LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-13-2008, 12:44 AM   #1
ZAMO
Member
 
Registered: Mar 2007
Distribution: Redhat &CentOS
Posts: 598

Rep: Reputation: 30
Granting Access using MAC for a multiple user environment.


Hi all,

I have a user environment , which can be accessible with a username and Public key as authentication . I have a set of users using the same username to access the same single environment .

To track the individual user activities inside the environment, Is there anyway ?
As they are all using the same username , Is there anyway to differentiate the users using their MAC address?
 
Old 08-13-2008, 01:24 AM   #2
chort
Senior Member
 
Registered: Jul 2003
Location: Silicon Valley, USA
Distribution: OpenBSD 4.6, OS X 10.6.2, CentOS 4 & 5
Posts: 3,660

Rep: Reputation: 76
If they all connect from a directly-attached local network, you can see which MAC address passed each IP datagram, but keeping track of that would be a huge pain and it would only tie computer to connection, it wouldn't correlate computer to commands or actions that were performed.

Why wouldn't you just create multiple user accounts?
 
Old 08-13-2008, 06:05 AM   #3
ZAMO
Member
 
Registered: Mar 2007
Distribution: Redhat &CentOS
Posts: 598

Original Poster
Rep: Reputation: 30
Chort,

It is must to keep the single user account. Yes Of course , keeping track of that would be a huge pain and it would only tie computer to connection.

So , In case am dropping the idea of tracking , but if I want to isolate the user who execute a command or created a file in single user environment, How can I do it? Is there any way to trace him? (I mean not track users all time, but if needed occasionally).

Any ideas? You can suggest one other than MAC also(if it is there) .

Thanks a Lot
 
Old 08-13-2008, 01:00 PM   #4
chort
Senior Member
 
Registered: Jul 2003
Location: Silicon Valley, USA
Distribution: OpenBSD 4.6, OS X 10.6.2, CentOS 4 & 5
Posts: 3,660

Rep: Reputation: 76
Yes, there's a good suggestion:
DON'T USE A SINGLE ACCOUNT!

Honestly, if you're concerned about auditing user actions, you need to figure out a way to assign separate accounts. Trying to figure out how to track individual humans using the same account is going to take more time than figuring out a way to use separate accounts would. The benefit is the same amount of effort invested in creating separate accounts will result in a vastly superior access control system, vastly superior monitoring, and it would be a permanent solution rather than a band-aid that you would have to come back and solve all over again every time you have a new problem with the shared account.
 
Old 08-13-2008, 03:47 PM   #5
farslayer
LQ Guru
 
Registered: Oct 2005
Location: Northeast Ohio
Distribution: linuxdebian
Posts: 7,249
Blog Entries: 5

Rep: Reputation: 191Reputation: 191
If they use the same account, what's the point of even trying to track them ?

You could NEVER prove in court that any one person was guilty of anything since they all share the same account.. you would be unable to prove which user was on any specific machine at a given time, the logs and effort to create them would be a waste of time.

Any decent security policy/regulation (PCI, Sarbanes-Oxley, Hippa, ISO 27002, etc..) will state that all users should have an individual, secure, unique login.

I can create multiple accounts and give them all access to the same resources/data I don't see why that is not possible in your environment.. ??
 
Old 08-14-2008, 04:51 AM   #6
ZAMO
Member
 
Registered: Mar 2007
Distribution: Redhat &CentOS
Posts: 598

Original Poster
Rep: Reputation: 30
Thank You For your suggestions
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
visudo and granting access to mount for a normal user nass Slackware 9 01-26-2007 10:25 PM
Granting SSH access to a Ruby on Rails user calande Linux - Security 1 01-12-2006 02:33 PM
Granting user access to devices like a jumpdrive tleadley Fedora - Installation 0 02-17-2005 07:02 PM
Granting users full internet access!? adham1sa Linux - Networking 3 12-22-2004 06:08 AM
ipop3 only granting one user access KnightCrusader Linux - Networking 1 11-25-2003 04:26 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 02:42 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration