Operating System - HP-UX
1751860 Members
5319 Online
108782 Solutions
New Discussion юеВ

Re: su - switch user - NON-root

 
SOLVED
Go to solution
OFC_EDM
Respected Contributor

su - switch user - NON-root

As you all know if you're logged into an HP-UX server as "root" when you switch user (su) to another account you can do so - without being prompted for a password.

I'd like to setup this same behaviour for 2 regular user accounts.

Preferrably without having to install sudo.

Any ideas on how to accomplish this?
The Devil is in the detail.
2 REPLIES 2
Steven E. Protter
Exalted Contributor

Re: su - switch user - NON-root

Kevin,

You are asking for an account to have a special prviledge only granted to root, without being root.

You are essentially granting root access to these accounts. Its an enormous security hole, but if you assign the numeric account id to zero, same as root, these accounts will have the same power.

They will also have all the other powers of root and I recommend you not do this.

You may be able to manipulate the pam.d configuration files to create the same behavior.

This is risky and root user and root cron should be used for these operations.

SEP
Steven E Protter
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
Solution

Re: su - switch user - NON-root

Hi,

1.Create a new group and assign those two users in the new group.
2.Edit /etc/default/security file and make SU_ROOT_GROUP as the new group.
3.Customise the pam authentication, so that the password is not prompted for those two users when they issue 'su'

Regards,
Sunil
Your imagination is the preview of your life's coming attractions