- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - Linux
- >
- SUDO question
Operating System - Linux
1753727
Members
4744
Online
108799
Solutions
Forums
Categories
Company
Local Language
юдл
back
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Forums
Forums
Discussions
юдл
back
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Blogs
Information
Community
Resources
Community Language
Language
Forums
Blogs
Go to solution
Topic Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО04-07-2010 11:34 AM
тАО04-07-2010 11:34 AM
I am setting up some users with sudo access to startup and shutdown an application as oracle user. I am taking the following scripts:
1- I created a user alias APP_ADMIN in the sudoers file using visudo:
User_Alias APP_ADMIN = user1, user2
2- I created command alias in the sudoers file as follows:
Cmnd_Alias APP = /pathtoscript/start_servers.sh, /pathtoscript/stop_servers.sh
3- Now I have given the user group APP_ADMIN permission to run the startup and shutdown scripts using visudo as follows:
APP_ADMIN localhost=(oracle) NOPASSWD:APP
4- Now when user1 logs in and issue the startup or shutdown script, he gets the following error:
$ sudo -u oracle /pathtoscript/start_servers.sh
Password:
user1 is not allowed to run sudo on server_01. This incident will be reported.
Any one can please help me out if I am missing some thing here. Or some other way to do this thing. The main idea is to give users access just to start and stop the application as oracle without giving them other rights and priviledges as oracle user.
1- I created a user alias APP_ADMIN in the sudoers file using visudo:
User_Alias APP_ADMIN = user1, user2
2- I created command alias in the sudoers file as follows:
Cmnd_Alias APP = /pathtoscript/start_servers.sh, /pathtoscript/stop_servers.sh
3- Now I have given the user group APP_ADMIN permission to run the startup and shutdown scripts using visudo as follows:
APP_ADMIN localhost=(oracle) NOPASSWD:APP
4- Now when user1 logs in and issue the startup or shutdown script, he gets the following error:
$ sudo -u oracle /pathtoscript/start_servers.sh
Password:
user1 is not allowed to run sudo on server_01. This incident will be reported.
Any one can please help me out if I am missing some thing here. Or some other way to do this thing. The main idea is to give users access just to start and stop the application as oracle without giving them other rights and priviledges as oracle user.
Solved! Go to Solution.
3 REPLIES 3
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО04-07-2010 12:24 PM
тАО04-07-2010 12:24 PM
Solution
You have "localhost" specified as the server, but "server_01" shows up when you run sudo. You need to specify that name in your APP_ADMIN definition.
APP_ADMIN server_01=(oracle) NOPASSWD:APP
You could also create a HOST_ALIAS entry with localhost and server_01 as entries.
Something like:
Host_Alias THISHOST=localhost,server_01
Then use THISHOST in you APP_ADMIN definition.
APP_ADMIN THISHOST=(oracle) NOPASSWD:APP
APP_ADMIN server_01=(oracle) NOPASSWD:APP
You could also create a HOST_ALIAS entry with localhost and server_01 as entries.
Something like:
Host_Alias THISHOST=localhost,server_01
Then use THISHOST in you APP_ADMIN definition.
APP_ADMIN THISHOST=(oracle) NOPASSWD:APP
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО04-07-2010 01:00 PM
тАО04-07-2010 01:00 PM
Re: SUDO question
@Patrick... what would be wrong with using ALL instead of HOST or localhost ?
it would make this config portable, would it not ?
it would make this config portable, would it not ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО04-07-2010 08:24 PM
тАО04-07-2010 08:24 PM
Re: SUDO question
ALL would work, and yes it would make this portable. BUT you might not want user1 to have that access on ALL servers.
I prefer setting host security explicitly for each host. If you do that there is less of a chance of someone getting access they don't really need or aren't entitiled to.
I prefer setting host security explicitly for each host. If you do that there is less of a chance of someone getting access they don't really need or aren't entitiled to.
The opinions expressed above are the personal opinions of the authors, not of Hewlett Packard Enterprise. By using this site, you accept the Terms of Use and Rules of Participation.
News and Events
Support
© Copyright 2024 Hewlett Packard Enterprise Development LP