12-17-2005
Preventing passwd root?
I knew it would happen sooner or later....
We have a requirement that specific individuals need "sudo root" authority. I knew it only a matter of time before someone decided to change the root password (at least they owned up to it).
Now the question is how can I grant all rights except execution of passwd root? I've tried entering the following line in my sudoers file but it didn't seem to make much difference.
GRP_IDS ALL = (ALL) !/usr/bin/passwd *root*, ALL
Thanks
10 More Discussions You Might Find Interesting
1. UNIX for Dummies Questions & Answers
Hello chiefs :)
I have a SUN Enterprise 250, running Solaris 8.5 - I have managed to be able to connect a dumb terminal to the box via a standard straight-through rj45 cable, to my ibm laptop. OK so Putty can connect to the box via ssh - nice! But I dont have the password for root - or any... (1 Reply)
Discussion started by: congo
1 Replies
2. UNIX for Dummies Questions & Answers
I booted up Sun V240 server with boot cdrom -s using the Sun Operating System CD. I now am at the # prompt and su - root . The system will not allow me to set password for root. Get following error:
# passwd
New Password: xxxxxxxx
Re-enter new Password: xxxxxxxx
passwd: Unexpected failure. ... (4 Replies)
Discussion started by: mayewil
4 Replies
3. Solaris
Any body pls let me know the procedure to recover ROOT password in Sun Netra 20 Server..I forgot the password. (5 Replies)
Discussion started by: gini
5 Replies
4. Solaris
I forget the Root Passwd of my Sun Netra 20 server and break the same by editing /etc/shadow.Now there is no passwd for Root.
And How to set new root passwd?Pls help.... (2 Replies)
Discussion started by: gini
2 Replies
5. UNIX for Dummies Questions & Answers
heyy
i forgot my root passwd but i cant reinstall due to some reason can anyone tell me hw to reterive root passwd (10 Replies)
Discussion started by: mightypp.nits
10 Replies
6. UNIX for Dummies Questions & Answers
Hi All,
Today I faced a problem trying to log in as root. The output error is
cannot execute sh: No such file....
I doubted there is something wrong with shell interpreter which resides in /etc/passwd file for every user who logs in.
I checked and the line for root account was... (4 Replies)
Discussion started by: elthox
4 Replies
7. Red Hat
hi
i have a RHEL 4 and have forgot root passwd
tried to boot in by singel user and then changing the passwd but it's not letting me do that ......throwing some weird error as .......manipulation
i also tried to make a new user from CLI but even though it's not letting me in from that user as... (12 Replies)
Discussion started by: techbravo
12 Replies
8. AIX
Hi Guys,
some one could help me on this that will be great .
I have AIX 5.1 . when ever u login as root .it says u r passwd is expiredchoose new passwd . I tried couple of times changeing the passwd .still it behaves every time u login it asks to change the passwd . i teied to lokk into... (3 Replies)
Discussion started by: aixguy
3 Replies
9. Red Hat
I accidentally changed root shell from /bin/bash to bash in /etc/password, then logged out from root. Now I can't login as root and got "No shell" error, although I have root password. "su -f -s /bin/bash" command does NOT work. There is no GUI interface for this system.
My question: Do I have... (7 Replies)
Discussion started by: aixlover
7 Replies
10. Solaris
hi all
I'm new to solaris
my vncviewer windows is closed suddenly after give root and root passwd in solaris 10 sparc machine ... i checked vnc services are online and everything is ok .. but i dont know how to solve this solution... any one face this solution before and share your knowledge ... (1 Reply)
Discussion started by: coolboys
1 Replies
LEARN ABOUT POSIX
d_passwd
d_passwd(4) File Formats d_passwd(4)
NAME
d_passwd - dial-up password file
SYNOPSIS
/etc/d_passwd
DESCRIPTION
A dial-up password is an additional password required of users who access the computer through a modem or dial-up port. The correct pass-
word must be entered before the user is granted access to the computer.
d_passwd is an ASCII file which contains a list of executable programs (typically shells) that require a dial-up password and the associ-
ated encrypted passwords. When a user attempts to log in on any of the ports listed in the dialups file (see dialups(4)), the login program
looks at the user's login entry stored in the passwd file (see passwd(4)), and compares the login shell field to the entries in d_passwd.
These entries determine whether the user will be required to supply a dial-up password.
Each entry in d_passwd is a single line of the form:
login-shell:password:
where
login-shell The name of the login program that will require an additional dial-up password.
password An encrypted password. Users accessing the computer through a dial-up port or modem using login-shell will be required to
enter this password before gaining access to the computer.
d_passwd should be owned by the root user and the root group. The file should have read and write permissions for the owner (root) only.
If the user's login program in the passwd file is not found in d_passwd or if the login shell field in passwd is empty, the user must sup-
ply the default password. The default password is the entry for /usr/bin/sh. If d_passwd has no entry for /usr/bin/sh, then those users
whose login shell field in passwd is empty or does not match any entry in d_passwd will not be prompted for a dial-up password.
Dial-up logins are disabled if d_passwd has only the following entry:
/usr/bin/sh:*:
EXAMPLES
Example 1: Sample d_passwd file.
Here is a sample d_passwd file:
/usr/lib/uucp/uucico:q.mJzTnu8icF0:
/usr/bin/csh:6k/7KCFRPNVXg:
/usr/bin/ksh:9df/FDf.4jkRt:
/usr/bin/sh:41FuGVzGcDJlw:
Generating An Encrypted Password
The passwd (see passwd(1)) utility can be used to generate the encrypted password for each login program. passwd generates encrypted pass-
words for users and places the password in the shadow (see shadow(4)) file. Passwords for the d_passwd file will need to be generated by
first adding a temporary user id using useradd (see useradd(1M)), and then using passwd(1) to generate the desired password in the shadow
file. Once the encrypted version of the password has been created, it can be copied to the d_passwd file.
For example:
1.
Type useradd tempuser and press Return. This creates a user named tempuser.
2. Type passwd tempuser and press Return. This creates an encrypted password for tempuser and places it in the shadow file.
3. Find the entry for tempuser in the shadow file and copy the encrypted password to the desired entry in the d_passwd file.
4. Type userdel tempuser and press Return to delete tempuser.
These steps must be executed as the root user.
FILES
/etc/d_passwd dial-up password file
/etc/dialups list of dial-up ports requiring dial-up passwords
/etc/passwd password file
/etc/shadow shadow password file
SEE ALSO
passwd(1), useradd(1M), dialups(4), passwd(4), shadow(4)
WARNINGS
When creating a new dial-up password, be sure to remain logged in on at least one terminal while testing the new password. This ensures
that there is an available terminal from which you can correct any mistakes that were made when the new password was added.
SunOS 5.10 2 Sep 2004 d_passwd(4)