home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!spool.mu.edu!agate!ucbvax!UH01.Colorado.EDU!DWING
- From: DWING@UH01.Colorado.EDU (Dan Wing)
- Newsgroups: comp.os.vms
- Subject: Re: operator accounts
- Message-ID: <01GTTB8GP1XE006MJF@VAXF.COLORADO.EDU>
- Date: 22 Jan 93 16:11:53 GMT
- Sender: usenet@ucbvax.BERKELEY.EDU
- Organization: The Internet
- Lines: 18
-
- Stephen LaBelle, <LABELLES@ZENO.MSCD.EDU>, writes:
-
- >You can control priviledges and still allow your operators to do their work
- >by setting up one or more restricted accounts. Look at the restricted flag
- >for UAF records. I personally like using the "RESTRICTED" flag, VMS takes care
- >of some of the security issues as far as breaking out to the dollar sign.
- >I challenged a couple of my operators to break it they could not.
-
- If you want a captive account, use CAPTIVE and not RESTRICTED. See VMS V5.5
- release notes, section 2.4.3, which warns that in "a future release of VMS,
- system software components will be modified so they do not use the RESTRICTED
- flag to disable SPAWN commands. In particular, MAIL and TPU will not disable
- a SPAWN command ... if the account has been marked RESTRICTED.". There's more
- text in the actual release notes that details this modification.
-
- -Dan Wing, dwing@uh01.colorado.edu or wing_d@ucolmcc.bitnet (DGW11)
- Systems Administrator, University Hospital, Denver
-
-