LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - General
User Name
Password
Linux - General This Linux forum is for general Linux questions and discussion.
If it is Linux Related and doesn't seem to fit in any other forum then this is the place.

Notices


Reply
  Search this Thread
Old 07-27-2009, 07:38 AM   #1
mario.almeida
Member
 
Registered: May 2008
Location: India
Distribution: Ubuntu 10.04, CentOS, Manjaro
Posts: 179

Rep: Reputation: 27
read only access


Hi All,

Any idea how to give read only access to a particular user if login from a specific IP?

eg:

user xyz log in to the server (ssh) from ip 10.200.2.1 has full access
user xyz log in to the server (ssh) from ip 10.200.2.20 has read access


//Remy
 
Old 07-27-2009, 09:08 AM   #2
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
This is not a valid security model, you would need to think more carefully about what you're trying to achieve in order to have alevel of security. Additionally it makes no sense to ask about "full access" and such when they are getting shell access to a multi-user system. no one other than root should have "full access" anyway...
 
Old 07-28-2009, 12:52 AM   #3
mario.almeida
Member
 
Registered: May 2008
Location: India
Distribution: Ubuntu 10.04, CentOS, Manjaro
Posts: 179

Original Poster
Rep: Reputation: 27
Quote:
Originally Posted by acid_kewpie View Post
This is not a valid security model, you would need to think more carefully about what you're trying to achieve in order to have alevel of security. Additionally it makes no sense to ask about "full access" and such when they are getting shell access to a multi-user system. no one other than root should have "full access" anyway...
I've not made my self clear

what I mean by full access it not to the system root access

xyz user is a normal users have access to a file eg a log file /var/log/maillog

If that user login to the system from IP 10.200.2.1 can modify delete that file
If the same user login to the system from different ip 10.200.2.20 can only view that file

this is just an example

any idea how to achieve this with out creating new user?

//Remy
 
Old 07-28-2009, 01:02 AM   #4
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
Again, that's really a bad model. your IP address is such an arbitrary piece of data. I think you need to think about what you need to actually achieve and come up with a better way of doing it.
 
Old 07-28-2009, 01:48 AM   #5
mario.almeida
Member
 
Registered: May 2008
Location: India
Distribution: Ubuntu 10.04, CentOS, Manjaro
Posts: 179

Original Poster
Rep: Reputation: 27
Quote:
Originally Posted by acid_kewpie View Post
Again, that's really a bad model. your IP address is such an arbitrary piece of data. I think you need to think about what you need to actually achieve and come up with a better way of doing it.
Thanks for the reply, need to think of some other options eg new user
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Read only access to partitions roadrash Linux - Desktop 3 03-10-2009 06:35 PM
how do i access files off cd that are read-only e3l Linux - Newbie 8 02-27-2006 11:41 PM
read-only access after a few days jacko1729 Linux - Networking 4 07-27-2005 08:52 AM
access to read only files absalon Linux - Newbie 4 06-22-2005 06:31 AM
read write access phoenix_wolf Linux - Newbie 2 12-05-2004 09:35 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - General

All times are GMT -5. The time now is 09:21 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration