home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!mcsun!Germany.EU.net!urmel.informatik.rwth-aachen.de!beor!jonas
- From: jonas@beor.informatik.rwth-aachen.de (Josef Nelissen)
- Newsgroups: comp.sys.hp
- Subject: vuesession's lock seems to be broken under /.secure
- Date: 17 Dec 92 16:09:25 GMT
- Organization: Rechnerbetrieb Informatik - RWTH Aachen
- Lines: 35
- Message-ID: <jonas.724608565@beor>
- NNTP-Posting-Host: beor.informatik.rwth-aachen.de
- Summary: Locking by using vuesession doesn't work under /.secure
- Keywords: vue, sessionmgr, lock, security
-
- Hi netters,
- I just detected that vuesession's lock facility seems to be broken
- under /.secure on a HP720 with HP-UX 8.07.
- The facts: I had locked the screen by use of the workspace manager's
- lock button. Then, some minutes later, not recognizing the locking, I
- typed in a command, which is pretty sure not my or root's password :-).
- After hitting return the lock mask disappeared and I could proceed as
- if I had typed in the correct password.
-
- Well, as I easily recall the ugly beep which followed the input of an
- incorrect password some weeks ago, something must have happened in the
- meantime which caused the incorrect behaviour of the lock function.
- The only thing I can think of is the change to /.secure to hold the
- decoded passwords, and this seems to be quite reasonable for the
- failure of the lock.
-
- Now my two questions:
-
- 1. Is this a known bug or can anyone think of another reason why the
- locking fails (I have tested this behaviour on another HP 720 with the
- same result)?
-
- 2. Is there an easy fix or workaround available? Our local guru told
- me, that the only possibility would be to run the lock program under
- suid to access the (secure :-) passwords, which he rated as a
- double-edged thing.
-
- Any help would be greatly appreciated.
-
- Thanks in advance, Josef
- --
- Josef Nelissen, Lehrstuhl fuer Angewandte Mathematik, insbesondere Informatik,
- RWTH-Aachen, Ahornstr. 55, W-5100 Aachen, Germany, Tel. +49 241/80-21060,
- FAX +49 241/80-21079, e-mail jonas@beor.informatik.rwth-aachen.de
- *******************************************************************************
-