Notification of Password Expired for Root Equivalent ID

This is a discussion on Notification of Password Expired for Root Equivalent ID within the Linux Security forums, part of the System Security and Security Related category; Hi, I have a Red Hat Enterprise Linux AS release 4 (Nahant) here. When a user's password is expired, ...


Go Back   Usenet Forums > System Security and Security Related > Linux Security

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 01-04-2007
Jenny
 
Posts: n/a
Default Notification of Password Expired for Root Equivalent ID

Hi,

I have a Red Hat Enterprise Linux AS release 4 (Nahant) here.

When a user's password is expired, the system will prompt the user to
change the password. However, when a root-equivalent ID's password is
expired, the system would not prompt user to change password. Instead,
it does not allow the root equivalent ID to sign on although the
password is correct. The error message displayed is "Access Denied". I
would like to know, how can we configure so that when a root equivalent
ID's password is expired, the system will prompt for a password change
and then allow user to sign on to the system.

Thanks and regards,
Jenny

Reply With Quote
  #2 (permalink)  
Old 01-04-2007
Phil Sherman
 
Posts: n/a
Default Re: Notification of Password Expired for Root Equivalent ID

I'd suspect that this is done as a security measure because a "root
equivalent" ID has a lot of authority on a system. Your best bet may be
to setup a script for those users that will check the password
expiration at each logon and notify the user when the password is within
n days of expiring. Of course, this won't help the user who goes on a
two week vacation and has the password expire near the end of it.

Phil Sherman


Jenny wrote:
> Hi,
>
> I have a Red Hat Enterprise Linux AS release 4 (Nahant) here.
>
> When a user's password is expired, the system will prompt the user to
> change the password. However, when a root-equivalent ID's password is
> expired, the system would not prompt user to change password. Instead,
> it does not allow the root equivalent ID to sign on although the
> password is correct. The error message displayed is "Access Denied". I
> would like to know, how can we configure so that when a root equivalent
> ID's password is expired, the system will prompt for a password change
> and then allow user to sign on to the system.
>
> Thanks and regards,
> Jenny
>

Reply With Quote
  #3 (permalink)  
Old 01-05-2007
Michael Heiming
 
Posts: n/a
Default Re: Notification of Password Expired for Root Equivalent ID

In comp.os.linux.security Jenny <yennee_yap@yahoo.com>:
> Hi,


> I have a Red Hat Enterprise Linux AS release 4 (Nahant) here.


> When a user's password is expired, the system will prompt the user to
> change the password. However, when a root-equivalent ID's password is
> expired, the system would not prompt user to change password. Instead,


What is that? Do you have more then one user with UID 0? Very
very bad idea, use sudo instead:

$ man -k sudo
sudo (8) - execute a command as another user
sudoers (5) - list of which users may execute what
visudo (8) - edit the sudoers file

Good luck

--
Michael Heiming (X-PGP-Sig > GPG-Key ID: EDD27B94)
mail: echo zvpunry@urvzvat.qr | perl -pe 'y/a-z/n-za-m/'
#bofh excuse 335: the AA battery in the wallclock sends
magnetic interference
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 08:04 PM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0