Re: PermitRootLogin=yes versus su

From: Ian Gregory (i.h.gregory@herts.ac.uk)
Date: 01/26/03


From: Ian Gregory <i.h.gregory@herts.ac.uk>
Date: 26 Jan 2003 21:26:15 GMT

Bill Unruh wrote:
 
> sudo is appropriate if you want to give certain users the right to run
> some program with root priviledges who you do not want to have
> unrestricted access to root. It makes no sense at all for the person who
> really acts as system administrator.

Sorry, but it makes PERFECT sense to me.

I run a development machine where I am the only one who ever accesses
it. I do admin stuff on it every day which requires having UID 0 but I
don't even remember what my root password is. When I need to do root
stuff I just type "sudo bash" and I get my favorite shell with my
current environment and UID 0. It is NOT the same as logging in as
root because the root shell never gets executed. Simple, convenient
and encourages good habits - don't knock it if you haven't tried it!

Of course I have to find my root password when I need to boot single
user but that is pretty rare.



Relevant Pages

  • Re: FC4 "sudo su -" breaks roots access to X server
    ... > be a bug - but really, it is a BAD idea to allow sudo to do anything ... > that can result in a root shell. ... almost placed a disclaimer about knowing the security risks. ...
    (Fedora)
  • Re: Card Reader
    ... Running your script ... instead of sudo is worthless because your script *can't do ... And of course it doesn't ask for a root password, ... >> That's just more bullshit Bryan, and you might as well leave ...
    (rec.photo.digital)
  • Re: hi all..
    ... And with sudo, I certainly wouldn't because they already have root. ... If you somehow had access to my account right now, ... install an effective key logger without root. ...
    (Fedora)
  • Re: Firefox 1.5.0.7 RPM
    ... I need root password to sudo. ... because sudoers can do just as stupid things as root. ...
    (alt.os.linux.suse)
  • Re: hi all..
    ... compromise security to achieve it - such as very insecure sudo defaults ... that essentially make any admin group user password a root password. ... IE someone gets your user account password, they can do more than just ...
    (Fedora)