This page describes security with the
Remote Shell command used with the ViewStation.
Permission
for Remote Shell Commands
The process of starting the local window manager from a remote host
uses the Remote Shell command, usually rsh (or rcmd on
SCO hosts or remsh on HP hosts). This process establishes
identifications, environments, and privileges for the ViewStation to use
the remote host's permissions to start other remote processes on other
network devices. These permissions are governed on the host by the hosts.equiv
and .rhosts files, discussed below.
With these things in place, the ViewStation is a trusted
machine, that is, if a remote shell command comes from a particular
host to the ViewStation, it will permit remote shell processes only
back to that host or hosts specified in that host's permission files.
The initial user logon from the ViewStation to the host sets the
username, password, environment, and permissions. These permissions are
extended to the ViewStation by the remote shell process, and any
further extension of those privileges is governed by the hosts.equiv
file. In this way system security is preserved at the same level for the
ViewStation as an X terminal and any host or workstation on the
network. The ViewStation is no more vulnerable (or any less vulnerable)
than any other device on the network.
Using the
/etc/hosts.equiv File
The most common security permission is set in the /etc/hosts.equiv
file, which is a simple list of hostnames which have permissions
equivalent to the host. Generally, you must add the ViewStation's
hostname to this file on the remote host you will be using.
Syntax for this hosts.equiv file varies with different
operating systems. Adding names to this file is not done automatically
(some operating systems, like Sun OS, do permit the addition of a plus
sign "+" to this file, which indicates permission for automatic
addition of host names), but in general, you must explicitly add the
ViewStation's name to this file. The following examples are suggestive
of the contents of this file. Check your own man pages for correct
syntax on your system. # hosts.equiv syntax examples
#
# host1 userA this allows userA access to host1
# + host1 this allows all users access to host1
#
host1 -userA this denies userA access to host1
# - host1 this denies all users access to host1
#
-@groupA this denies groupA users access to hosts
# +@groupA +@groupB this allows groupB users access to
groupA hosts
Using the .rhosts File
Another location that may have permissions set, or prohibited, is
the .rhosts file in the user's home directory. This file allows the
user to specify permissions and equivalency of his user name for other
hosts. You may also have to modify this file. The syntax for this file
is similar to the hosts.equiv file, but varies with different operating
systems.
ViewStation's local .rhosts
File
With HDSware version 3.2, the ViewStation has a local
.rhosts file which offers additional security for the ViewStation.
ViewStation Remote Access Reporting
The ViewStation reports
each host and user access attempting to connect to it with messages in
its Console Window.
Some sample messages are: rshd_io:
accepted rsh by gregh@hdssun1.hds.com
rshd_io: accepted rlogin by
gregh@hdssun1.hds.com
rshd_io: rejected rsh by
gregh@hdssun5.hds.com
rshd_io: rejected rlogin by
gregh@hdssun5.hds.com
These messages allow you to
monitor any activity trying to access the ViewStation.
Return to Section Heading Page
Return to the Home Page
If you need more information than is available here, you can reach
HDS via email at info@hds.com, or
call us at 1.800.HDS.1551 in the USA, or at +610.277.8300 from outside
the US. For questions or problems regarding the HDS WWW page, contact
webmaster@hds.com.
© 1996 by HDS Network Systems
Inc.