<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: cpsho_user config pushed from Check Point? in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/cpsho-user-config-pushed-from-Check-Point/m-p/187304#M31318</link>
    <description>&lt;P&gt;Thanks for the reply Val. I am wondering how this config got there without interaction. It came a bit out of the blue.&lt;/P&gt;&lt;P&gt;Indeed I see the user only on mgmt systems.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any idea how this config got pushed? And why does it need to run a task to monitor CPM?&lt;/P&gt;</description>
    <pubDate>Mon, 24 Jul 2023 08:46:09 GMT</pubDate>
    <dc:creator>Lesley</dc:creator>
    <dc:date>2023-07-24T08:46:09Z</dc:date>
    <item>
      <title>cpsho_user config pushed from Check Point?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/cpsho-user-config-pushed-from-Check-Point/m-p/187293#M31314</link>
      <description>&lt;P&gt;Hey everyone,&lt;/P&gt;&lt;P&gt;I noticed the following changes occurred the previous weekend. Some config changes got I assume pushed from Check Point.&lt;/P&gt;&lt;P&gt;I cannot find anything regarding this. I suspect there is a relation with HCP update from 19-7.&lt;/P&gt;&lt;P&gt;Anyone else has noticed this? Below the GAIA config, they are from 2 different customers.&amp;nbsp;&lt;/P&gt;&lt;P&gt;add cron job wsc_cpm_monitoring command "sh /opt/CPsuite-R81.10/fw1/webconsole/wsc_cpm_monitoring.sh" recurrence daily time *:*&lt;BR /&gt;add user cpsho_user uid 1000 homedir /home/cpsho_user&lt;BR /&gt;set user cpsho_user gid 100 shell /etc/cli.sh&lt;BR /&gt;set user cpsho_user realname "Cpsho_user"&lt;BR /&gt;set user cpsho_user password-hash &amp;lt;HASH&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;add cron job wsc_cpm_monitoring command "sh /opt/CPsuite-R81/fw1/webconsole/wsc_cpm_monitoring.sh" recurrence daily time *:*&lt;BR /&gt;add user cpsho_user uid 1000 homedir /home/cpsho_user&lt;BR /&gt;set user cpsho_user gid 100 shell /etc/cli.sh&lt;BR /&gt;set user cpsho_user realname "Cpsho_user"&lt;BR /&gt;set user cpsho_user password-hash &amp;lt;HASH&amp;gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2023 07:25:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/cpsho-user-config-pushed-from-Check-Point/m-p/187293#M31314</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2023-07-24T07:25:17Z</dc:date>
    </item>
    <item>
      <title>Re: cpsho_user config pushed from Check Point?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/cpsho-user-config-pushed-from-Check-Point/m-p/187298#M31316</link>
      <description>&lt;P&gt;This is a system user account related to the web console, and some other management features, with R81.10 and above. Should only appear on management servers.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2023 08:11:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/cpsho-user-config-pushed-from-Check-Point/m-p/187298#M31316</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-07-24T08:11:14Z</dc:date>
    </item>
    <item>
      <title>Re: cpsho_user config pushed from Check Point?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/cpsho-user-config-pushed-from-Check-Point/m-p/187304#M31318</link>
      <description>&lt;P&gt;Thanks for the reply Val. I am wondering how this config got there without interaction. It came a bit out of the blue.&lt;/P&gt;&lt;P&gt;Indeed I see the user only on mgmt systems.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any idea how this config got pushed? And why does it need to run a task to monitor CPM?&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2023 08:46:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/cpsho-user-config-pushed-from-Check-Point/m-p/187304#M31318</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2023-07-24T08:46:09Z</dc:date>
    </item>
    <item>
      <title>Re: cpsho_user config pushed from Check Point?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/cpsho-user-config-pushed-from-Check-Point/m-p/187314#M31322</link>
      <description>&lt;P&gt;Probably via autopudatercli as the last release of the Web Smart Console is dated from July 18th, and makes mention of the tool for offline updates. Interestingly, the web Smart Console is not listed in the components of the autoupdatercli SK.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2023 10:06:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/cpsho-user-config-pushed-from-Check-Point/m-p/187314#M31322</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2023-07-24T10:06:03Z</dc:date>
    </item>
    <item>
      <title>Re: cpsho_user config pushed from Check Point?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/cpsho-user-config-pushed-from-Check-Point/m-p/187328#M31327</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'd like to address several questions that have been raised in regars to cpsho_user.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What permissions and credentials cpsho_user has?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;The&lt;/EM&gt;&lt;EM&gt; password is&lt;/EM&gt;&amp;nbsp;&lt;EM&gt;randomly generated&lt;/EM&gt;&amp;nbsp;&lt;EM&gt;and it is 108 characters long&lt;/EM&gt;&lt;EM&gt;, it &lt;/EM&gt;&lt;EM&gt;is not stored anywhere, hence this user is never used to login.&amp;nbsp;&lt;/EM&gt;&lt;EM&gt;Gaia&lt;/EM&gt;&amp;nbsp;&lt;EM&gt;has the definition of the user&lt;/EM&gt;&lt;EM&gt;, it has &lt;/EM&gt;&lt;EM&gt;Non-root permission ( groupid 100 )&lt;/EM&gt;.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;When is cpsho_user created?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN&gt;Installation&lt;/SPAN&gt;&amp;nbsp;of WebSmartConsole package will trigger the creation of the user. WebSmartConsole can be installed manually, by automatic update, and as part of the JHF.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Why is cpsho_user created?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;cpsho_user is being created for internal&lt;/EM&gt; &lt;EM&gt;system purposes.&lt;/EM&gt;&amp;nbsp;&lt;EM&gt;Several dockers on the MGMT server are using this low privileged user in order to read input files and write to log files. &amp;nbsp;For example Infinity Services and WebSmartConsole.&lt;/EM&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Can cpsho_user&amp;nbsp;be deleted?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Deleting this user is not recommended and might have impact on several Management features -&amp;nbsp;Infinity Services, WebSmartConsole&amp;nbsp;and&amp;nbsp;SmartConsole&amp;nbsp;(as some views and pages are of SmartConsole are based on WebSmartConsole&amp;nbsp;as infrastructure)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;More information available at&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk181305" target="_self"&gt;sk181305&lt;/A&gt;&amp;nbsp;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best Regards,&lt;/P&gt;
&lt;P&gt;Itai&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jul 2023 10:50:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/cpsho-user-config-pushed-from-Check-Point/m-p/187328#M31327</guid>
      <dc:creator>Itai_Minuhin</dc:creator>
      <dc:date>2023-07-27T10:50:00Z</dc:date>
    </item>
    <item>
      <title>Re: cpsho_user config pushed from Check Point?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/cpsho-user-config-pushed-from-Check-Point/m-p/188291#M31571</link>
      <description>&lt;P&gt;I just discovered this new user on my management servers, to say I was surprised would be quite the understatement. Having an automated process that can randomly create new users on my management servers (no matter what permissions are set) is completely unacceptable and irresponsible on Check Point's part. We are heavily regulated and our management server configurations are audited.&amp;nbsp; We must have justification for each and every user account on our management servers, how am I to explain this to an auditor? Check Point decided, for no reason that is well documented, to create this user? What's to stop Check Point from creating a different user account with different permissions?&lt;/P&gt;
&lt;P&gt;We have automatic updates enabled on our management servers for IPS downloads, AppCtrl, etc. It would have been inconceivable to me that this would enable Check Point to create user accounts on my devices. I'm at a loss as to why Check Point would think this is acceptable.&lt;/P&gt;
&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2023 15:14:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/cpsho-user-config-pushed-from-Check-Point/m-p/188291#M31571</guid>
      <dc:creator>David_C1</dc:creator>
      <dc:date>2023-08-01T15:14:13Z</dc:date>
    </item>
    <item>
      <title>Re: cpsho_user config pushed from Check Point?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/cpsho-user-config-pushed-from-Check-Point/m-p/188462#M31591</link>
      <description>&lt;P&gt;I couldn't agree more.&lt;/P&gt;&lt;P&gt;We're in the same situation like Dave, and having such user and cron job pushed by an auto-update process is unacceptable. It is still not clear to me from which update it came in; I first thought it was from JHF109 which we recently deployed, but 1st) I am not seeing it on our "offline" managers and 2nd) users were created before JHF109 deployment, so it must be any of cpuse, IPS, ... online update services.&lt;/P&gt;&lt;P&gt;This situation literally means we have lost control over granting access to our devices as the vendor can (and does!) push in any user required.&lt;BR /&gt;The explanation in the SK about what this user exactly does is vague ("used for internal processes"); also it does not list the exact permissions and "files read". According the SK it has "Non-root permission (groupid 100)", but when checking existing users for audits reports with "show users" command, it will show "Access to Expert features" on the Privilege tab, same as "admin".&lt;/P&gt;&lt;P&gt;Additionally, the SK was published three days _after_ users were pushed to our servers by "admin", so to me it looks as if Check Point had to quickly explain themselves.&lt;/P&gt;&lt;P&gt;For the cron job, it produces error messages when it runs (we get notified about failures on cron jobs); is there any QA on this before pushing out?&lt;BR /&gt;/opt/CPsuite-R81.10/fw1/webconsole/mwc.sh: line 153: service: command not found&lt;BR /&gt;/opt/CPsuite-R81.10/fw1/webconsole/mwc.sh: line 155: service: command not found&lt;BR /&gt;tail: cannot open '/opt/CPsuite-R81.10/fw1/log/wsc_cpm_monitoring.elg' for reading: No such file or directory&lt;/P&gt;&lt;P&gt;I'm quoting for truth:&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/10229"&gt;@David_C1&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;[..]We have automatic updates enabled on our management servers for IPS downloads, AppCtrl, etc. It would have been inconceivable to me that this would enable Check Point to create user accounts on my devices. I'm at a loss as to why Check Point would think this is acceptable.&lt;/P&gt;&lt;P&gt;Dave&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;adding:&lt;BR /&gt;"and even more concerned they are even doing it".&lt;/P&gt;&lt;P&gt;I am really disappointed!&lt;/P&gt;&lt;P&gt;Mario&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2023 14:33:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/cpsho-user-config-pushed-from-Check-Point/m-p/188462#M31591</guid>
      <dc:creator>MStu</dc:creator>
      <dc:date>2023-08-02T14:33:30Z</dc:date>
    </item>
    <item>
      <title>Re: cpsho_user config pushed from Check Point?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/cpsho-user-config-pushed-from-Check-Point/m-p/188504#M31599</link>
      <description>&lt;P&gt;I am guessing there is much more to this story than Check Point is telling us. This happened for a reason and the explanation is vague for a reason.&lt;/P&gt;
&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2023 22:28:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/cpsho-user-config-pushed-from-Check-Point/m-p/188504#M31599</guid>
      <dc:creator>David_C1</dc:creator>
      <dc:date>2023-08-02T22:28:23Z</dc:date>
    </item>
    <item>
      <title>Re: cpsho_user config pushed from Check Point?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/cpsho-user-config-pushed-from-Check-Point/m-p/188585#M31615</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/15539"&gt;@Itai_Minuhin&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'd like to address several questions that have been raised in regars to cpsho_user.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;What permissions and credentials cpsho_user has?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;The&lt;/EM&gt;&lt;EM&gt; password is&lt;/EM&gt;&amp;nbsp;&lt;EM&gt;randomly generated&lt;/EM&gt;&amp;nbsp;&lt;EM&gt;and it is 108 characters long&lt;/EM&gt;&lt;EM&gt;, it &lt;/EM&gt;&lt;EM&gt;is not stored anywhere, hence this user is never used to login.&amp;nbsp;&lt;/EM&gt;&lt;EM&gt;Gaia&lt;/EM&gt;&amp;nbsp;&lt;EM&gt;has the definition of the user&lt;/EM&gt;&lt;EM&gt;, it has &lt;/EM&gt;&lt;EM&gt;Non-root permission ( groupid 100 )&lt;/EM&gt;.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Not exactly true - the password is obviously stored on the local management server. Can the password be changed without causing "impact on several Management features"?&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;When is cpsho_user created?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN&gt;Installation&lt;/SPAN&gt;&amp;nbsp;of WebSmartConsole package will trigger the creation of the user. WebSmartConsole can be installed manually, by automatic update, and as part of the JHF.&lt;/EM&gt;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;This account showed up on my management servers on a Sunday. WebSmartConsole was not manually installed on this day, nor was a JHF installed. What "automatic update" would trigger this?&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Why is cpsho_user created?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;cpsho_user is being created for internal&lt;/EM&gt; &lt;EM&gt;system purposes.&lt;/EM&gt;&amp;nbsp;&lt;EM&gt;Several dockers on the MGMT server are using this low privileged user in order to read input files and write to log files. &amp;nbsp;For example Infinity Services and WebSmartConsole.&lt;/EM&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;How were these "internal system purposes" handled prior to the creation of this account? Why suddenly the need for this new account to handle these processes which presumably were working before this account showed up?&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;STRONG&gt;Can cpsho_user&amp;nbsp;be deleted?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Deleting this user is not recommended and might have impact on several Management features -&amp;nbsp;Infinity Services, WebSmartConsole&amp;nbsp;and&amp;nbsp;SmartConsole&amp;nbsp;(as some views and pages are of SmartConsole are based on WebSmartConsole&amp;nbsp;as infrastructure)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Again, these features were working prior to this account showing up. Could you provide more details about this potential impact?&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;More information available at&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk181305" target="_self"&gt;sk181305&lt;/A&gt;&amp;nbsp;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best Regards,&lt;/P&gt;
&lt;P&gt;Itai&lt;/P&gt;
&lt;HR /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2023 14:51:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/cpsho-user-config-pushed-from-Check-Point/m-p/188585#M31615</guid>
      <dc:creator>David_C1</dc:creator>
      <dc:date>2023-08-03T14:51:12Z</dc:date>
    </item>
    <item>
      <title>Re: cpsho_user config pushed from Check Point?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/cpsho-user-config-pushed-from-Check-Point/m-p/189116#M31714</link>
      <description>&lt;P&gt;It appears that the only thing currently preventing a remote login (SSH/web UI) is the lack of an assigned role. If you change the password and try to login via SSH you get the following in /var/log/messages:&lt;/P&gt;&lt;P&gt;Aug 10 15:33:34 2023 fwmgr clish[23032]: User not logged in. He has no configured role.&lt;BR /&gt;Aug 10 15:33:34 2023 fwmgr clish[23032]: User cpsho_user logged out due to an error from CLI shell&lt;/P&gt;&lt;P&gt;Web UI gives "Permission denied"&lt;/P&gt;&lt;P&gt;If you assign an rba role it will happily log you in.&lt;/P&gt;&lt;P&gt;Either way, a vendor known static password (however long) deployed on a customer system without their consent is called a backdoor and is a security accident waiting to happen. Not what you expect from a security company.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Aug 2023 03:40:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/cpsho-user-config-pushed-from-Check-Point/m-p/189116#M31714</guid>
      <dc:creator>Paul_Hagyard</dc:creator>
      <dc:date>2023-08-10T03:40:54Z</dc:date>
    </item>
    <item>
      <title>Re: cpsho_user config pushed from Check Point?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/cpsho-user-config-pushed-from-Check-Point/m-p/189118#M31715</link>
      <description>&lt;P&gt;Re-reading this:&lt;/P&gt;&lt;P&gt;"&lt;EM&gt;The&lt;/EM&gt;&lt;EM&gt; password is&lt;/EM&gt;&amp;nbsp;&lt;EM&gt;randomly generated&lt;/EM&gt;&amp;nbsp;&lt;EM&gt;and it is 108 characters long&lt;/EM&gt;&lt;EM&gt;, it &lt;/EM&gt;&lt;EM&gt;is not stored anywhere, hence this user is never used to login.&lt;/EM&gt;"&lt;/P&gt;&lt;P&gt;Randomly generate per-install, or once by Check Point? If it is not stored &lt;EM&gt;anywhere&lt;/EM&gt; how can it be used, and why is a password needed at all?&lt;/P&gt;</description>
      <pubDate>Thu, 10 Aug 2023 04:30:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/cpsho-user-config-pushed-from-Check-Point/m-p/189118#M31715</guid>
      <dc:creator>Paul_Hagyard</dc:creator>
      <dc:date>2023-08-10T04:30:31Z</dc:date>
    </item>
    <item>
      <title>Re: cpsho_user config pushed from Check Point?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/cpsho-user-config-pushed-from-Check-Point/m-p/189119#M31716</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;The password is randomly generated per machine, it is very long and not kept after it is generated.&lt;BR /&gt;Therefore it is not a static password that anyone can use to log in.&lt;/P&gt;
&lt;P&gt;Essentially, we defined this user in a way that no one will be able to use it to log in, under any circumstances. The random password is generated simply because that is needed to create the user.&lt;BR /&gt;It was created as a security precaution since it has lower privileges and it allows us to run some processes without full system permissions.&lt;/P&gt;
&lt;P&gt;It retrospect, we understand that this was not clear to the field and we need to better communicate such underlying changes. We appreciate the feedback and will try to document this much better.&lt;/P&gt;
&lt;P&gt;I want to emphasize though, that this does not introduce security concerns, to the contrary, it was done to tighten security.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Aug 2023 06:01:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/cpsho-user-config-pushed-from-Check-Point/m-p/189119#M31716</guid>
      <dc:creator>Tomer_Noy</dc:creator>
      <dc:date>2023-08-10T06:01:16Z</dc:date>
    </item>
    <item>
      <title>Re: cpsho_user config pushed from Check Point?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/cpsho-user-config-pushed-from-Check-Point/m-p/189171#M31718</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/9372"&gt;@Tomer_Noy&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;The password is randomly generated per machine, it is very long and not kept after it is generated.&lt;BR /&gt;Therefore it is not a static password that anyone can use to log in.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;True, but if this is the case, why was the user created with Web and Clish Access enabled?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cpsho1.jpg" style="width: 435px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22028i015B7D6431BED6B2/image-dimensions/435x213?v=v2" width="435" height="213" role="button" title="cpsho1.jpg" alt="cpsho1.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;Essentially, we defined this user in a way that no one will be able to use it to log in, under any circumstances. The random password is generated simply because that is needed to create the user.&lt;BR /&gt;It was created as a security precaution since it has lower privileges and it allows us to run some processes without full system permissions.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Details, please. What was previously running with full system permissions that had to be fixed with a named user? UID 1000 already existed, why the need for a named user? What bug was found (and not disclosed)?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cpsho2.jpg" style="width: 727px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22029i223ACC656A15E547/image-size/large?v=v2&amp;amp;px=999" role="button" title="cpsho2.jpg" alt="cpsho2.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;It retrospect, we understand that this was not clear to the field and we need to better communicate such underlying changes. We appreciate the feedback and will try to document this much better.&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Umm...yeah. Would this had ever been brought to light if a few of us didn't notice this additional user?&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;I want to emphasize though, that this does not introduce security concerns, to the contrary, it was done to tighten security.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Again, details would help restore some trust.&lt;/P&gt;
&lt;P&gt;Also, an explanation between this discrepancy:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cpsho3.jpg" style="width: 693px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22030i744B19C7F3B88C57/image-dimensions/693x53?v=v2" width="693" height="53" role="button" title="cpsho3.jpg" alt="cpsho3.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cpsho4.jpg" style="width: 691px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22031iD699AB1DB9008B07/image-dimensions/691x219?v=v2" width="691" height="219" role="button" title="cpsho4.jpg" alt="cpsho4.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Dave&lt;/P&gt;
&lt;HR /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Aug 2023 13:03:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/cpsho-user-config-pushed-from-Check-Point/m-p/189171#M31718</guid>
      <dc:creator>David_C1</dc:creator>
      <dc:date>2023-08-10T13:03:17Z</dc:date>
    </item>
    <item>
      <title>Re: cpsho_user config pushed from Check Point?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/cpsho-user-config-pushed-from-Check-Point/m-p/197242#M33067</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have now seen 3 times at 3 different customers after upgrading from R81.10 to R81.20 we get Segmentation fault in clish when trying to back up, or after show configuration.&amp;nbsp;&lt;BR /&gt;After some debug I&lt;/SPAN&gt;&lt;SPAN class=""&gt;&amp;nbsp;pinpointed the problem. During the the upgrade process the user "Cpsho_user" is automatically created, but this user is created without a home dir:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;[Expert@s-manage03:0]# grep "passwd:cpsho_user" /config/active&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;passwd:cpsho_user t&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;passwd:cpsho_user:realname Cpsho_user&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;passwd:cpsho_user:gid 100&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;passwd:cpsho_user:uid 1000&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;passwd:cpsho_user:lastchg 1694536445&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;passwd:cpsho_user:shell /sbin/nologin&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;passwd:cpsho_user:passwd *&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;In one installation I exported the configuration, reinstalled on R81.20 and imported config and the Cpsho_user was gone, and everything worked&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;On the other I deleted Cpsho_user, and everything worked&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;And on the 3rd I added the homedir: set user cpsho_user homedir /home/cpsho_user&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;why is&amp;nbsp;&lt;SPAN class=""&gt;Cpsho_user not created on a fresh installed R81.20?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;/gsa&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Nov 2023 21:27:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/cpsho-user-config-pushed-from-Check-Point/m-p/197242#M33067</guid>
      <dc:creator>Georgios_Sagos</dc:creator>
      <dc:date>2023-11-06T21:27:00Z</dc:date>
    </item>
    <item>
      <title>Re: cpsho_user config pushed from Check Point?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/cpsho-user-config-pushed-from-Check-Point/m-p/199343#M33289</link>
      <description>&lt;P&gt;Anyone else that hits this thread:&lt;/P&gt;&lt;P&gt;In our instance:&lt;/P&gt;&lt;P&gt;Message logs filled with:&lt;BR /&gt;kernel:clish[xxxxx]: segfault at 0 ip 00000000f5078a5f sp 00000000ffeeb3b0 error 4 in libcli_passwd.so&lt;/P&gt;&lt;P&gt;cpsho_user was missing both homedir &amp;amp; realname&lt;/P&gt;&lt;P&gt;Gaia administrator "cpsho_user" is added on Management Servers&lt;BR /&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk181305" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk181305&lt;/A&gt;&lt;/P&gt;&lt;P&gt;"show configuration user" command fails with "Segmentation fault" on the Security Management Server&lt;BR /&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk181626" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk181626&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2023 11:41:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/cpsho-user-config-pushed-from-Check-Point/m-p/199343#M33289</guid>
      <dc:creator>StackCap43382</dc:creator>
      <dc:date>2023-11-30T11:41:28Z</dc:date>
    </item>
    <item>
      <title>Re: cpsho_user config pushed from Check Point?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/cpsho-user-config-pushed-from-Check-Point/m-p/204424#M33929</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/33562"&gt;@StackCap43382&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Anyone else that hits this thread:&lt;/P&gt;&lt;P&gt;In our instance:&lt;/P&gt;&lt;P&gt;Message logs filled with:&lt;BR /&gt;kernel:clish[xxxxx]: segfault at 0 ip 00000000f5078a5f sp 00000000ffeeb3b0 error 4 in libcli_passwd.so&lt;/P&gt;&lt;P&gt;cpsho_user was missing both homedir &amp;amp; realname&lt;/P&gt;&lt;P&gt;Gaia administrator "cpsho_user" is added on Management Servers&lt;BR /&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk181305" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk181305&lt;/A&gt;&lt;/P&gt;&lt;P&gt;"show configuration user" command fails with "Segmentation fault" on the Security Management Server&lt;BR /&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk181626" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk181626&lt;/A&gt;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Yes, we had the same issue exactly. It appeared on R81.10 after installing JHF130 over JHF95.&amp;nbsp; Adding home directory helped.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2024 12:44:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/cpsho-user-config-pushed-from-Check-Point/m-p/204424#M33929</guid>
      <dc:creator>AlekzNet</dc:creator>
      <dc:date>2024-01-29T12:44:48Z</dc:date>
    </item>
    <item>
      <title>Re: cpsho_user config pushed from Check Point?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/cpsho-user-config-pushed-from-Check-Point/m-p/241101#M40229</link>
      <description>&lt;P&gt;Upgraded to R82 JHFA10.&lt;/P&gt;&lt;P&gt;HealthCheck Point (HCP) now send WARNING!&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Test name                                         Status    Runtime (sec)
==========================================================================
Users in Gaia Database............................[WARNING] 0.00108


+------------------------------------------------------------------------------------------------------------------------------------+
|                                                              Results                                                               |
+====================================================================================================================================+
|                                               Gaia OS/General/Users in Gaia Database                                               |
+------------------------------------------------------------------------------------------------------------------------------------+
| Result: WARNING                                                                                                                    |
|                                                                                                                                    |
| Description: This test checks if all users in the Gaia Database have the required settings (bindings)                              |
|                                                                                                                                    |
| Summary:1 user is missing the required bindings:                                                                                   |
| User 'cpsho_user' is missing these required bindings: homedir                                                                      |
|                                                                                                                                    |
| Finding:                                                                                                                           |
| User 'cpsho_user' is missing these required bindings: homedir                                                                      |
|                                                                                                                                    |
| Finding:                                                                                                                           |
| Suggested steps in Gaia Clish for each user with missing bindings:                                                                 |
| (1) Delete the problematic user:                                                                                                   |
|     delete user &amp;lt;Username&amp;gt;                                                                                                         |
| (2) Save the changes in the Gaia Database:                                                                                         |
|     save config                                                                                                                    |
| (3) Create the required user:                                                                                                      |
|     add user &amp;lt;Username&amp;gt; uid &amp;lt;UID&amp;gt; homedir &amp;lt;Path&amp;gt;                                                                                   |
| (4) Configure the new user:                                                                                                        |
|     set user &amp;lt;Username&amp;gt; &amp;lt;Parameters&amp;gt;                                                                                               |
| (5) Save the changes in the Gaia Database:                                                                                         |
|     save config&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We prefer it should not trigger security WARNING in included health check system to suggest to remove or recreate the user.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;How should the homedir issue be fixed? Do I need to create it or will it be fixed in coming JHFA or in the HCP check?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;/Johan&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2025 09:24:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/cpsho-user-config-pushed-from-Check-Point/m-p/241101#M40229</guid>
      <dc:creator>Johan_T</dc:creator>
      <dc:date>2025-02-13T09:24:21Z</dc:date>
    </item>
    <item>
      <title>Re: cpsho_user config pushed from Check Point?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/cpsho-user-config-pushed-from-Check-Point/m-p/241147#M40237</link>
      <description>&lt;P&gt;Correct homedir =&amp;nbsp;&lt;SPAN&gt;add user cpsho_user uid 1000 homedir &lt;STRONG&gt;/home/cpsho_user&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;I would try this to see if the error is then gone.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2025 17:32:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/cpsho-user-config-pushed-from-Check-Point/m-p/241147#M40237</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-02-13T17:32:38Z</dc:date>
    </item>
    <item>
      <title>Re: cpsho_user config pushed from Check Point?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/cpsho-user-config-pushed-from-Check-Point/m-p/244819#M40842</link>
      <description>&lt;P&gt;Hi, It look like you want to add cpsho_user homedir with normal clish configuration, that does not look correct for me since I do not have anything else in clish for the cpsho_user. Different compared to some other user earlier in this thread that look like they do have it in clish.&amp;nbsp; I will add it directly in the db to update passwd file instead.&lt;/P&gt;&lt;P&gt;That look like this if anyone else want to do the same and also do not see the cpsho_user when running in clish &lt;STRONG&gt;show configuration&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;dbset passwd:cpsho_user:homedir /home/cpsho_user&lt;BR /&gt;dbset :save&lt;/PRE&gt;&lt;P&gt;/Johan&lt;/P&gt;</description>
      <pubDate>Wed, 26 Mar 2025 12:44:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/cpsho-user-config-pushed-from-Check-Point/m-p/244819#M40842</guid>
      <dc:creator>Johan_T</dc:creator>
      <dc:date>2025-03-26T12:44:21Z</dc:date>
    </item>
  </channel>
</rss>

