- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Re: Separate Root logon Required for HP Support.
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-10-2003 01:44 AM
06-10-2003 01:44 AM
Separate Root logon Required for HP Support.
We have recently been audited and one of the audit recommendations is for us to create a separate logon for HP Support when they want to jump on to our box. Now we normally let HP login as user ???root???, so should I simply create another user ???hp_root??? (say) with the same settings as the root user ie UID 0 and Primary Group SYS???? or should I be doing something else???? any thoughts on this please.
Kind Regards
Khalil
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-10-2003 01:53 AM
06-10-2003 01:53 AM
Re: Separate Root logon Required for HP Support.
what you suggested is a way.
Another way is to create another normal account (let say hproot) and install the sudo utility (downloadale from http://hpux.connect.org.uk/)
Then you set-up sodu to let they switch to user root, with all it logged.
To set-up sudo, there are other threads.
HTH,
Massimo
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-10-2003 01:54 AM
06-10-2003 01:54 AM
Re: Separate Root logon Required for HP Support.
If you have to do something then I would do this.
Create the account as requested. (hp)
Give normal shell access not root
If they need root access (HP engineer) then change it and when they are finished change it back.
I would never do this. They can always give you the commands that they want run and then send them the output. Nothing against HP, but why would you let a total stranger on your system with full access rights ....
Regards
Michael
"When I have trouble spelling, it's called fat finger syndrome."
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-10-2003 01:55 AM
06-10-2003 01:55 AM
Re: Separate Root logon Required for HP Support.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-10-2003 01:57 AM
06-10-2003 01:57 AM
Re: Separate Root logon Required for HP Support.
exactly what you wrote. Please create a further user, e.g. "hp_root" with same UID and GID like "root", this will make all HP logins transparent (command 'last', file 'syslog.log', ...).
Regards...
Armin
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-10-2003 02:34 AM
06-10-2003 02:34 AM
Re: Separate Root logon Required for HP Support.
commands for HP support engineers and permit them to run those only.If they should run some command but couldnd (and this command isn't in the HP allowed list) - they would call and you can add this command to the list.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-10-2003 04:39 AM
06-10-2003 04:39 AM
Re: Separate Root logon Required for HP Support.
I would never do this. There should be NO direct root or root-equivalent logins. There's no way to know who logged in. If your root/root-equiv PW got cracked you're system would be a sitting duck - a tempting target.
You should set them up a normal account & then require them to su (setting a temp root PW) or sudo to root. Direct root logins should ONLY be allowed from the console - period.
My 2 cents,
Jeff
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-10-2003 04:51 AM
06-10-2003 04:51 AM
Re: Separate Root logon Required for HP Support.
Obviously there are times (like single-user mode or system recovery) when you have to log in as root.
If you do create a seperate root -level id for HP support, keep it disabled when not needed. You don't need extra root accounts sitting around unused.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-10-2003 05:10 AM
06-10-2003 05:10 AM
Re: Separate Root logon Required for HP Support.
Bill Hassell, sysadmin
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-10-2003 06:06 AM
06-10-2003 06:06 AM
Re: Separate Root logon Required for HP Support.
Khalil
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-10-2003 07:22 AM
06-10-2003 07:22 AM
Re: Separate Root logon Required for HP Support.
Chris
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-10-2003 07:23 AM
06-10-2003 07:23 AM
Re: Separate Root logon Required for HP Support.
Because the auditors recommended it does not make it right.
Root access to your server must be controlled and one entry point is more than enough.
Paula
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-10-2003 07:31 AM
06-10-2003 07:31 AM
Re: Separate Root logon Required for HP Support.
Install SUDO and use it for everything else requiring root authority.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-10-2003 08:51 AM
06-10-2003 08:51 AM
Re: Separate Root logon Required for HP Support.
I also think that root access should be granted only from the console. I have been involved in some situations where I had to be the middle man between HP and the machine because I did not want to allow direct access to our boxes. In my oppinion, I also like to know what they are planning on doing. That way, I am still in control of the box.
Regards,
DR
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-10-2003 10:04 AM
06-10-2003 10:04 AM
Re: Separate Root logon Required for HP Support.
If you dont use or want/cant use sudo, then like what others already said create a generic user and change root passwd before HP intervention, force that user to su - (- important), write a script where you log who does su root or like me modify root's .profile to log:
who which user, from where, at what time
add in the .profile also the script command
with -a
(with maybe a well placed exit...)
dont forget to check the timestamp of your new .profile hasnt changed
Like that you have a record of what has been done...
All the best
Victor
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-10-2003 10:16 AM
06-10-2003 10:16 AM
Re: Separate Root logon Required for HP Support.
Whatever goes wrong, whoever did it, ultimately, it's your responsibility. If HP needs certain commands run and the output gathered then YOU run the commands. Even seemingly innocuous commands might cause an application crash be the HP guys didn't know enough about your specific system.