- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Re: sudo or other type access
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-20-2005 06:42 AM
12-20-2005 06:42 AM
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-20-2005 06:47 AM
12-20-2005 06:47 AM
Re: sudo or other type access
Pete
Pete
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-20-2005 06:47 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-20-2005 06:48 AM
12-20-2005 06:48 AM
Re: sudo or other type access
There is an application called PowerBroker but this is a cost product. Lots of good with the package and lots of configuration is needed.
There is an application called 'rootsh'. Use this is conjuction with sudo. You will have the logging from sudo indicating that userA invoked sudo to execute the command. Once in rootsh another log file is appended to. This rootsh log file captures all input and output. Nothing missing in these log files.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-20-2005 06:49 AM
12-20-2005 06:49 AM
Re: sudo or other type access
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-20-2005 06:53 AM
12-20-2005 06:53 AM
Re: sudo or other type access
Sudo is the way to go.
HP and SUN are promoting RBAC, but I'm still in favour of SUDO.
What also can do to prevent root usage:
Restrict root logins to system console
echo console > /etc/securetty
chown root:sys /etc/securetty
chmod 600 /etc/securetty
Check if there are other users than root with uid=0
logins -d | grep ' 0 '
GoodLuck
Darrel
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-20-2005 07:16 AM
12-20-2005 07:16 AM
Re: sudo or other type access
I think sudo is most popular, primarily because it is free. But becasue it is free it is decentralised, you have to manage it seperately on each server.
The other alternative that i have worked with is powerbroker from symark. This is a very good product but costs $$$'s. The benefit is centralised manaagement and losts of features for a person to explore and use. since it can be configured from a central location, makes management of the policies easier.
Powerbroker site: http://www.symark.com
Hope this helps.
regds
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-20-2005 09:42 AM
12-20-2005 09:42 AM
Re: sudo or other type access
The source code can bo downloaded here:
http://hpux.cs.utah.edu/hppd/hpux/Sysadmin/super-3.9.7/
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-20-2005 10:21 AM
12-20-2005 10:21 AM