Ownership And Management Of Client Mode Entities - HP NonStop SSH 544701-014 Reference Manual

Table of Contents

Advertisement

Be the owner of the underlying Safeguard user ID of <user-or-alias> or be the group manager of the owner of
the underlying Safeguard user ID of <user-or-alias>
SSHCOM Access Summary
Shortcuts used in the following table:
'SUPER' - SUPER.SUPER
'OU' - OBJECTTYPE USER
'OUR' - OBJECTTYPE USER RECORD
'FullSA' - FULLSSHCOMACCESSUSERi/GROUPj
'PartialSA' - PARTIALSSHCOMACCESSUSERk/GROUPn
User is
Thawed
'SUPER'
'OU' exists
(Yes/No)
(Yes/No)
Yes
No
Yes
Yes
Yes
Yes
Yes
Yes
Yes
Yes
No
No
No
No
No
No
No
Yes
No
Yes
No
Yes
No
Yes
No
Yes

Ownership and Management of Client Mode Entities

In release 89 a finer granularity for access and administration of mode client records was introduced. In previous releases
client mode records were owned by a Guardian user identifier. Even when logged on as alias the underlying Guardian
identifier was used to add and retrieve KEY, PASSWORD and KNOWNHOST records. The philosophy behind this
assumed that one person used a specific Guardian user identifier as well as the configured aliases for that Guardian user
identifier. This approach is consistent with the general security on NonStop (ACL, file security, etc.), which is based on
the Guardian user identifier.
As each alias has its own password it is possible to create a NonStop environment where different persons use different
aliases pointing to the same Guardian user identifier. In such an environment storing KEY, PASSWORD and
KNOWNHOST records under the same user id represents a security problem:
Assuming aliases a1 and a2 exist, both configured with underlying Guardian user identifier grp1.usr1. If alias a1 stored a
password for remote host h1 and remote user u1 in the client mode database (under grp1.usr1), then alias a2 can connect
to host h1 specifying remote user u1 using the stored password entry, i.e. alias a2 gets access to remote host h1 without
knowing the password of remote user u1.
HP NonStop SSH Reference Manual
User configured
User included in
'FullSA'
in 'OUR'
configuration
(No / Create /
DENY Create /
(Yes / No / Not
Not Applicable)
Applicable)
N/A
N/A
No
N/A
Create
N/A
DENY Create
N/A
DENY Create
N/A
N/A
No
N/A
No
N/A
Yes
No
N/A
No
N/A
Create
N/A
DENY Create
N/A
DENY Create
N/A
User included in
Allowed USER Commands
'PartialSA'
(All / Alter&Info / None)
configuration
(Yes/No)
N/A
All
N/A
All
N/A
All
No
None
Yes
Alter&Info
No
None
Yes
Alter&Info
N/A
All
No
None
Yes
Alter&Info
N/A
All
No
None
Yes
Alter&Info
SSHCOM Command Reference • 137

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents