Re: root group in solaris

Noel del Rosario <[email protected]> Mon, 18 Sep 2006 13:56:46 -0700 (PDT)
Newsgroups gmane.comp.security.sun
Message-ID <[email protected]>
Hi,

   I absolutely agree that RBAC is the BEST option 
   all you have to do is to change type of user for
   root from normal to a role (/etc/use_attr).
   Then `usermod -R root username`.
cheers


--- Valerie Anne Bubb <[email protected]> wrote:

> On Mon, 18 Sep 2006, dubaisans dubai wrote:
> 
> > Hi,
> >
> > I would like to give root user privileges to a set of
> OS
> > administrators. Everyone has individual user-ids on the
> system.
> > Currently they login with their personal ID and then SU
> to root. I
> > donot want to share root password with these many
> people.
> >
> > I am thinking of adding all these users to the "root"
> group[GID 0].
> > Will it provide root-equivalent UID O access to these
> users. If not
> > why ? Does the "root" group not have root user-id
> equivalent
> > privileges?
> >
> > Is it possible manually to make the GID 0 privileges
> equivalant of UID O?
> >
> > How else can I give these individual users root
> privileges - make all
> > of them UID 0 or something.? Is that a smart idea?
> >
> > I am looking at something simpler than SUDO or RBAC
> 
> Hi there -
> 
> What is the issue you are having with RBAC? It is
> included
> by default in Solaris, many things like SSH are RBAC
> aware,
> it is logged & audited.
> 
> If you're running solaris 10 or newer, you can also use
> least priveleges to limit what each operator can do.
> 
> Valerie
> -- 
> Now appearing as Gloria Rasputin and various other
> characters in
>     "Bye Bye Birdie" at SDG
> http://www.saratogadramagroup.com/
>           Sept 23 - Oct 14. Tickets: (408) 266-4734
> 


Noel Z. Del Rosario


__________________________________________________
Do You Yahoo!?
Tired of spam?  Yahoo! Mail has the best spam protection around 
http://mail.yahoo.com