discussions You Might Find Interesting
1. UNIX for Advanced & Expert Users
Hello All,
I am a student sys admin and not a professional. I'd like to know how can I migrate the user accounts in the current server to a new server( to be installed) non-destructively. Also in what way the old server can be used after installation of the new server. I'd sincerely... (2 Replies)
Discussion started by: maybemedic
2 Replies
2. UNIX for Dummies Questions & Answers
Hi Admin,
I need a help regarding to lock the user for 5 days..
for example i want to lock user account from Monday 1.00AM to Friday 1.00PM..
is there any method to do from Cron or passwd command.
Regards,
Prem :cool: (2 Replies)
Discussion started by: Prem
2 Replies
3. UNIX for Advanced & Expert Users
I'd just like to know what you use for user account management on your DMZ servers?
Do you use the same authentication realm as internally?
Do you use a different authentication realm, perhaps only for the DMZ?
Do you use local accounts? (2 Replies)
Discussion started by: humbletech99
2 Replies
4. Solaris
I have turned off PermitEmptyPasswords in sshd_config, but a user with empty passwd (deleted by passwd -d user) can still login without password, why? it is big security concern, linux doesn't have the issue.
$ uname -a
SunOS 5.10 Generic_118855-14 i86pc i386 i86pc
... (8 Replies)
Discussion started by: honglus
8 Replies
5. Solaris
Hi,
I need to Change passwd for bulk servers using SSH script.
I have one server, from which i can reach all the servers without password via SSH.
There is some expect script, from which i can achieve it.
Can any one help me out here.
Thanks in advance.
Vicky (1 Reply)
Discussion started by: vickyingle5
1 Replies
6. Cybersecurity
Hi all,
I am having some issues with openssh vers OpenSSH_4.6p1 on SCO unixware 7.1.4
when a user accesses the system via ssh and the password is incorrect and more attempts have been made that the lock out limit I find that although there are messages in the syslog the account does not lock... (0 Replies)
Discussion started by: chlawren
0 Replies
7. Red Hat
Hi friends,
I must to give ssh connection to own customer.
So I want to lock ssh user on own home directory. It is not necessery to reach other folders. I know that ftp user can lock on own folder but I don't know how to lock ssh user.
I am waitting your kindly helps :D
---------- Post... (10 Replies)
Discussion started by: getrue
10 Replies
8. UNIX for Dummies Questions & Answers
I am trying to obtain all user accounts and their respective home directories.
/etc/passwd contains the required information, but I want to filter it to only show the uid,username and home directory path.
I am working on a Solaris 11 machine.
I made a little headway so far, but I got stuck... (7 Replies)
Discussion started by: Hijanoqu
7 Replies
9. UNIX and Linux Applications
i am new to scripting ,i need bash script in jump server to pull the /etc/passwd of all servers and the ssh keys are installed (3 Replies)
Discussion started by: profiles
3 Replies
10. Shell Programming and Scripting
Hi All, Wishes!!
I need some help to prepare a script to copy the public key from admin host to multiple client hosts to make them login without password.
Detailed :
I have an admin host "admin1" and i generated sshkeygen, now i have id_rsa.pub and i have around 50 client hosts. i... (4 Replies)
Discussion started by: kumar85shiv
4 Replies
LEARN ABOUT SUSE
chpasswd
chpasswd(8) System Manager's Manual chpasswd(8)
NAME
chpasswd - change user passwords in batch
SYNOPSIS
chpasswd [-D binddn] [-P path] [-c des|md5|blowfish | -e] [file]
DESCRIPTION
chpasswd changes passwords for user accounts in batch. It reads a list of login and password pairs from standard input or a file and uses
this information to update the passwords of this user accounts. The named account must exist and the password age will be updated. Each
input line is of the format:
user_name:password
If the hash algorithmus is not given on the commandline, the value of GROUP_CRYPT or, if not specified, CRYPT from /etc/default/passwd is
used as hash algorithmus. If not configured, the traditinal des algorithmus is used.
OPTIONS
-c des|md5|blowfish
This option specifies the hash algorithmus, which should be used to encrypt the passwords.
-e The passwords are expected to be in encrypted form. Normally the passwords are expected to be cleartext.
-D, --binddn binddn
Use the Distinguished Name binddn to bind to the LDAP directory. The user will be prompted for a password for simple authentica-
tion.
-P, --path path
The passwd and shadow files are located below the specified directory path. chpasswd will use this files, not /etc/passwd and
/etc/shadow.
FILES
/etc/default/passwd - default values for password hash
SEE ALSO
passwd(1), passwd(5), shadow(5)
AUTHOR
Thorsten Kukuk <kukuk@suse.de>
pwdutils Feburary 2004 chpasswd(8)