Re: nis : how to avoid user1 becoming user2 using local root ?

From: Frederic Medery (dist-list_at_LEXUM.UMontreal.CA)
Date: 03/30/04


Date: Tue, 30 Mar 2004 09:00:12 -0500
To: Mailing List Linux- Security <focus-linux@securityfocus.com>

first thanks for all you great imput !!!

How can ldap help me ? We want to migrate from nis to ldap /kerberos
this year.

Thanks again !
F

Deep Thought wrote:

> Hello,
>
>Le Fri, Mar 26, 2004 at 04:58:06PM -0500, Frédéric Médery dixit:
>FM> our situation :
>FM> All linux servers, all nfs share use the root_squash option.
>FM> We're using NIS
>FM> All developpers can become root on their local machines.
>FM> The prob : if user1 do a `su -` on their station. And then, `su user2`
>FM> they can become user2.
>FM> For me it's a huge problem (windows don't have this prob, local admin
>FM> are very different from domain/server admin) is there a way to avoid
>FM> this prob ?
>
> Yes : use LDAP
>
>FM> Thanks !
>
> You're welcome
>
>
>



Relevant Pages

  • Re: Directory Server LDAP/LDIF import - working yet not working???
    ... I then generated LDIF files from the /etc files on our NIS ... > 10,000-foot understanding of LDAP. ... > I already downloaded the various LDAP BluePrints and Directory Server ...
    (comp.unix.solaris)
  • Directory Server LDAP/LDIF import - working yet not working???
    ... We currently have NIS and are looking to get rid of NIS completely in ... I then generated LDIF files from the /etc files on our NIS ... 10,000-foot understanding of LDAP. ... This is to be nothing more than importing /etc/passwd (and ...
    (comp.unix.solaris)
  • Re: Solaris 9 naming services
    ... Just my own experience with the Solaris implementations of NIS, ... and the Iplanet/SunONE LDAP server. ... it's hard to know what the folks at the conference ...
    (comp.unix.solaris)
  • Re: Solaris 9 naming services
    ... Just my own experience with the Solaris implementations of NIS, ... and the Iplanet/SunONE LDAP server. ... it's hard to know what the folks at the conference ...
    (comp.sys.sun.admin)
  • Summary: NIS+ and LDAP - Single sign on
    ... The overwhelming response was that NIS+ is proprietary and that Sun will not ... The majority of the responses indicate that LDAP is the way to go. ... I mainly need this for authentication (login ... Everybody is going LDAP these days: Sun, ...
    (SunManagers)