Re: root group in solaris
Noel del Rosario <[email protected]> Mon, 18 Sep 2006 13:56:46 -0700 (PDT)
| Newsgroups | gmane.comp.security.sun |
|---|---|
| Message-ID | <[email protected]> |
Hi, I absolutely agree that RBAC is the BEST option all you have to do is to change type of user for root from normal to a role (/etc/use_attr). Then `usermod -R root username`. cheers --- Valerie Anne Bubb <[email protected]> wrote: > On Mon, 18 Sep 2006, dubaisans dubai wrote: > > > Hi, > > > > I would like to give root user privileges to a set of > OS > > administrators. Everyone has individual user-ids on the > system. > > Currently they login with their personal ID and then SU > to root. I > > donot want to share root password with these many > people. > > > > I am thinking of adding all these users to the "root" > group[GID 0]. > > Will it provide root-equivalent UID O access to these > users. If not > > why ? Does the "root" group not have root user-id > equivalent > > privileges? > > > > Is it possible manually to make the GID 0 privileges > equivalant of UID O? > > > > How else can I give these individual users root > privileges - make all > > of them UID 0 or something.? Is that a smart idea? > > > > I am looking at something simpler than SUDO or RBAC > > Hi there - > > What is the issue you are having with RBAC? It is > included > by default in Solaris, many things like SSH are RBAC > aware, > it is logged & audited. > > If you're running solaris 10 or newer, you can also use > least priveleges to limit what each operator can do. > > Valerie > -- > Now appearing as Gloria Rasputin and various other > characters in > "Bye Bye Birdie" at SDG > http://www.saratogadramagroup.com/ > Sept 23 - Oct 14. Tickets: (408) 266-4734 > Noel Z. Del Rosario __________________________________________________ Do You Yahoo!? Tired of spam? Yahoo! Mail has the best spam protection around http://mail.yahoo.com