LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-26-2011, 12:49 PM   #1
egyas
LQ Newbie
 
Registered: Oct 2010
Posts: 6

Rep: Reputation: 0
Unhappy sudo to Root without password


Ok, here's my situation. I'm a SA for several hundred Linux servers. One of our departments major rules is that we simply do NOT share root. PERIOD.

This has worked well, and I have been the "Great Wall of No" at work for quite some time.

However, now politics are involved. We have a couple of clusters that are running Oracle. If you're familiar with Oracle you know that it basically has to be installed as root. Something I detest. anyway, when we are building out the box, we change the root pw and give it to the DBA team to do their installs and configs. When they are done, we change the root pw (and do not give it to them), and configure sudo to allow them the rights needed to manage Oracle and their databases.

Now however, we have a different situation. The DBAs need access to uninstall and reinstall components and make modifications on an ongoing basis. Since we only support OS and hardware, not app, they are requesting permanent root access. I promptly told them no, and the politics ensued. Their manager went to their director, who went to my director, and suddenly an exception is given for his good golfing buddy.

So here I am, forced to turn lose DBAs on my clusters with full root access/pw. Unless you guys can help me find a *LEGAL* way to do that which I think is impossible.

I need a way to allow specific users (or perhaps a specific user group) the ability to become root WITHOUT sharing the root pw with them.

I'm screwed, aren't I?
 
Click here to see the post LQ members have rated as the most helpful post in this thread.
Old 01-26-2011, 01:27 PM   #2
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
Well to cut a long story short... use sudo. it does *exactly* what you're asking for, that's it's reason for existing. You don't use the root password in sudo, you use your own. "man sudoers" for more details.
 
Old 01-26-2011, 01:28 PM   #3
AlucardZero
Senior Member
 
Registered: May 2006
Location: USA
Distribution: Debian
Posts: 4,824

Rep: Reputation: 615Reputation: 615Reputation: 615Reputation: 615Reputation: 615Reputation: 615
use sudo.

Note: sudo CAN be configured to ask for the root password, but only SLES 10 does that by default (which you can change). Everybody else asks for the user's password.
 
Old 01-26-2011, 07:14 PM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Next to practical Sudo usage I would like to point out the benefit of having an isolated staging area: it may allow you to recover more easily from breakage, monitor (ab)use and track completed RFC's. You then transfer those to the separate production environment only you have access to.
 
2 members found this post helpful.
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Sudo Password for Root, not Going? Novatian Fedora 12 11-10-2010 02:16 AM
sudo non-user/non-root password Alex_Dc Linux - Security 3 02-19-2010 06:28 PM
my sudo password is not the root password newbiesforever Linux - General 7 01-02-2010 09:59 PM
sudo - root password not working Valkyrie_of_valhalla Linux - Software 3 03-11-2007 01:01 PM
root password doesn't work when I use sudo ... bucovaina78 Linux - Security 5 11-10-2004 02:50 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:49 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration