<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Word 12 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
{font-family:Tahoma;
panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
margin-bottom:.0001pt;
font-size:12.0pt;
font-family:"Times New Roman","serif";}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:blue;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{mso-style-priority:99;
color:purple;
text-decoration:underline;}
span.EmailStyle17
{mso-style-type:personal-reply;
font-family:"Calibri","sans-serif";
color:#1F497D;}
.MsoChpDefault
{mso-style-type:export-only;}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="blue" vlink="purple">
<div class="WordSection1">
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D">Create a dummy MOS account. All you need is an email address. So if you are a CSI admin, create a new account with an email address that goes to you. Approve
it, then add it to all of the proper CSI(s) for the support you need. Once you have done that, use that account. That is what I do here.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"> --Dave<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D"><o:p> </o:p></span></p>
<div style="border:none;border-left:solid blue 1.5pt;padding:0in 0in 0in 4.0pt">
<div>
<div style="border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif"">From:</span></b><span style="font-size:10.0pt;font-family:"Tahoma","sans-serif""> pca-bounces@lists.univie.ac.at [mailto:pca-bounces@lists.univie.ac.at]
<b>On Behalf Of </b>Fred<br>
<b>Sent:</b> Monday, May 09, 2011 9:48 AM<br>
<b>To:</b> PCA (Patch Check Advanced) Discussion<br>
<b>Subject:</b> [pca] Account security settings<o:p></o:p></span></p>
</div>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">I'm looking at setting up a pca proxy. On the client side, I have the config file referencing the webserver CGI for patches, xref file and pcafile. It's all working great.
<br>
<br>
On the server side, my pca-proxy.conf specifies where patches are cached, as well as a wgetproxy necessary for external access, and for now, it's using my MOS account. But this needs to change. My concern is regarding the MOS username and password, and where
to specify it. The patching process will be used by many sysadmins, all of whom have their own MOS accounts (all licensed under the corporate CSI).
<br>
<br>
Ideally, I would like the sysadmin running the pca client to use the -a argument so that he/she is prompted for the MOS credentials interactively, but doing this doesn't seem to send the credentials to the proxy server. Rather, the client tries the proxy and
it returns a 401 unauthorized error. The client then proceeds to authenticate directly against
<a href="http://getupdates.oracle.com">getupdates.oracle.com</a>. In my environment, hosts don't have access to the big band Internet, so these attempts will fail.
<br>
<br>
So I'm resigned to think that I must have an MOS account user and passwd configured within the /etc/pca-proxy.conf file on the server side. All out admins have access to the servers. so the problem here is I don't think I'll get someone to volunteer to have
their MOS account's password written in cleartext on the proxy host's filesystem.
<br>
<br>
What other options do I have?<br clear="all">
<br>
-- <br>
Fred Chagnon<br>
<a href="mailto:fchagnon@gmail.com">fchagnon@gmail.com</a><o:p></o:p></p>
</div>
</div>
</body>
</html>