Re: Thanks to all (was Re: Solaris, Sudo, and locking...)

From: Vladimir Ivanov (VIvanov@tee.toshiba.de)
Date: 10/02/01


Message-ID: <3BB987FF.76A40037@tee.toshiba.de>
Date: Tue, 02 Oct 2001 11:25:19 +0200
From: Vladimir Ivanov <VIvanov@tee.toshiba.de>
To: focus-sun@securityfocus.com
Subject: Re: Thanks to all (was Re: Solaris, Sudo, and locking...)


> P.S. I think there are VERY few situations where an "su root" or even
> "sudo su root" should be needed ... so hopefully one can convince the
> admin staff that using sudo is a "good" idea ... and then the root
> password can be shared with a small group that understands that and
> used for those VERY few situations where it is truly needed.

BTW, is sudo compatible to Solaris RBAC?
so, is it possible to use user "native" password to login to
different "roles" ?

-- 
Vladimir Ivanov                      
System Administrator                 E-Mail:  VIvanov@tee.toshiba.de
Toshiba Electronics Europe GmbH      Tel/Fax: +49-211-5296-297/386



Relevant Pages

  • Re: history
    ... very easy to setup but Solaris has a much more powerfull utility called RBAC ... one reason I recommened avoid 3rd party tools is because 1) sudo is setuid ... >> I work on Solaris and on theses hosts everybody is root. ...
    (comp.unix.admin)
  • Re: Card Reader
    ... Running your script ... instead of sudo is worthless because your script *can't do ... And of course it doesn't ask for a root password, ... >> That's just more bullshit Bryan, and you might as well leave ...
    (rec.photo.digital)
  • Re: hi all..
    ... And with sudo, I certainly wouldn't because they already have root. ... If you somehow had access to my account right now, ... install an effective key logger without root. ...
    (Fedora)
  • Re: hi all..
    ... compromise security to achieve it - such as very insecure sudo defaults ... that essentially make any admin group user password a root password. ... IE someone gets your user account password, they can do more than just ...
    (Fedora)
  • Re: Choosing a distribution
    ... 'sudo bash' where I haven't had a proper root account to work with. ... cracked and hence give the intruder root access. ...
    (Ubuntu)