Re: unix compliance checks - file ownership

"Doug Nordwall" <[email protected]>
Newsgroups gmane.comp.security.nessus.general
Message-ID <[email protected]>
*sigh* :)
this is for historical reasons. I've been fighting this particular issue now
for about 7 years. In our case, it allows us to have a user who controls
root on his box and allows us to have an account that has root level
permissions to "assist in administration".

now, I realize this is not a normal config. there is even a handy dandy
compliance check that says that I have two uid 0 accounts. however, this
doesn't negate that there is an error in the compliance check :)

On Mon, Jun 2, 2008 at 1:48 PM, Renaud Deraison (lists) <
[email protected]> wrote:

>
> On Jun 2, 2008, at 8:22 PM, Doug Nordwall wrote:
>
>  so, we have boxes (many) with 2 UID 0 accounts.
>>
>
> Stop right here. This goes against every Unix administrative best practices
> playbook which clearly says that each user should have its own UID. Why do
> you have such a setup ?
>
>
>                                -- Renaud
>



-- 
Doug Nordwall
Unix, Network, and Security Administrator
You mean the vision is subject to low subscription rates?!!? - Scott Stone,
on MMORPGs

_______________________________________________
Nessus mailing list
[email protected]
http://mail.nessus.org/mailman/listinfo/nessus
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.