(9889) Security and Password Verification?

Archive of the OpenVMS Ask the Wizard (ATW) questions and answers database.
Locked

Topic author
User
Visitor
Posts: 0
Joined: Mon Jan 10, 2022 8:16 am
Reputation: 0
Status: Offline

(9889) Security and Password Verification?

Post by User » Wed Oct 27, 2004 9:26 am

Where and how do I list the pwd.h file I need to map the pwd.h to validate users for a specific routine
Last edited by marty.stu on Thu Aug 18, 2022 9:52 am, edited 1 time in total.


Wizard
Visitor
Posts: 0
Joined: Mon Jan 10, 2022 8:17 am
Reputation: 0
Status: Offline

Re: (9889) Security and Password Verification?

Post by Wizard » Thu Oct 28, 2004 9:26 am

Use the $acm system service, or -- better -- use standard OpenVMS system security attributes including security identifiers or such.

Verifying a password directly can introduce security problems, permitting security attacks and (if not implemented entirely
correctly) bypassing standard security defenses including auditing and evasion.

The OpenVMS Wizard would recommend review of the security manual, and would generally avoid directly verifying the password within an application.
Last edited by marty.stu on Thu Aug 18, 2022 9:52 am, edited 1 time in total.

Locked