- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Re: SU Restriction
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-16-2002 01:03 PM
07-16-2002 01:03 PM
SU Restriction
rather than logging directly into root. Is there a method in HPUX11.00
to limit who can use the su command or better yet, a method to limit su
to root?
John Carver
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-16-2002 01:13 PM
07-16-2002 01:13 PM
Re: SU Restriction
"su" is a regular unix command. If you want that su should work only if root is passed as an argument, you can move the binary executable su to a location not in the regular user path and then put a wrapper around the su command in a script such that the script can check if root is passed as aan arguement, if so it works else it fails.
however is there a problem in allowing the regular users to su to another user id than root?. should be okay if the user can do an su to another user id since any userid other than root will be required to give the passwd for the userid someone is su'ing to.
Hope this helps.
regds
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-16-2002 01:15 PM
07-16-2002 01:15 PM
Re: SU Restriction
Maybe you can use sudo for it :
see :
http://forums.itrc.hp.com/cm/QuestionAnswer/1,,0xaf7e37f45ef7d4118fef0090279cd0f9,00.html
regards
Steven
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-16-2002 01:15 PM
07-16-2002 01:15 PM
Re: SU Restriction
SU_ROOT_GROUP=group name
in the file /etc/default/security. So only the users in that particular users will be able to su to root.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-16-2002 01:18 PM
07-16-2002 01:18 PM
Re: SU Restriction
Here is how we do it . edit /etc/profile and add the following lines :
loginid=`who am i | awk '{print $1}'`
echo $loginid
if [ $loginid = root ]
then
exit
fi
this will throw out anyone trying to log in as root , so to go to root you have to su to root after logging in as a normal user.
Manoj Srivastava
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-16-2002 01:18 PM
07-16-2002 01:18 PM
Re: SU Restriction
You can get sudo from here,
http://hpux.cs.utah.edu/hppd/hpux/Sysadmin/sudo-1.6.6/
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-16-2002 04:07 PM
07-16-2002 04:07 PM
Re: SU Restriction
http://docs.hp.com/cgi-bin/fsearch/framedisplay?top=/hpux/onlinedocs/B2355-90696/B2355-90696_top.html&con=/hpux/onlinedocs/B2355-90696/00/01/111-con.html&toc=/hpux/onlinedocs/B2355-90696/00/01/111-toc.html&searchterms=security%7c4&queryid=20020716-171645
and
http://docs.hp.com/hpux/onlinedocs/5185-4391/5185-4391.html
Bill Hassell, sysadmin
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
07-16-2002 04:14 PM
07-16-2002 04:14 PM