03-27-2003
I didn't write that program, so I don't know for sure, but isn't it just forcing the user to logoff (exit command) and then providing another prompt so that some different user could potentially log on?
10 More Discussions You Might Find Interesting
1. Filesystems, Disks and Memory
Dear all,
I am trying to create a new user account that can have the minimum access to the HP-Ux box, as in it only need to perform system info query like bdf and only able to read access system log files but not able to delete any file from any other directory beside it's own user directory... (5 Replies)
Discussion started by: gelbvonn
5 Replies
2. Solaris
I have a senario and i wonder how to do it ? i used NcFTPd and i dont think its applicable using that application or i didnt know how to configure it.
i want to have a user for FTP that user is only restricted to put and get from a certain directory and all sub-directories for that directory,... (0 Replies)
Discussion started by: mduweik
0 Replies
3. AIX
I want to restrict user's loging according to number of session.
example the user named "patrik" can be login concurrently from 12 stations thru telnet the 13th if some body tries to telnet 13th session it should not allow, until any of the 12 sessions are closed.
is it possibel ...i think... (2 Replies)
Discussion started by: pchangba1
2 Replies
4. AIX
hi,
I am facing a problem
from the remote system if i login to my AIX5.3 machine as root (thru telnet) the session does not expire for 2 hours even if the session is kept ideal
But whenever i do the same thing from some other user then the session is lost within 10 minutes (if session is kept... (2 Replies)
Discussion started by: pchangba
2 Replies
5. UNIX for Advanced & Expert Users
Dear All
I had one user called msc. In that i had two folder.xxx and yyy
ex: /home/msc/xxx
ex: /home/msc/yyy
Now i want that msc user only able to access xxx folder only. No other folder should be visible to it.
Kindly let me know. How it possile??
Regards
Jaydeep (3 Replies)
Discussion started by: jaydeep_sadaria
3 Replies
6. AIX
Hi,
I'm at AIX 5.3, I have a print queue named chqprinter, I want to allow access to print only 2 users to that print queue, jobs printed by all other users to above queue should be deleted.
Any idea how to achieve that?
---------- Post updated at 10:33 AM ---------- Previous update was at... (5 Replies)
Discussion started by: tayyabq8
5 Replies
7. UNIX for Dummies Questions & Answers
Hello,
I would to create a new user with some restriction:
1. The user will not be able to CD any directory (I mean he'll login to the defined home directory and that's all).
2. The user will not be able to delete anything in that home directory
Thanks a lot in advance,
Shahar (1 Reply)
Discussion started by: shaharoz
1 Replies
8. Linux
Hi Friends,
I have installed a FTP Server on my Linux machine (Fedora 11).
I want the ftp users to be restricted to their own home dir using sftp.
But the said condition is met when the user logs in using ftp over port 21 and when the user logs in using sftp i.e. protocol 22, he/she has... (4 Replies)
Discussion started by: pashy
4 Replies
9. AIX
Hello,
I am curious that is there a way I can restrict a user or a set of users to execute the C/C++ compiler, basically what I want is to lock it down to a particular user and none of the other users should be able to compile any code.
Thanks in advance. (14 Replies)
Discussion started by: m6248m
14 Replies
10. Solaris
Is there a way to stop users envoking a root shell with sudo on Solaris 10.
I want users to use sudo <cmd> but not sudo -s (5 Replies)
Discussion started by: u20sr
5 Replies
LEARN ABOUT LINUX
aa-genprof
AA-GENPROF(8) AppArmor AA-GENPROF(8)
NAME
aa-genprof - profile generation utility for AppArmor
SYNOPSIS
aa-genprof <executable> [-d /path/to/profiles]
OPTIONS
-d --dir /path/to/profiles
Specifies where to look for the AppArmor security profile set.
Defaults to /etc/apparmor.d.
DESCRIPTION
When running aa-genprof, you must specify a program to profile. If the specified program is not a fully-qualified path, aa-genprof will
search $PATH in order to find the program.
If a profile does not exist for the program, aa-genprof will create one using aa-autodep(1).
Genprof will then:
- set the profile to complain mode
- write a mark to the system log
- instruct the user to start the application to
be profiled in another window and exercise its functionality
It then presents the user with two options, (S)can system log for entries to add to profile and (F)inish.
If the user selects (S)can or hits return, aa-genprof will parse the complain mode logs and iterate through generated violations using
aa-logprof(1).
After the user finishes selecting profile entries based on violations that were detected during the program execution, aa-genprof will
reload the updated profiles in complain mode and again prompt the user for (S)can and (D)one. This cycle can then be repeated as necessary
until all application functionality has been exercised without generating access violations.
When the user eventually hits (F)inish, aa-genprof will set the main profile, and any other profiles that were generated, into enforce mode
and exit.
BUGS
If you find any bugs, please report them at <http://https://bugs.launchpad.net/apparmor/+filebug>.
SEE ALSO
apparmor(7), apparmor.d(5), aa-enforce(1), aa-complain(1), aa-disable(1), aa_change_hat(2), aa-logprof(1), logprof.conf(5), and
<http://wiki.apparmor.net>.
AppArmor 2.7.103 2012-06-28 AA-GENPROF(8)