home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!spool.mu.edu!agate!ucbvax!ZENO.MSCD.EDU!LABELLES
- From: LABELLES@ZENO.MSCD.EDU (Stephen LaBelle - MSCD)
- Newsgroups: comp.os.vms
- Subject: Re: RE: Operator Accounts
- Message-ID: <01GTTIP7JBB28WW9IZ@ZENO.MSCD.EDU>
- Date: 22 Jan 93 18:59:39 GMT
- Sender: daemon@ucbvax.BERKELEY.EDU
- Distribution: world
- Organization: The Internet
- Lines: 51
-
- Dan Wing, dwing@uh01.colorado.edu or wing_d@ucolmcc.bitnet, writes:
-
- *!Stephen LaBelle, <LABELLES@ZENO.MSCD.EDU>, writes:
- *!
- *!>You can control priviledges and still allow your operators to do their work
- *!>by setting up one or more restricted accounts. Look at the restricted flag
- *!>for UAF records. I personally like using the "RESTRICTED" flag, VMS takes
- *!>care
- *!>of some of the security issues as far as breaking out to the dollar sign.
- *!>I challenged a couple of my operators to break it they could not.
- *!
- *!If you want a captive account, use CAPTIVE and not RESTRICTED. See VMS V5.5
- *!release notes, section 2.4.3, which warns that in "a future release of VMS,
- *!system software components will be modified so they do not use the RESTRICTED
- *!flag to disable SPAWN commands. In particular, MAIL and TPU will not disable
- *!a SPAWN command ... if the account has been marked RESTRICTED.". There's
- *!more
- *!text in the actual release notes that details this modification.
- *!
- *!-Dan Wing, dwing@uh01.colorado.edu or wing_d@ucolmcc.bitnet (DGW11)
- *! Systems Administrator, University Hospital, Denver
-
- Hello INFO-VAX and/or COMP.OS.VMS,
-
- For the record, Dan Wing is a friend of mine. He also is someone whom many
- times keeps me on my toes! Dan pointed out that one should use CAPTIVE and
- NOT RESTRICTED. I stand corrected! In fact I have a security hole which I
- will be plugging today.
-
- To the original party whom posted the inquiry, follow Dan's advice not
- mine. Use the CAPTIVE flag!!! This assumes you set things up in a manner
- such as I suggested, you may choose not to.
-
- I also found some of the other responses about doing operator with a
- a specific account for each of them interesting. A different rationale,
- with its own merits.
-
- Dan volunteered to break my operator environment! I declined!
-
- Steve
-
- ##############################################################################
- # Stephen LaBelle # Internet : labelles@zeno.mscd.edu #
- # Systems Programmer # labelles@clem.mscd.edu #
- # Metropolitan State College of Denver #####################################
- # Denver, Colorado USA # Bitnet : LABELLES@MSCD.BITNET #
- ##############################################################################
- # DISCLAIMER: The opinions expressed are mine and in no way, shape or form #
- # neccessarily reflect those of Metropolitan State College of Denver. #
- ##############################################################################
-
-