1826598 Members
3785 Online
109695 Solutions
New Discussion

dns-mgt as non root

 
Systeemingenieurs Infoc
Valued Contributor

dns-mgt as non root

hi, i want to revoke root access for my network admins, and let them administer dns with a non-root user. I have some questions :

1. Is it possible to change ownerships of the /etc/named.data/* - files ?
2. What other files have to be chowned ?
3. What commands should i configure in sudo (sig_named, ...) ?
4. Or is the whole thing a bad idea ?

tia

A Life ? Cool ! Where can I download one of those from ?
5 REPLIES 5
eran maor
Honored Contributor

Re: dns-mgt as non root

Hi

i will not advise you to change all the owner and the primission on this file .
the primision it not cause any problem but changing the owner can cause problem .

i will advise to create a user name for them and let them use the root access with sudo .

sudo is a software ( not HP !! ) that gives you the ablilty to manage users .

you can download the sudo from : http://hpux.cs.utah.edu/

i m also giving you the realese node of the sudo in a file
love computers
Systeemingenieurs Infoc
Valued Contributor

Re: dns-mgt as non root

defining vi in sudo to edit files, means they can escape from vi and execute commands as root. There've been some threads about this subject in the past.
A Life ? Cool ! Where can I download one of those from ?
Systeemingenieurs Infoc
Valued Contributor

Re: dns-mgt as non root

Is it better to change the group (netadmin) and the permissions (664)of the files ?
A Life ? Cool ! Where can I download one of those from ?
Rainer von Bongartz
Honored Contributor

Re: dns-mgt as non root

What about installing webmin.

Download it from

http://www.webmin.com/download.html

and configure to your needs.


Regards
Rainer
He's a real UNIX Man, sitting in his UNIX LAN making all his UNIX plans for nobody ...
Sachin Patel
Honored Contributor

Re: dns-mgt as non root

If you changes the owner of that file then you will going to see some funny result.
I have linux server who has dns database own by named and hp has database own by root and there was a problem. as soon as I change linux to root all problem disappear.

If you do so don't forget to change on all secondary servers also. Also create a user on all secondary server as well.

Sachin
Is photography a hobby or another way to spend $