<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: root or non root in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/root-or-non-root/m-p/4133807#M316575</link>
    <description>The bickering over root access rapidly boiled over into a ridiculous situation, all emotion and no fact. So nobody gets it.&lt;BR /&gt;&lt;BR /&gt;1. We build all our systems as a platform, and then use ignite to create production instances. &lt;BR /&gt;&lt;BR /&gt;2. We make extensive use of sudo, to issue 'root'-level commands but with logging and accountability to particular users.</description>
    <pubDate>Wed, 23 Jan 2008 23:58:31 GMT</pubDate>
    <dc:creator>Sorrel G. Jakins</dc:creator>
    <dc:date>2008-01-23T23:58:31Z</dc:date>
    <item>
      <title>root or non root</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/root-or-non-root/m-p/4133803#M316571</link>
      <description>&lt;BR /&gt;Currently in our env we have root doing all the installation and administration of the applications like JBOSS / apache / all middlwares etc. My idea is to move to non root accounts so that things can be managed securely and in a better way.&lt;BR /&gt;&lt;BR /&gt;Please suggest whether you have faced this situation before and how to deal with it in terms of moving the existing applications to non root user. What are the things that we need to take care of in order to seamlessly migrate over .</description>
      <pubDate>Wed, 23 Jan 2008 00:09:05 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/root-or-non-root/m-p/4133803#M316571</guid>
      <dc:creator>Allanm</dc:creator>
      <dc:date>2008-01-23T00:09:05Z</dc:date>
    </item>
    <item>
      <title>Re: root or non root</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/root-or-non-root/m-p/4133804#M316572</link>
      <description>Many of these types of applications may require root to install them.  That is fine.  The application teams should coordinate with the systems administrators for installation.&lt;BR /&gt;&lt;BR /&gt;However, day-to-day administration of these types of things should NOT require root. Your application teams/users should have their own user ids which they should use for their purposes.&lt;BR /&gt;&lt;BR /&gt;In terms of moving existing applications to use non-root users for administration, they will probably be a difficult task.  Things like this need to be looked at and planned prior to the products actually being installed.</description>
      <pubDate>Wed, 23 Jan 2008 01:20:34 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/root-or-non-root/m-p/4133804#M316572</guid>
      <dc:creator>Patrick Wallek</dc:creator>
      <dc:date>2008-01-23T01:20:34Z</dc:date>
    </item>
    <item>
      <title>Re: root or non root</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/root-or-non-root/m-p/4133805#M316573</link>
      <description>Hello,&lt;BR /&gt;&lt;BR /&gt;I agree with Patrick.&lt;BR /&gt;&lt;BR /&gt;You will have two kinds of issues:&lt;BR /&gt;&lt;BR /&gt;a) Resistance by humans to stop&lt;BR /&gt;relying on root access for everything.&lt;BR /&gt;&lt;BR /&gt;Various application admin teams often request&lt;BR /&gt;root access as though they cannot exist&lt;BR /&gt;without it.&lt;BR /&gt;&lt;BR /&gt;By nature, humans are not keen on&lt;BR /&gt;changes. Even when the change looks good,&lt;BR /&gt;people like to stick to what they already&lt;BR /&gt;know or have.&lt;BR /&gt;&lt;BR /&gt;Besides, lot of people like to&lt;BR /&gt;have root access. It gives them sense of power.&lt;BR /&gt;&lt;BR /&gt;Personally, I prefer not to know root passwords :) It is too much trouble to&lt;BR /&gt;worry about them...&lt;BR /&gt;&lt;BR /&gt;b) Technical problems:&lt;BR /&gt;&lt;BR /&gt;1. Does given application need to open&lt;BR /&gt;the Well Known Ports (those from 0 through&lt;BR /&gt;1023)?&lt;BR /&gt;&lt;BR /&gt;2. Was given application designed to&lt;BR /&gt;run as root (due to bad design or whatever)?&lt;BR /&gt;&lt;BR /&gt;3. How many commands require privileged&lt;BR /&gt;access?&lt;BR /&gt;&lt;BR /&gt;And so on.&lt;BR /&gt;&lt;BR /&gt;Here is a brief plan of attack:&lt;BR /&gt;&lt;BR /&gt;a) Read documentation for each application&lt;BR /&gt;and/or user account that supports it.&lt;BR /&gt;&lt;BR /&gt;That includes contacting vendors as well.&lt;BR /&gt;&lt;BR /&gt;And, of course, asking questions in Forums&lt;BR /&gt;like ITRC.&lt;BR /&gt;&lt;BR /&gt;b) Analyze active ports on the server&lt;BR /&gt;and verify who is using them.&lt;BR /&gt;&lt;BR /&gt;c) Talk to application support teams&lt;BR /&gt;in a friendly manner.&lt;BR /&gt;&lt;BR /&gt;d) Make one change at a time - preferably&lt;BR /&gt;on a test/development server (if you have&lt;BR /&gt;one).&lt;BR /&gt;&lt;BR /&gt;Cheers,&lt;BR /&gt;&lt;BR /&gt;VK2COT</description>
      <pubDate>Wed, 23 Jan 2008 10:50:03 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/root-or-non-root/m-p/4133805#M316573</guid>
      <dc:creator>VK2COT</dc:creator>
      <dc:date>2008-01-23T10:50:03Z</dc:date>
    </item>
    <item>
      <title>Re: root or non root</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/root-or-non-root/m-p/4133806#M316574</link>
      <description>I've found very few applications that need root privileges to run. Everywhere I've gone it's been standard practice to install as root but run/manage as non-root, with sudo (or similar) access as appropriate.&lt;BR /&gt;&lt;BR /&gt;You may have to push vendors a little when you start asking questions. Many of them (even big players like IBM) say to run things as root, but if you press they'll admit that it's only necessary in specific situations.&lt;BR /&gt;&lt;BR /&gt;I predict that you'll get very tired of patiently explaining to people that you want to identify why something is failing instead of just doing it as root.&lt;BR /&gt;</description>
      <pubDate>Wed, 23 Jan 2008 21:50:01 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/root-or-non-root/m-p/4133806#M316574</guid>
      <dc:creator>Heironimus</dc:creator>
      <dc:date>2008-01-23T21:50:01Z</dc:date>
    </item>
    <item>
      <title>Re: root or non root</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/root-or-non-root/m-p/4133807#M316575</link>
      <description>The bickering over root access rapidly boiled over into a ridiculous situation, all emotion and no fact. So nobody gets it.&lt;BR /&gt;&lt;BR /&gt;1. We build all our systems as a platform, and then use ignite to create production instances. &lt;BR /&gt;&lt;BR /&gt;2. We make extensive use of sudo, to issue 'root'-level commands but with logging and accountability to particular users.</description>
      <pubDate>Wed, 23 Jan 2008 23:58:31 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/root-or-non-root/m-p/4133807#M316575</guid>
      <dc:creator>Sorrel G. Jakins</dc:creator>
      <dc:date>2008-01-23T23:58:31Z</dc:date>
    </item>
  </channel>
</rss>

