Re: root group in solaris

sudo -s opens a root level shell that can be used to issue multiple
commands. If running in a gui, the admin could even have more than one
shell open and use the root and non-root shells simultaneously for
appropriate commands. That's pretty simple and requires knowledge of only
the user's own password. The only command logged is the command to spawn
the shell, not the commands issued in that shell, unlike the audit trail
that could be kept if commands were issued separately prefixed with sudo.

sudo without the -s option issues a new password challenge when the last
challenge is five minutes old to prevent someone from using a root shell
when an admin steps away without locking his account....not a bad idea.
Can you set the inactivity time limit for sudo?

Sent by: To
listbounce@securi dubaisans dubai <dubaisans@xxxxxxxxx>
09/18/2006 02:07 Subject
PM Re: root group in solaris

I would like to give root user privileges to a set of OS
administrators. Everyone has individual user-ids on the system.
Currently they login with their personal ID and then SU to root. I
donot want to share root password with these many people.

I am thinking of adding all these users to the "root" group[GID 0].
Will it provide root-equivalent UID O access to these users. If not
why ? Does the "root" group not have root user-id equivalent

Is it possible manually to make the GID 0 privileges equivalant of UID O?

No; you could have easily tested this but it has no effect at all.

How else can I give these individual users root privileges - make all
of them UID 0 or something.? Is that a smart idea?

I am looking at something simpler than SUDO or RBAC

Even simpler?

I would still strongly suggest RBAC or sudo as both all your system
administrators to execute programs with appropriate privileges when
needed. Giving them "root privileges all the time" is a bad idea;
it means that they can no longer safely use their user accounts
for email, web browsing or anything else.


