Re: Application Admins with Local Admin on Servers



On 2007-07-09 Megan Kielman wrote:
I am trying to get a feel for what other companies do with regard to
application developers needing local admin privileges on servers. I am
specifically working in a Windows environment but believe that the
same principles would apply in any environment. Here are my questions:

Do you grant admin privileges to application developers?

On production servers? No.

Developer workstations are located in a separate network segment, and
each developer has admin privileges on his own workstation. I addition
to that there are servers for testing purposes in the developers'
network segment. Developers have admin privileges on these servers, too.
The transition developer server -> production server is done by system
administrators, with the assistence of the respective developer(s)
whenever needed.

If not, do you grant them specific access or do you take care of the
work for them?

No.

I do understand that it is a violation of separation of duties to
allow application developers to have local admin or root on systems, I
am simply try to get an idea of what the rest of the community does in
practice.

Properly separate the duties.

Regards
Ansgar Wiechers
--
"All vulnerabilities deserve a public fear period prior to patches
becoming available."
--Jason Coombs on Bugtraq



Relevant Pages

  • Re: VS 2005 questions
    ... can't use VS 2005 for a few years, but at least our developers can prepare ... because the applications must be hosted on military servers over which we ... Microsoft software is among the most mission-critical for them, ... because then developers could adopt VS 2005 more quickly. ...
    (microsoft.public.vsnet.general)
  • Re: warnings or -w ?
    ... my own stations are one under Windows and the second under ... developer send his work to all other developers for final check and (it ... And the Linux servers on which problem ... that in these Komodo settings, he (surely not volontarily because it has ...
    (comp.lang.perl.misc)
  • Re: Quality of FreeBSD
    ... >> I know the developers don't hear it often enough, ... Mainly NFS and Samba servers, ... Some special kind words go to Soren Schmidt here. ...
    (freebsd-stable)
  • Re: Windows 2000 - Read only access for developers.
    ... In the internal domain developers can already see the Event Viewer and COM+ ... need to see would typically have access denied from say the guest account. ... servers in order to effect this. ...
    (microsoft.public.win2000.general)
  • Re: P4 Xeon compatibility with 5.0.5
    ... How come it's so far behind Linux then, ... AND hardware support and SCO ... >the middle of the sweet spot of most developers interest. ... organiser, through 486 based robots, phones, up to 16 way servers (I ...
    (comp.unix.sco.misc)