Operating System - HP-UX
1846628 Members
1940 Online
110256 Solutions
New Discussion

Re: restricted root access

 
bassey essien_1
Frequent Contributor

restricted root access

i,m a sr. unix admin and would love to restrict root access permission that is granted to one of my database admin without
stopping him from doing his oracle functions.
what shell do i need to run to accomplish these.please respond ASAP.
Thanks, bassey essien.
12 REPLIES 12
CHRIS_ANORUO
Honored Contributor

Re: restricted root access

Create /etc/securetty file and put console in the file. This will restrict root access to all terminals except console.
When We Seek To Discover The Best In Others, We Somehow Bring Out The Best In Ourselves.
John Palmer
Honored Contributor

Re: restricted root access

Hi,

Is he not able to do his Oracle activities from the 'oracle' account (or whatever you've called it). He shouldn't need root access just to administer the databases.

Regards,
John
Rick Garland
Honored Contributor

Re: restricted root access

sudo sounds like a good choice. You can configure the DBA to have root access to only those commands you specify in the sudoers file. Additional, there is good logging associated with the utility and all sudo commands will be logged with a date-time stamp.
James R. Ferguson
Acclaimed Contributor

Re: restricted root access

Hi:

I presume that you want your DBA to be able to do some root functions. Have you considered using "restricted SAM"?

...JRF...
Victor BERRIDGE
Honored Contributor

Re: restricted root access

Why does he need root access?
Here no oracle user have root privilege, I mean no dba have root passwd...
now when they need anything they should ask the sysadm...(Thats the official version...)
If root privilege is needed for a special task you have 2 choices:
1)look if you cannot solve this with restricted SAM.
2) Use sudo which will give root priv. for what you have defined
Alan Riggs
Honored Contributor

Re: restricted root access

Restricted SAM and sudo are both good options. Personally, I prefer sudo because you have a finer degree of control over the specific ativities allowed and because I find teh sulog easier to examine/parse tha SAMlogs.
CHRIS_ANORUO
Honored Contributor

Re: restricted root access

You see, Bassey essien (Nde foo) We have answered you "ASAP"! NOW AWARD YOUR MARKS FOR OUR TIME!
When We Seek To Discover The Best In Others, We Somehow Bring Out The Best In Ourselves.
Victor BERRIDGE
Honored Contributor

Re: restricted root access

Hey Chris, do you think steven chen has been rechristianned bassey essien ?
Alan Riggs
Honored Contributor

Re: restricted root access

LOL

I usually try to steer clear of this issue, but I find it highly amusing that the only post in this thread which was helpful to the OP was apparently Chris' request that points be assigned.

James R. Ferguson
Acclaimed Contributor

Re: restricted root access

Hi:

Ditto to Alan's last post re. points!!!

...JRF...
Rick Garland
Honored Contributor

Re: restricted root access

Is this a joke or what?

You only award points to those that ask?
Well, you are reading it, we are all asking.
Junior C.
Frequent Advisor

Re: restricted root access

No DBA should have root access. The only time root access comes in play is when executing root.sh script.

Junior