LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-19-2010, 05:10 PM   #1
papoyan
LQ Newbie
 
Registered: Feb 2008
Posts: 2

Rep: Reputation: 0
NIS password mapping question


I hoping someone can help me out here, to correct my configuration.

I have a NIS server and a web server as a client.

I have a regular linux user (without root privileges) "techsupport1" on NIS server.
On the client web server, I have root user, and my clients.

Now what I want to achieve is, allow my user "techsupport1" to access the web server, but instead of logging in using root user, I'd like the client to use username "techsupport1", but in the same time, give that user root privileges on the web server (client)

The reason, is that I have more than one user who need to manage the web server (client), so I want to be able to clearly see in the bash_history, who has been running what commands.

right now, when I login as a techsupport user to the web server (client) from my NIS server

ssh demo@webserver.com
#id
uid=517(techsupport) gid=517(clientjohn) groups=517(clientjohn)

and I don't have root privileges, also my gid is matching to gid of a customer who has the same 517 on the web server.

How can I configure, so when a tech support agent 1, logs in to web server, NIS grants root privileges, but keeps the techsupport username?

Thank you in advance,
P.S. I also setup autofs for home directory, which works just fine, the home directory of techsupport user from NIS server gets automatically mounted on web server, but the problem is the privileges, that I can't figure out how to fix.
 
Old 05-19-2010, 08:43 PM   #2
chrism01
LQ Guru
 
Registered: Aug 2004
Location: Sydney
Distribution: Rocky 9.2
Posts: 18,359

Rep: Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751
How about adding him to the webserver's group? You might need to

chmod g+s <doc root>

so that all files created in there have webserver group ownership+perms.
I assume by web root you mean web docs, not system root to admin the webserver?
 
Old 05-19-2010, 11:10 PM   #3
papoyan
LQ Newbie
 
Registered: Feb 2008
Posts: 2

Original Poster
Rep: Reputation: 0
thanks

First of all thank you for your reply.

Actually it's a production web server, and I need the support people to access pretty much everything on that server, NOT only some directories, so that's why I wanted to know, how can I have them with username "techsupport", but somehow give them UID of 0 I guess.

The goal is to be able to track each tech support agent's actions.

Thanks
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
NIS Client/Server setup... mapping Home Directories trey85stang Linux - Networking 4 01-06-2011 05:29 AM
samba mapping to NIS user PB0711 Linux - Server 2 01-30-2008 04:57 PM
Can't change NIS Password lemay_jeff Linux - Networking 1 06-29-2004 02:48 PM
UID Mapping for NFS without NIS jgombos Linux - Networking 1 07-27-2003 06:52 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 09:15 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration