[comp.os.vms] PCFS 1.1 security

S211KENO@HTIKUB5.BITNET (06/21/88)

> HELP!
> We recently received PCFS 1.1 (PC-file-server) and I'm supposed to
> install this product.
> Now it wants to do remarkable things during its installation, like
>
> create user accounts with network access and NO password ...
>
> (it's from DEC, really!)
> Did anyone install that beast WITHOUT completely compromising
> system security?
>
> Wolfgang J. Moeller, GWDG, D-3400 Goettingen, F.R.Germany | Disclaimer ...
> Bitnet/Earn: U0012@DGOGWDG5         Phone: +49 551 201516 | No claim intended

There are 2 solutions:

- wait for version 2.0 which has eliminated the need for the network
  accounts.
- give every PCFS account a captive login-command procedure
  which does one thing: $ LOGOUT
  For example:
  UAF> modify [15,*] /lgi=sys$manager:pcfs_login   ! 15 is the pcfs group

  this way it is impossible to login under the account but it is still
  perfectly usable with PCFS ! (I think because actually PCFS does not
  login but only CHECKS if login is possible. And login IS possible,
  but immediately followed by logout).

=========================================================================
Kees Noyens
Computing Centre Tilburg University
P.O. Box 90153
5000 LE Tilburg
The Netherlands

Surfnet : KUBVX1::S211KENO
Bitnet  : S211KENO@HTIKUB5.BITNET
Internet: S211KENO%HTIKUB5.BITNET@CUNYVM.CUNY.EDU