home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.os.vms
- Path: sparky!uunet!usc!sdd.hp.com!ux1.cso.uiuc.edu!news.cso.uiuc.edu!uihepa.hep.uiuc.edu!MAKO
- From: mako@uihepa.hep.uiuc.edu ("Makoto Shimojima, Univ of Tsukuba/CDF")
- Subject: RE: operator accounts
- References: <9301210244.AA05110@uu3.psi.com>
- Message-ID: <C19yos.HML@news.cso.uiuc.edu>
- Sender: usenet@news.cso.uiuc.edu (Net Noise owner)
- Reply-To: mako@uihepa.hep.uiuc.edu
- Organization: High Energy Physics, University of Illinois, Urbana-Champaign
- Date: Fri, 22 Jan 1993 21:36:27 GMT
- Lines: 36
-
- In article <9301210244.AA05110@uu3.psi.com>, leichter@lrw.com (Jerry Leichter) writes:
- >
- > Some sites use a single privileged account with an additional
- > "sign in" in a forced login file. (Individual operators on
- > such a system usually get individual non-privileged accounts
- > as well.) The theory is to provide a central log of operator
- > logins. Often, the "sign in" asks for a one-line comment
- > about what the person intends to do.
-
- On our system at Tsukuba, we share SYSTEM account among our student
- managers --- in Japanese University it is not easy to hire a system
- manager or an operator and since the entire cluster was used by us
- (10-20 people, mostly students) we had to manage it ourselves.
-
- When I was one of such managers, someone had already written a little
- command procedure that asked who it was when we logged into SYSTEM
- and logged it in a file. Of course we could type in anything, so I
- modified it to check if it was a valid username and if that account
- had a particular identifier granted (basically $ASCTOID + $FIND_HELD).
-
- That worked fairly well, I think, though from time to time, I saw _my_
- name in the database while I was here... You see, it logs the remote
- site/id information (or port name if local) as well as other useful
- information so I know it was not me. (Well, I think I could login to
- that system "locally" through the terminal server, but I say I do not
- remember the password anymore.)
-
- Anyway, if that bothers you, you could also ask for the password of
- the account in noecho mode, encrypt it, and check it with the hashed
- quadword in the SYSUAF database. (I never found it that bothersome.)
-
- mako
- (mako@uihepa.hep.uiuc.edu)
-
- PS: I also created BACKUP captive account to backup user files to
- 8mm/VHS tapes but that was mainly to make the task efficient.
-