LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-25-2006, 05:10 AM   #1
rblampain
Senior Member
 
Registered: Aug 2004
Location: Western Australia
Distribution: Debian 11
Posts: 1,288

Rep: Reputation: 52
root issues on multi lan/wan set up


Setting up computers scattered over the globe, in LAN, WAN etc.
The need seems to be to have one super "root" (and a delegate or deputy) who has access to everything and local "root" (and a delegate as above) who has access to local machines etc.

This could get rather complex and I wonder if there is anybody who could have advices or advise good material to learn from. It seems the usual permissions wouldn't really solve this problem.

What I probably need is some broad ideas as I cannot visualize a solution easily. I know of the existence of ACL but I'm not sure if it's the answer or not.

Thank you for your help
 
Old 05-25-2006, 10:16 AM   #2
MensaWater
LQ Guru
 
Registered: May 2005
Location: Atlanta Georgia USA
Distribution: Redhat (RHEL), CentOS, Fedora, CoreOS, Debian, FreeBSD, HP-UX, Solaris, SCO
Posts: 7,831
Blog Entries: 15

Rep: Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669
Does everyone actually need full root access? You may wish to explore the use of "sudo". This allows you to grant access to users to run apps as root without actually giving them the root password. Another benefit is it logs everything so you can later see who did what if something goes wrong.

If you do need full root access a couple of ideas:
1) Create a "Security Server" to which only the global and his delegate have access. On this make everything secure and put an encrypted file (vim -x filename) that has the passwords for all systems. (We did this at one place I worked.)

2) Use a common root phrase that is modified based on location or machine name (insuring only the global and the delegate know this is the method). Give the root password to each local and delegate only for their location.
Example:
common component: Pap3r
local identifier: First letter of city, First letter of country.

Password for Syndney Australia would be sPap3ra.
Pasword for New York City USA would be nPap3ru.
Password for Rio De Janeiro Brazil would be rPap3rb.
Password for Nairobi Kenya would be nPap3rk.

Very easy to remember for everyone involved. It is possible you'd end up with duplicates but they wouldn't be everywhere so it would be happenstance for someone to get to the right one unless they knew the local identifier methodology - that's why you restrict the knowledge of the methodology to the global and his delegate. You can make it even less likely by choosing something less obvious but easy for you to remember.

Last edited by MensaWater; 05-25-2006 at 10:17 AM.
 
Old 05-26-2006, 04:21 AM   #3
rblampain
Senior Member
 
Registered: Aug 2004
Location: Western Australia
Distribution: Debian 11
Posts: 1,288

Original Poster
Rep: Reputation: 52
Thank you for your answer, a combination of "sudo" and passwords as you describe sounds like a good solution.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LAN but no WAN BCarey Linux - Networking 4 05-07-2006 12:24 PM
open source multi-WAN router lothario Linux - Networking 3 11-24-2005 05:31 AM
2 routers WAN, LAN could you please tell me... microsmart Linux - Networking 5 08-06-2005 01:17 PM
Routing LAN -> WAN -> LAN with unhelpful router synx13 Linux - Networking 2 06-14-2004 02:35 PM
LAN works, WAN doesn't ? BrianK Linux - Networking 2 06-16-2003 07:11 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:08 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration