<?xml version="1.0" encoding="utf-8"?><!DOCTYPE article  PUBLIC '-//OASIS//DTD DocBook XML V4.4//EN'  'http://www.docbook.org/xml/4.4/docbookx.dtd'><article><articleinfo><title>AdminUserSetup</title><revhistory><revision><revnumber>4</revnumber><date>2012-09-06 07:12:15</date><authorinitials>ClintonEbadi</authorinitials><revremark>pointlessly split content alert</revremark></revision><revision><revnumber>3</revnumber><date>2009-08-19 13:57:01</date><authorinitials>78.134.196.178-dsl.net.metronet.hr</authorinitials></revision><revision><revnumber>2</revnumber><date>2009-08-19 13:28:44</date><authorinitials>78.134.196.178-dsl.net.metronet.hr</authorinitials></revision><revision><revnumber>1</revnumber><date>2009-08-13 21:22:42</date><authorinitials>78.134.195.65-dsl.net.metronet.hr</authorinitials></revision></revhistory></articleinfo><tip><para>Merge with <ulink url="https://wiki.hcoop.net/AdminUserSetup/AddingNewAdmins#">AddingNewAdmins</ulink> </para></tip><section><title>Adding admin users</title></section><section><title>Disabling admin users</title><orderedlist numeration="arabic"><listitem><para>Disable local password on all hosts (sudo usermod -L USER_admin) </para></listitem><listitem><para>Disable local homedir on all hosts (sudo chmod 000 /home/USER_admin) </para></listitem><listitem><para>Remove from /etc/login.restrict on all hosts (that file is present on non-member-login machines) </para></listitem><listitem><para>Remove from /etc/sudoers on all hosts (sudo visudo) </para></listitem><listitem><para>Randomize Kerberos password ON ALL KRB SERVERS (kadmin.local -p YOU_admin -q &quot;cpw -randkey USER_admin&quot;) </para></listitem><listitem><para>Randomize user.daemon Kerberos password ON ALL KRB SERVERS (kadmin.local -p YOU_admin -q &quot;cpw -randkey USER_admin/daemon&quot;) </para></listitem><listitem><para>Remove all permissions on USER_admin homedir in AFS (fs sa /afs/hcoop.net/user/U/US/USER_ADMIN -clear) </para></listitem><listitem><para>Remove from BOS superuser list ON ALL AFS SERVERS (bos removeuser SERVER USER_admin) </para></listitem></orderedlist></section><section><title>Changing system passwords</title><orderedlist numeration="arabic"><listitem><para>On all hosts: sudo usermod -p '$1$...md5hash' root </para></listitem><listitem><para>ssh root@ or <ulink url="mailto:admin@kvm.hcoop.net">admin@kvm.hcoop.net</ulink>, run 'setup', choose S, type in new password twice, choose W. (KVM will reboot to reload pw) </para></listitem><listitem><para>ssh <ulink url="mailto:admin@mire-sp.hcoop.net">admin@mire-sp.hcoop.net</ulink>, run 'access update password -u admin', and also 'access get users' to make sure there are no accounts besides 'admin' </para></listitem></orderedlist><!--rule (<hr>) is not applicable to DocBook--><para> <ulink url="https://wiki.hcoop.net/AdminUserSetup/CategorySystemAdministration#">CategorySystemAdministration</ulink> <ulink url="https://wiki.hcoop.net/AdminUserSetup/CategoryNeedsWork#">CategoryNeedsWork</ulink> </para></section></article>