- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- root user privileges for select functions only--wi...
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-10-2002 11:49 AM
06-10-2002 11:49 AM
root user privileges for select functions only--without restricted sam.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-10-2002 11:52 AM
06-10-2002 11:52 AM
Re: root user privileges for select functions only--without restricted sam.
1) Download and install 'sudo' from any of the HP-UX Porting Centre's
2) Create small C setuid wrappers.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-10-2002 11:56 AM
06-10-2002 11:56 AM
Re: root user privileges for select functions only--without restricted sam.
How about trying a super user with rsh , like create a user and change the default shell to rksh and the uid to 0 and gid to 3 . In the .profile for that user you can specify a path of a direcort which just holds these command like lp. passwds etc .
"
The restricted shell is designed to put the user into an environment where his or her ability to move around and write files is severely limited. It's usually used for "guest" accounts. You can make a user's login shell restricted by putting rksh or ksh -r in the user's /etc/passwd entry.
The specific constraints imposed by the restricted shell disallow the user from doing the following:
Changing working directories: cd is inoperative. If you try to use it, you will get the error message "ksh: cd: restricted".
Redirecting output to a file: the redirectors >, >|, <>, and >> are not allowed.
Assigning a new value to the environment variables SHELL, ENV, or PATH.
Specifying any pathnames with slashes (/) in them. The shell will treat files outside of the current directory as "not found."
These restrictions go into effect after the user's .profile and environment files are run.
This means that the restricted shell user's entire environment is set up in .profile. Since the user can't overwrite that file, this lets the system administrator configure the environment as he or she sees fit.
Two common ways of setting up such environments are to set up a directory of "safe" commands and have that directory be the only one in PATH, and to set up a command menu from which the user can't escape without exiting the shell.
Manoj Srivastava
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-10-2002 12:10 PM
06-10-2002 12:10 PM
Re: root user privileges for select functions only--without restricted sam.
Marty
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-10-2002 12:14 PM
06-10-2002 12:14 PM
Re: root user privileges for select functions only--without restricted sam.
"SUDO" is the best solution. You can also audit the commands run by the user. You can get it from
http://hpux.cs.utah.edu/hppd/hpux/Sysadmin/sudo-1.6.6/
Other "insecured" way is to create a group and place only this user in it.
Then write a script with some case statements in it that will do the job. Now give sticky bit to the script with "only" execute permissions for the group and "no" permission to others.
-Sri
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-10-2002 12:42 PM
06-10-2002 12:42 PM
Re: root user privileges for select functions only--without restricted sam.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-12-2002 01:10 PM
06-12-2002 01:10 PM
Re: root user privileges for select functions only--without restricted sam.
You might also look into HP's ServiceControl Manager (SCM) at http://www.software.hp.com/products/SCMGR
I've just started looking into it so I don't have much info. It, like sudo, is a free tool that may do what you want (and more).
You can search the forums and find a number of hits on SCM.
Darrell