secure UNIX log server

From: fanny (fannysaunders@yahoo.com)
Date: 05/28/02


From: fannysaunders@yahoo.com (fanny)
Date: 28 May 2002 10:57:38 -0700

I am defining policy and procedures for my company to collect, store
and review UNIX logs. We are storing them a seperate UNIX "log
server" and locally on servers. The log server is physcially secured
and limited in who can log in but I am still concerned that the logs
could be erased by someone who compromised the root account or by a
UNIX administrators authorized to use the root acount.

The only answer I have come up with is to take root away from the UNIX
administrators on the log server and give it to the Security team.
Then UNIX admins have root on individuals servers but not on the log.
Politically, taking root away from the UNIX admins, even on one
server, could be impossible. I could have all logs sent to a Windows
2000 server instead. Do I have any other alternatives? Are there any
security engineers out there who have come up with a good solution to
this problem? thanks in advance,

Fanny



Relevant Pages

  • RE: Access Denied message evenwhen loging in locallyafter joining
    ... -The other computers and the Unix box are in a workgroup. ... -The only problem is that I can not access the shared folders in the Unix ... So, as I said, I can connect to the Unix server to use the company's ... > Thank you for posting to the SBS Newsgroup. ...
    (microsoft.public.windows.server.sbs)
  • Re: secure UNIX log server
    ... Could always write to Cd-R rather than a file system. ... We are storing them a seperate UNIX "log ... The log server is physcially secured ... > UNIX administrators authorized to use the root acount. ...
    (comp.security.unix)
  • Re: secure UNIX log server
    ... Could always write to Cd-R rather than a file system. ... We are storing them a seperate UNIX "log ... The log server is physcially secured ... > UNIX administrators authorized to use the root acount. ...
    (comp.security.unix)
  • Re: secure UNIX log server
    ... We are storing them a seperate UNIX "log ... The log server is physcially secured ... >> UNIX administrators authorized to use the root acount. ... >> administrators on the log server and give it to the Security team. ...
    (comp.security.unix)
  • Re: secure UNIX log server
    ... We are storing them a seperate UNIX "log ... The log server is physcially secured ... >> UNIX administrators authorized to use the root acount. ... >> administrators on the log server and give it to the Security team. ...
    (comp.security.unix)