HDS ViewStation System Administrator's Guide

A Hypertext Document


ViewStation Security with the Remote Shell Command

This page describes security with the Remote Shell command used with the ViewStation.

Permission for Remote Shell Commands
The process of starting the local window manager from a remote host uses the Remote Shell command, usually rsh (or rcmd on SCO hosts or remsh on HP hosts). This process establishes identifications, environments, and privileges for the ViewStation to use the remote host's permissions to start other remote processes on other network devices. These permissions are governed on the host by the hosts.equiv and .rhosts files, discussed below.

With these things in place, the ViewStation is a trusted machine, that is, if a remote shell command comes from a particular host to the ViewStation, it will permit remote shell processes only back to that host or hosts specified in that host's permission files. The initial user logon from the ViewStation to the host sets the username, password, environment, and permissions. These permissions are extended to the ViewStation by the remote shell process, and any further extension of those privileges is governed by the hosts.equiv file. In this way system security is preserved at the same level for the ViewStation as an X terminal and any host or workstation on the network. The ViewStation is no more vulnerable (or any less vulnerable) than any other device on the network.

Using the /etc/hosts.equiv File
The most common security permission is set in the /etc/hosts.equiv file, which is a simple list of hostnames which have permissions equivalent to the host. Generally, you must add the ViewStation's hostname to this file on the remote host you will be using.

Syntax for this hosts.equiv file varies with different operating systems. Adding names to this file is not done automatically (some operating systems, like Sun OS, do permit the addition of a plus sign "+" to this file, which indicates permission for automatic addition of host names), but in general, you must explicitly add the ViewStation's name to this file. The following examples are suggestive of the contents of this file. Check your own man pages for correct syntax on your system.

# hosts.equiv syntax examples
#
# host1 userA this allows userA access to host1
# + host1 this allows all users access to host1
# host1 -userA this denies userA access to host1
# - host1 this denies all users access to host1
# -@groupA this denies groupA users access to hosts
# +@groupA +@groupB this allows groupB users access to groupA hosts


Using the .rhosts File
Another location that may have permissions set, or prohibited, is the .rhosts file in the user's home directory. This file allows the user to specify permissions and equivalency of his user name for other hosts. You may also have to modify this file. The syntax for this file is similar to the hosts.equiv file, but varies with different operating systems.

ViewStation's local .rhosts File
With HDSware version 3.2, the ViewStation has a local .rhosts file which offers additional security for the ViewStation.

ViewStation Remote Access Reporting
The ViewStation reports each host and user access attempting to connect to it with messages in its Console Window.

Some sample messages are:
rshd_io: accepted rsh by gregh@hdssun1.hds.com
rshd_io: accepted rlogin by gregh@hdssun1.hds.com
rshd_io: rejected rsh by gregh@hdssun5.hds.com
rshd_io: rejected rlogin by gregh@hdssun5.hds.com


These messages allow you to monitor any activity trying to access the ViewStation.

Return to Section Heading Page


Return to the Home Page

If you need more information than is available here, you can reach HDS via email at info@hds.com, or call us at 1.800.HDS.1551 in the USA, or at +610.277.8300 from outside the US. For questions or problems regarding the HDS WWW page, contact webmaster@hds.com.
© 1996 by HDS Network Systems Inc.