How to disable role password in Solaris 11

Roles can only be assumed by logged in users. That is the definition of a role. Therefore role authentication is to some extent double authentication. The user has already authenticated as himself when he logged in and the sysadmin has enough trust in him to grant him a certain role. So why would he need to authenticate to the role? Isn't that double authentication ? Anyway I can see why that makes sense on a role like 'root' but on other more normal types of roles ? Really?
Anyway that is not what this posting is about. It is about me not being able to figure out how to disable role password in Oracle 11.
In Solaris 10 I would do:
<pre>passwd -r files -d myrole</pre>
That would set the myrole account to a no password account and that would be enough to disable it.
In Solaris 11 I cannot make this work. I suspect this is because of the introduction of the roleauth attribute but I've tried all possible combinations:
<pre>passwd -r files -d myrole</pre>
<pre>rolemod -K roleauth=user myrole</pre>
or
<pre>passwd -r files -d myrole</pre>
<pre>rolemod -K roleauth=role myrole</pre>
Can't make any of these work.
Pls help.

Hello MrMonza,
I do not completely understand what you are looking for. Perhaps it would help if you explained, for which purpose you want to use your new role.
In short, a role is simply a user account, to which you cannot login directly. As to every user account, rights are assigned to each role. And as for every user account, you have to provide a password for it.
If you want to switch to a role without password, this is nearly the same as extending the rights of your account.
This is possible by assigning additional profiles to it via /etc/user_attr. Privileged commands, written by you, and connected to these profiles, can be defined in /etc/security/exec_attr.d/local-entries. These commands can be called via pfexec, see pfexec(1), which grants privileges (e.g. uid=0) for just the call.
See also user_attr(4), prof_attr(4), exec_attr(4) and the "SEE ALSO" sections in there.
Profiles can be chosen from the predefined profiles in /etc/security/prof_attr.d, or they can be self-assembled from these profiles and authorizations from /etc/security/auth_attr.d.
New profiles should be stored in /etc/security/prof_attr.d/local-entries.

Similar Messages

  • How to disable the password asked everytime I try to acces my contacts

    Hi, I'd like to know how to disable the password asked everytime I try to acces my contacts (another lousy feature of that lousy os!) Thanks!

    Settings>General>Restrictions...are yours on? Read here:
    http://support.apple.com/kb/ht4213

  • How to disable backup password

    how to disable backup password knowing that the box under backup (encrypt local backup) is not aailable to unmark

    Well, you can't, if that's the case. The requirement to encrypt your backup can be enforced by setting up an Exchange account on your phone, if you have such.

  • How to disable change password at next logon field

    Hello,
    I want to disable change password at next logon field,so could anyone tell me how to do that & what is
    the column name in USR table for change password at next logon field.
    Thank-You
    Rahul Shah

    For 9.x
    Open FormMetaData.xml and comment the below lines
    <Attribute name="-31" label="createuser.label.changePwdAtNextLogon" displayComponentType="CheckBox" variantType="String" dataLength="1" map="Users.Change Password At Next Logon" />
    <AttributeReference editable="true" optional="true">-31</AttributeReference>
    Now open design console go to Administration->>System Configuration and search for keyword XL.ForcePasswordChangeAtFirstLogin. Set this value to FALSE.
    Dont forget to restart the server.

  • How to disable BIOS password

    hi please help me,my hp pavillion dv6-2112sa always ask me for administration password whenever i on my computer.i know the password but dont know how to disable it.pls help
    This question was solved.
    View Solution.

    Hi,
    You can remove the need for a power on password as follows.
    Shut down the notebook.  Tap away at the esc key as soon as you press the power button to access the Start-up menu and then select f10 to enter the Bios menu.  Use the arrow keys to highlight the Security tab and hit enter.  Use the arrow keys again to highlight power on password and hit enter.  Enter the current password and then for the new password, just leave this blank and hit enter - do the same for the confirmation field.  Press f10, select to save the new settings and hit enter.
    Regards,
    DP-K
    ****Click the White thumb to say thanks****
    ****Please mark Accept As Solution if it solves your problem****
    ****I don't work for HP****
    Microsoft MVP - Windows Experience

  • How to disable BIOS password on Satellite Pro A120?

    Is it possible to disable BIOS password on Pro A120 laptop?
    I know the password, but I can't delete it. I tried both through Password Utility on Windows and through BIOS, and in both I can change the password, but not disable it (i get DELETION DENIED message).
    Thanks in advance.

    Hi there Majkel and all others,
    This forum gui is difficult to use/understand so apologies for my naivety.
    This is a strange situation so hopefully someone can help!
    Recently I found a Toshiba A120 satellite pro in a rubbish bin.
    I cant stand the idea of goog tech going to waste so I pick it out and dusted it off hoping that I could get it
    working again.
    However even though when I got it home and it powered up oh joy, my glee was indeed short lived by
    one single word, thats right
    "password="
    I tried reading the sata hard drive on a separate usb to see if I could find out whose it was and contact them.
    Hard drive dead.
    I tried knocking on all the doors near where I found it to find the owner and try and get the password from them.(fingers crossed someone may be able to help?)
    I tried my nearest laptop repair shop he quoted 100 for soldering in a new bios chip which sounded expensive and suspiciously like it wouldnt work.
    I'm willing to send it into toshiba if I have to but I would really like to find a way to contact the original owner
    and simply ASK THEM what the password is, I would even pay them to find out if I had to.
    The only info I have is the serial number which is- s/n- 76041309h or the longer number on the bottom which is- i76041309hssac0007009ENB
    If there is any way to get hold of the original owner and ask them it would be a godsend!
    Thank you to anyone who can help!
    Luke ;-)

  • How to disable change password in finder while connecting to a network computer?

    Hi folks,
    I'd like to disable the Change Password option that shows when I want to connect into a network computer:
    - Both users (client and server) are already running with parental controls set to "prevent(s) the user from changing their password in the Users & Groups preference pane".
    Thanks in advance.

    Hi,
    I am also facing the same issue and I am not able to su to root user as the password is expired. and the user I am currently logged in does not have permission to change the root password. I just want to know how I can change the root password now? I am connected to my SPARC Solaris 10 T1000 server through hyperterminal.
    The worst thing is that, I do not have IP to the server through which I can try ssh to the server and change the password. Please let me know the solution if you know.
    Thanks in advance.

  • How to disable bios password for desktop hp envy 700 056

    I tried to remove the battery out of the motherboard and wait for 1 minutes and more, and then put in back the motherboard, but the password is still there. I don't know how to remove or disable the bios password. I need help, please.
    Thank you very much.

    Hi,
    Review this posted HP information.
    HP DV9700, t9300, Nvidia 8600, 4GB, Crucial C300 128GB SSD
    HP Photosmart Premium C309G, HP Photosmart 6520
    HP Touchpad, HP Chromebook 11
    Custom i7-4770k,Z-87, 8GB, Vertex 3 SSD, Samsung EVO SSD, Corsair HX650,GTX 760
    Custom i7-4790k,Z-97, 16GB, Vertex 3 SSD, Plextor M.2 SSD, Samsung EVO SSD, Corsair HX650, GTX 660TI
    Windows 7/8 UEFI/Legacy mode, MBR/GPT

  • How to disable/set password expiration to None in EBS

    HI ,
    I just clone a 11i , and was asked to set all users password not to expire . I have studied FND_USER_PKG.UPDATEUSER , but has no idea how to do it . Can anyone help ? Thanks
    Felix

    Hi;
    Please check below which could be helpful for your issue:
    Password information-Where ebs pass keep
    Re: Password information
    password expiration for EBS users
    how to set password expiration for EBS users
    password polciy
    Password policy
    Regard
    Helios

  • How to disable asking password when session expires

    Hi,
    When the session is timed out, I want application should automatically turned on when I click on alert/message box.
    Please suggest me in what way I can do this.
    Thanks in Advance!!!
    Regards
    Madhu Kumar

    Hi,
    This is an expected behavior and you cannot let the user login again without entering the username/password.
    One possible solution would be increasing the session timeout.
    Note: 269884.1 - How To Fix The Forms Timeout Issue In Oracle Applications 11i
    https://metalink2.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=269884.1
    Regards,
    Hussein

  • How to disable/remove password requirement every time you send amessage

    Every time I try to send an email, I get a box requiring me to type in a password (the one associated w/my ISP provider account). I can't find a way to turn off. My daughter uses Thunderbird & does not have this problem. She has a desktop pc & I am using a laptop, but I wouldn't think that would make a difference? This is so annoying and I couldn't find an answer any where in HELP or online support. My daughter set Thunderbird up for me & can't figure out why this is happening or how to make it so I don't have to do this. Please help & provide me w/a solution. THANKS!

    There is no check box with, at or near the password requirement. It is the same password used to access my server (comcast.net). I have asked comcast.net and they told me it is a Mozilla Thunderbird problem, and they have no control over it, so can't fix the problem - CALL THUNDERBIRD!
    But Thunderbird doesn't have any customer service. The problem only began when I had to change my comcast.net password (and no, the old one doesn't work either now).

  • How to delete saved passwords in SQL Developer User Profiles

    Hi
    Can anyone advise on how to delete (or flush-out) saved passwords in SQL developer connections? I have a serious security concern about saved passwords at user level and need a quick method to remove them from the backend without actual user's intervention.
    An early response is highly appreciated.
    Thanks
    UJ

    I have a serious security concern about saved passwords at user levelIf you could share more about your concerns, it might help us address or alleviate said concerns. Basically if your user's desktops are secure, then so are the passwords.
    To delete them w/o user intervention you would need to delete their connections by removing the file(s) from their installs. To prevent the problem from happening again, you'd need to put down a new sqldeveloper.conf file in their bin directory that would keep them from saving passwords - example here
    http://www.thatjeffsmith.com/archive/2012/04/how-to-disable-save-password-in-oracle-sql-developer/

  • OIM11g - disable set password on first logon + force challenge questions

    Hi all,
    I was initially trying to work out how to stop forcing users to set their passwords on first login. Initially by using the Force Password Change at First Login flag.
    I found the following in metalink:
    BUG:10256559: DOCUMENT THAT XL.FORCEPASSWORDCHANGEATFIRSTLOGIN NO LONGER USED IN 11G
    The system property "Force Password Change at First Login" is not used in Oracle Identity Manager 11g Release 1 (11.1.1). Setting this property has no effect.
    I have also tried setting all of the flags on a user relating to this manually, but that hasn't worked either e.g.
    usr_change_pwd_at_next_logon
    usr_pwd_must_change
    I saw the following workaround in metalink:
    How To : How to Disable Change Password At Next Logon in OIM 11g
    Go to EM and change the ssoEnabled flag as per below instructions
    1. Go to WebLogic Domain -> <Domain Name>
    2. Right click and open 'System MBean Browser'
    3. In the 'System MBean Browser' left panel, go to 'oracle.iam' -> Server:<server name> --> Application:oim --> XML Config --> Config --> XMLConfig.SSOConfig --> SSOConfig
    4. Set the SsoEnabled flag to 'true' and apply
    Which works, however it also prevents challenge questions being forced on a user, which we want.
    Does anyone know how to do this?
    Thanks!

    yes, system property doesn't work in this case. you can try the simple test case
    1. create a new user
    2. login to oim db and update usr set usr_change_pwd_at_next_logon=0 for newely created user. (default value is 1)
    3.commit the change in db
    4. close the browser or clear cache. sometime it pick the value from cache. better close the the browser and open it
    5. login with the new user it won't ask for the password change but it will force to set question.

  • How to disable auto_home and individual datasets on Solaris 11 11/11

    Good morning,
    There's a lot of changes in Solaris 11 that I like, but two of the ones I dislike, I just can't seem to get rid of them.
    I'd like to disable auto_home, permanently. I don't want users' home directories to be mapped on /home .
    I've read that all I needed was to remove all mentions of home in /etc/auto_home and/or /etc/auto_master (can't recall which one of the 2 files as I removed all mentions, 'f course...) .
    Once done, I read I simply needed to run automount once (automount -v) .
    No go. The next user I've created was mapped in /etc/auto_home, and /etc/password modified accordingly.
    Moreover, each new account is created as its own individual ZFS dataset. I understand the advantages of this, as each user can create his own snapshots, etc. But I don't need that, and I certainly won't need a zfs list output that scrolls on many pages !
    How can I disable this ? I just tested it, 2 seconds ago :
    [08:43:10|jfg@oslo:/opt] sudo useradd -u 9999 -c 'TEST' -d /export/home/TEST -m -s /bin/bash test
    80 blocks
    [08:45:59|jfg@oslo:/opt] grep TEST /etc/passwd ; grep TEST /etc/auto_* ; zfs list | grep TEST
    test:x:9999:10:TEST:/home/test:/bin/bash
    /etc/auto_home:test localhost:/export/home/TEST
    rpool/homes/oslo/test 35K 21.1G 35K /export/home/TEST
    <EDIT> : forgot to mention, I destroyed the original dataset for the home directories, rpool/export/home, and created a new one, rpool/homes/zoneName/ as multiple zones accounts will be "hosted" in this dataset.
    Thanks for helping,
    Regards,
    -- Jeff
    Edited by: user5989503 on Jan 10, 2012 8:54 AM

    Thanks Alan,
    I remember awhile back reading about this on OpenSolaris, but it just came back to mind as you mentioned it.
    Still, other than svcadm disable autofs, I can't see how to disable only auto_home.
    And I'm still stuck with my individual zfs datasets that I hate hoooo so much ! :-)
    Thanks,
    -- Jeff

  • How to disable "Password too short" reject/restrictions ?

    As I observed Solaris forces by default all users to enter a password with a minimum length of 6 chars.
    For a test-only system I would appreciate to select a shorter password.
    How can I disable all password (length) restrictions?
    Peter

    Hmm, thank you for the hint with /etc/default/passwd BUT:
    I changed PASSLENGTH=4
    and leave
    MAXWEEKS=
    MINWEEKS=
    ALL other lines were commented out with "#".
    Ok, now I rebooted, logged in and tried to change e.g. my own password to "ppss" with
    sudo passwd p
    but then I got another warning reject:
    "The password must contain at least 1 numeric or special character(s)"
    Why this? The file you suggested contains as only restriction a minimum length of 4 for the pw - no more other conditions.
    So why is there another rejection?
    Peter
    Edited by: user559463 on Dec 11, 2011 12:07 AM

Maybe you are looking for

  • IN APP

    Hi Gurus, in case app when print run i am getting an error saying "specify a lot for production run" i configured cheque lots correctly i don't know why i am getting this error, please help me out. This is urgent. sd/- Sreenivasulu.P

  • When trying to install jdk-1_5_0_13 on Solaris geting file is corrupt.

    I am trying to install jdk-1_5_0_13 on Solaris 10 using the following downloaded files from Sun Archive site jdk-1_5_0_13-solaris-sparc.sh and jdk-1_5_0_13-solaris-sparcv9.sh When tried to install using these self extracting files It gives error file

  • Installation of Nokia Cable Driver (USB) fails und...

    I am running Windows Vista Home Premium, SP2. I have installed Nokia PC Suite 7.1.30.8, and I want to connect a Nokia E65 via USB cable CA-53. The installation of the software works well except the installation of the cable driver. I do always get an

  • Service Master Integration from ECC

    Hi, We are on Extended Classic Scenario and we are wondering if we are able to use the Service Master which is replicated from the ECC and use it when creating a Service Type Shopping Cart? We managed to get the Service Master into SRM and visible in

  • How to make separate home for ASM

    Hi, I have 11gr1 RAC setup in vmware having the common oracle home for database and ASM. Now I want to create the separate home for ASM instead of having common home, can you please guide me the process of how to create the separate home and thus to