LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-30-2009, 10:58 AM   #16
orion.echo
LQ Newbie
 
Registered: Jul 2007
Location: Omaha Nebraska
Distribution: Redhat (Fedora / CentOS) - Slackware - Ubuntu
Posts: 15

Original Poster
Rep: Reputation: 0

Quote:
Originally Posted by edenCC View Post
I would not allow remote login for root, and instead I assign sudo permissions for some normal account, so that they can act as root.
Some password policy can be applied on these normal account, so they are meant to have change their password when needed.
This is actually what I'm going to be doing very soon. Its going to take some time because of the amount of servers I have to work with but in the end it will be worth it. When someone breaks something the audit trail will be much easier to follow. Once this has been implemented and nobody has complained I will then try to actually pull root access from everyone and use only sudo.
 
Old 10-31-2009, 01:23 PM   #17
twk
Member
 
Registered: Feb 2002
Location: Canada
Distribution: Fedora/RHEL
Posts: 152

Rep: Reputation: 31
Quote:
Originally Posted by orion.echo View Post
This is actually what I'm going to be doing very soon. Its going to take some time because of the amount of servers I have to work with but in the end it will be worth it. When someone breaks something the audit trail will be much easier to follow. Once this has been implemented and nobody has complained I will then try to actually pull root access from everyone and use only sudo.
I just recently completed this task and switched all secondary(e.g. application) admins to sudo. Our team basically told everyone who wish to have the password that their home & cell phone number will be on the call out list should anything happen to the server. That stopped all root password request pretty quickly.

As for root password changes, currently we have a management server that has public key access to all servers using dssh (http://pvid.net/w/index.php/DSSH). Eventually we'll probably phase it out with Red Hat Satellite.
 
Old 10-31-2009, 06:17 PM   #18
abefroman
Senior Member
 
Registered: Feb 2004
Location: lost+found
Distribution: CentOS
Posts: 1,430

Rep: Reputation: 55
Why can't you use fanout to automatically do a search and replace on the hash in /etc/shadow ?
 
Old 10-31-2009, 09:35 PM   #19
stickman
Senior Member
 
Registered: Sep 2002
Location: Nashville, TN
Posts: 1,552

Rep: Reputation: 53
Quote:
Originally Posted by TB0ne View Post
True....I'd not put root under LDAP either. Root under LDAP is a bad idea, and I probably wouldn't have suggested it, if I wasn't so tired yesterday.
I would not recommend this. If you LDAP system is down, then so is your root access. I'd recommend appropriate sudo access with something like rootsh. I'm sure that with a good for-loop and ssh/sudo access you could probably reset some passwords.
 
Old 11-02-2009, 08:19 AM   #20
fpmurphy
Member
 
Registered: Jan 2009
Location: /dev/ph
Distribution: Fedora, Ubuntu, Redhat, Centos
Posts: 299

Rep: Reputation: 62
Quote:
I'm 100% aware that this is insecure, I'm trying to fix this. Unfortunately it's not as easy as you might think. I can't just strip the root password from everyone. There are a lot of "higher ups" that won't allow this so I need to take baby steps to get a new process implemented. I have anywhere from 25 to 1000 users so getting the sudoers file fixed is also going to take time. The idea behind turning off direct root login's will allow me to get more info on who needs access to what server. Once this access is pulled I will be getting flooded with emails regarding adding / fixing user accounts. This is great, that means that I will be able to fix our sudoers file. I completely agree with you this is ridiculously insecure but its a legacy process so I have to make small changes verify that nothing breaks then move on. I was the one that complained about it being insecure so of course I get stuck with trying to fix the problem. The unknown root password is my ultimate goal but it's not going to happen over night.
You have the right idea. I agree with your approach. Unless you have the GM and all of senior management behind you, you are going to have to implement a series of small discrete steps over a period of time so that slowly but surely the need, be it real or perceived, for root access is eliminated.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Change my root password in Debian Linux if I have the current password? panseluta Linux - Newbie 2 12-28-2008 02:02 AM
How to retrieve( or reset) root password in Mandrake Linux, as I forgot my password? Reghunath Linux - Software 4 05-08-2008 04:11 AM
Password Synchronization for LINUX servers bhandu Linux - General 1 06-07-2007 08:47 PM
Changing root password on multiple servers user_lnx Linux - Enterprise 3 07-27-2006 01:16 PM
hardware for 4000 user servers zsoltrenyi Linux - Hardware 7 03-07-2005 06:55 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:59 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration