Re: root group in solaris




Hi,

I absolutely agree that RBAC is the BEST option
all you have to do is to change type of user for
root from normal to a role (/etc/use_attr).
Then `usermod -R root username`.
cheers


--- Valerie Anne Bubb <Valerie.Bubb@xxxxxxx> wrote:

On Mon, 18 Sep 2006, dubaisans dubai wrote:

Hi,

I would like to give root user privileges to a set of
OS
administrators. Everyone has individual user-ids on the
system.
Currently they login with their personal ID and then SU
to root. I
donot want to share root password with these many
people.

I am thinking of adding all these users to the "root"
group[GID 0].
Will it provide root-equivalent UID O access to these
users. If not
why ? Does the "root" group not have root user-id
equivalent
privileges?

Is it possible manually to make the GID 0 privileges
equivalant of UID O?

How else can I give these individual users root
privileges - make all
of them UID 0 or something.? Is that a smart idea?

I am looking at something simpler than SUDO or RBAC

Hi there -

What is the issue you are having with RBAC? It is
included
by default in Solaris, many things like SSH are RBAC
aware,
it is logged & audited.

If you're running solaris 10 or newer, you can also use
least priveleges to limit what each operator can do.

Valerie
--
Now appearing as Gloria Rasputin and various other
characters in
"Bye Bye Birdie" at SDG
http://www.saratogadramagroup.com/
Sept 23 - Oct 14. Tickets: (408) 266-4734



Noel Z. Del Rosario


__________________________________________________
Do You Yahoo!?
Tired of spam? Yahoo! Mail has the best spam protection around
http://mail.yahoo.com



Relevant Pages

  • Re: how to change roots shell
    ... Im going to see if I can walk a user at the site through single user mode. ... su to root or even login as root. ... Do You Yahoo!? ... Mail has the best spam protection around ...
    (freebsd-questions)
  • Re: arts/ALSA problem after unstable upgrade (solved)
    ... ...as root; ... Do You Yahoo!? ... Mail has the best spam protection around ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)
  • Re: Runlevel3 services
    ... when i su to root... ... press serv and tab and all i get is servertool and ... Do You Yahoo!? ... Mail has the best spam protection around ...
    (Fedora)
  • Re: Newbie cannot start graphical desktop
    ... > You are trying to use X programs as root? ... with Knoppix and my monitor now perfectly configured. ... Do You Yahoo!? ... Mail has the best spam protection around ...
    (Debian-User)
  • Re: Stopping a Service with cgi
    ... Your script will run with full root privileges. ... Some systems don't support secure set-id scripts, ... Do You Yahoo!? ... Mail has the best spam protection around ...
    (perl.beginners)