Re: root group in solaris : Tools

benjamin brumaire <[email protected]> Tue, 26 Sep 2006 08:41:35 +0200
Newsgroups gmane.comp.security.sun
Message-ID <[email protected]>
I 've deployed PowerBroker at several customers site. It was always 
successfull because of the central policy, the HA capability, a good 
support and the flexibility of the policy language.
In addition to the advantage already found against sudo I would add:
    - OOTB encryption for request/answer/log/keystrokelog
    - LDAP integration that allow users definition and autorization 
saved in directory
    - hardened shells and utilities (sh,ksh,vi,less)
    - integrated logs parser
    - checksum verificationof program to be executed
    - tiered policy

bbr

> What is the suggestion on using a tool like Powerbroker from Symark.
> The tool claims to centralise the "sudo" function and also provide
> logging? Does anyone have feedback on this tool or any other third
> party tool in the same space?
>
>
> On 9/19/06, Suzanne Widup <[email protected]> wrote:
>
>> Have you looked at implementing sudo?  It's a root delegation tool and
>> would give you some better accountability as to what people are doing.
>>
>> -----Original Message-----
>> From: [email protected] [mailto:[email protected]]
>> On Behalf Of dubaisans dubai
>> Sent: Monday, September 18, 2006 5:50 AM
>> To: [email protected]
>> Subject: root group in solaris
>>
>> Hi,
>>
>> I would like to give root user privileges to a set of OS administrators.
>> Everyone has individual user-ids on the system.
>> Currently they login with their personal ID and then SU to root. I donot
>> want to share root password with these many people.
>>
>> I am thinking of adding all these users to the "root" group[GID 0].
>> Will it provide root-equivalent UID O access to these users. If not why
>> ? Does the "root" group not have root user-id equivalent privileges?
>>
>> Is it possible manually to make the GID 0 privileges equivalant of UID
>> O?
>>
>> How else can I give these individual users root privileges - make all of
>> them UID 0 or something.? Is that a smart idea?
>>
>> I am looking at something simpler than SUDO or RBAC
>>
>>
>> "MMS <safeway.com>" made the following annotations.
>> ------------------------------------------------------------------------------ 
>>
>> Warning:
>> All e-mail sent to this address will be received by the Safeway 
>> corporate e-mail system, and is subject to archival and review by 
>> someone other than the recipient.  This e-mail may contain 
>> information proprietary to Safeway and is intended only for the use 
>> of the intended recipient(s).  If the reader of this message is not 
>> the intended recipient(s), you are notified that you have received 
>> this message in error and that any review, dissemination, 
>> distribution or copying of this message is strictly prohibited.  If 
>> you have received this message in error, please notify the sender 
>> immediately.
>>
>> ============================================================================== 
>>
>>
>>
>