Re: What's the deal on the -X vs -Y thing?

From: all mail refused (elvis_at_notatla.org.uk)
Date: 01/26/05


Date: 26 Jan 2005 00:48:39 GMT

In article <pan.2005.01.25.22.39.26.908259@dcs.nac.uci.edu>,
Dan Stromberg wrote:

>like the perspective of someone who's only worked on a small number of
>systems before. At UCI, we're herding cats.
>
>Believe it or not, not everyone has root access on the all the boxes they
>work on, and not all boxes have admins who are going to realize this
>change could help matters, nor do they have admins who would be responsive

This is why you want some capacity for central low-effort maintainance
of all those machines - including re-application of config requirements
ater they've been tampered with.

It sounds like you want to divide machines into "supported" and "unsupported"
and the supported ones should be enrolled in your central scheme with no
exceptions allowed.

If you could include automated edits (where nec.) to config files and a way
to restart the main sshd server without breaking current sessions you'd be
well on the way to solving this.

-- 
Elvis Notargiacomo  master AT barefaced DOT cheek
http://www.notatla.org.uk/goen/
    7.031: OnACPower returned value( 0x1 ) which is Equal To 0x1


Relevant Pages

  • Re: [Full-Disclosure] RE: DCOM RPC exploit
    ... >> A worm exploiting this might happen, but is it really that big of a deal? ... > of boxes that have DCOM open to the world.... ... m$ ladened admins have to maintain... ... This is not the first RPC nor ...
    (Full-Disclosure)
  • Re: Admins to Boxes ratio
    ... boxes worldwide. ... and HP admins who could do some stuff). ... Generally speaking, our customers ... follow-the-sun environment, you need to have a MINIMUM ...
    (AIX-L)
  • RE: [Full-Disclosure] RE: MS SQL WORM IS DESTROYING INTERNET BLOCK PORT 1434!
    ... > And blaming admins for not patching there boxes is bull. ... > wind up worse than Code Red, Nimda, or even the great worm of '88. ... > Charter: http://lists.netsys.com/full-disclosure-charter.html ...
    (Full-Disclosure)
  • Re: How can I disable (grey out) the "Password never expires" chec
    ... Its not so much that they don't comply but rather to meet the security ... These boxes can be greyed out as they are under certain cirumstances, ... the Admin account on a DC etc. ... >> Account properties windows so that the admins cannot bypass the password ...
    (microsoft.public.windows.server.active_directory)