LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-25-2008, 12:02 PM   #1
RaelOM
Member
 
Registered: Dec 2004
Posts: 110

Rep: Reputation: 16
Central Admin Framework Design


So I'm designing/setting up a central admin framework for UNIX (Solaris/Linux/HPUX) This framework will allow me to run commands locally targeted at other hosts enrolled in this management framework.

Example: I have a password change program that I can run on my CAF server

./passchange.pl --host=<TARGET HOST> --user=<USER> --password=<password>

This script would be executed remotely on the target machine changing the users password. (This is just a example of one of the many features)

I've setup a non privileged account on all my systems because I want root login of ssh to be disabled for security reasons. The non-privileged account is locked so it can not be logged into in any manner other than sudo.

I have a few routes in which I can accomplish this. I can write a cronjob that would poll a workq on each host every minute looking for jobs to execute as root. So the password command in this case would scp a file with the specifics of the job to the target host and the cronjob on the target would poll the workq and find this job and then execute it. This lacks realtime execution and providing realtime results of the execution.

I could also make the non-privlidged account a member of the root group.

My question here is would making this non-privlidged account a member of the root group present any security concerns? Assuming the account is well locked down with ACL's and directory permissions restricitng access so no one could manually populate the workq on the local machine would this be acceptable? Perhaps I could setup some form of trust keys for the poller and the CAF server to authenticate jobs as legitimate?

Does anyone have any input here on what I'm trying to accomplish?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Linux for Graphic Design, web design, and publishing maelstrom209 Linux - Software 8 07-17-2011 11:35 AM
Central Administration Framework RaelOM Linux - Software 6 08-06-2008 03:57 PM
LXer: Engine Manufacturer MTU Simplifies Design Workloads and Cuts Admin Time in Half by Using DataCore's Virtualization Software and VMware LXer Syndicated Linux News 0 09-05-2006 03:21 PM
2K admin now RHEL4 admin (I have some questions) wilsryan Red Hat 5 01-30-2006 12:18 PM
User admin and N/w admin on Gnome hangs ssrini *BSD 2 07-28-2005 07:55 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:37 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration