Re: Prevent remote root logins



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

boomboom999@xxxxxxxxx wrote:
I am still not convinced.

Why 3 users with an SU privilege (running shell as root) would be
better than 3 "root-equivalent" users (UID=0)?

It wouldn't. And no one said it would.

Don't use su(1) in a case like this. Instead, use sudo(8)

With sudo(8), the /real/ root user can limit which root priviledges each
user gets, by limiting the commands that /that/ user can perform using
sudo. With su(1) or your "root equivalent" (actually, multiple root)
users, there are no such controls.

In the both cases, I need trust these people.
In the both cases, if I have a malicious or demotivated admin, my
chances to survive are small ;)

Yes, so don't use those facilities.

Instead, use sudo(8) or one of the other facilities that gives you audit
and control over which root abilities these alternate administrators can
use.


- --

Lew Pitcher, IT Specialist, Corporate Technology Solutions,
Enterprise Technology Solutions, TD Bank Financial Group

(Opinions expressed here are my own, not my employer's)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2.2 (MingW32)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFEOpGwagVFX4UWr64RAsQIAKCQnY7CX1eRJmqvqXuV1UOJikVtPACdHpl4
e3p16vJaO0gLsALwfV77C2s=
=nztS
-----END PGP SIGNATURE-----
.



Relevant Pages

  • Re: Registry Cleanup
    ... any admin account has sufficient privilege. ... The problem is, since most users choose to run as admin rather than as a standard user, this privilege is often the subject of exploits. ... Any action that requires "root" privilege must be acknowledged, thus preventing undesirable actions without user intervention. ... "evenicoulddoit" wrote in message ...
    (microsoft.public.windows.vista.performance_maintenance)
  • Re: [patch] unprivileged mlock(2)
    ... only root may call mlock, and root may raise any limits. ... enable the privilege for non-privileged users. ... least by sysctl's kernel side). ... The temporary wirings performed as an ...
    (FreeBSD-Security)
  • Re: [patch] unprivileged mlock(2)
    ... only root may call mlock, and root may raise any limits. ... enable the privilege for non-privileged users. ... least by sysctl's kernel side). ... The temporary wirings performed as an ...
    (freebsd-arch)
  • Re: chmod broken?
    ... Bill Rees wrote: ... words "access" and "control" are not the same. ... since I have the root ... dictates that one use root privilege only sparingly, ...
    (Fedora)
  • Re: I cant post to this group
    ... with high privilege accounts, and this is seen as a normal mode of ... was using *nix for six months before I realized who this root user was. ...
    (alt.computer.security)