LinuxQuestions.org
Visit Jeremy's Blog.
Go Back   LinuxQuestions.org > Forums > Other *NIX Forums > AIX
User Name
Password
AIX This forum is for the discussion of IBM AIX.
eserver and other IBM related questions are also on topic.

Notices

Reply
 
LinkBack Search this Thread
Old 01-10-2008, 01:11 PM   #1
mudman69
Member
 
Registered: Mar 2007
Distribution: Whatever Works
Posts: 44

Rep: Reputation: 16
AIX Default User List


I have this AIX 5.3 machine kinda just thrown at me and they want me to clean up system. The first thing I wanted to do was rmuser all the users that aren't needed by the system. I tried to find (google) a list of "System Users" and really couldn't find what I was looking for. Ne1 have any ideas where else I might look?

By "System Users" I mean root,daemon,bin,sys,adm....
 
Old 01-10-2008, 04:00 PM   #2
Harry Seldon
Member
 
Registered: Feb 2004
Distribution: SLES 9
Posts: 112

Rep: Reputation: 15
I work at a company that gets audited all the time. The ones we're most commonly asked to remove are guest, lpd, uucp, nuucp (if it's there) and imnadmin. Here's a list of accounts I put together about a year ago; most of it is relevant, I think:

daemon - The daemon user account exists only to own and run system server processes and their associated files. This account guarantees that such processes run with the appropriate file access permissions.

bin - The bin user account typically owns the executable files for most user commands. This account's primary purpose is to help distribute the ownership of important system directories and files so that everything is not owned solely by the root and sys user accounts.

sys - The sys user owns the default mounting point for the Distributed File Service (DFS) cache, which must exist before you can install or configure DFS on a client.

adm - The adm user account owns the following basic system functions:
* Diagnostics, the tools for which are stored in the /usr/sbin/perf/diag_tool directory.
* Accounting, the tools for which are stored in the following directories:
o /usr/sbin/acct
o /usr/lib/acct
o /var/adm
o /var/adm/acct/fiscal
o /var/adm/acct/nite
o /var/adm/acct/sum

uucp - Owner of hidden files used by uucp protocol. The uucp user account is used for the UNIX-to-UNIX Copy Program, which is a group of commands, programs, and files, present on most AIX systems, that allows the user to communicate with another AIX system over a dedicated line or a telephone line.

guest - Allows access to users who do not have access to accounts.

nobody - The nobody user account is used by the Network File System (NFS) to enable remote printing. This account exists so that a program can permit temporary root access to root users

lpd - Owner of files used by printing subsystem. This account has been disabled.

imnadm - IMN search engine used for Documentation Library Search.

lp - Possibly something to do with printing.

invscout - Surveys the host system for currently installed microcode or Vital Product Data (VPD).

snapp - The account that manages Snapp, an extensible, XML-based application that provides a menu-driven interface for UNIX system administration tasks on a handheld PDA.

sshd - The user account for managing the sshd service.
 
Old 01-11-2008, 09:18 AM   #3
mudman69
Member
 
Registered: Mar 2007
Distribution: Whatever Works
Posts: 44

Original Poster
Rep: Reputation: 16
AWESOME! Thanks!
 
Old 01-30-2008, 10:59 AM   #4
Michael AM
Member
 
Registered: May 2006
Posts: 65

Rep: Reputation: 16
Since TL05 in AIX 5.3 there is a program called aixpert - or AIX Expert. It is meant to be a standard method to harden AIX. There are four 'press a button levels': 'None' (or factory), 'Low', 'Medium', and 'High'.

There is also a 'Custom' setting where the admin makes choices. Can be used from command-line, smit and websm.

Was expanded greatly (e.g. LDAP support for policy distribution) in AIX 6.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
How to list user in Linux box, add an user to a group! steady_lfcfan Linux - Newbie 10 05-03-2010 03:52 AM
AIX User Groups in India newaixuser AIX 1 09-02-2006 01:06 AM
User access in AIX DriveMeCrazy AIX 2 08-20-2004 01:04 PM
Default print settings on AIX (5.2) that does not have SysV printing enabled euchre513 AIX 0 07-21-2004 09:19 AM
default user list PlatinumRik Linux - Security 1 04-27-2004 06:35 PM


All times are GMT -5. The time now is 01:13 PM.

Main Menu
 
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: @linuxquestions
Open Source Consulting | Domain Registration