Hello,

We have a security concern with the fact that when a zLinux user logs on from 
the zVM Guest Console, the password is made available to anyone watching over 
the person's shoulder as they type it in  and is recorded in the spooled 
console log.

For example: 
-------------------------------------------------------
Red Hat Enterprise Linux AS release 4 (Nahant Update 1)  
Kernel 2.6.9-11.EL on an s390x  
  
lnxmsp12 login: root
root  
Password: <!!!the password is shown in the clear!!!>    <--- PROBLEM
  
Last login: Mon Sep 25 10:32:55 from blah blah blah...
You have mail.  
[EMAIL PROTECTED] ~ยจ# 
-------------------------------------------------------

Is there a way to let zVM know that this is a password field similar to when 
you are logging on to zVM or using the VM-FTP Client?

Thanks,
Kevin Morris
LexisNexis, a division of Reed Elsevier Inc.

----------------------------------------------------------------------
For LINUX-390 subscribe / signoff / archive access instructions,
send email to [EMAIL PROTECTED] with the message: INFO LINUX-390 or visit
http://www.marist.edu/htbin/wlvindex?LINUX-390

Reply via email to