LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 03-23-2016, 10:25 PM   #1
asteroid4u
Member
 
Registered: Jun 2015
Posts: 58

Rep: Reputation: Disabled
Restrict su from root to NIS user account


Hi,

We are using NIS services for users login for Unix accounts. We have test machines where users itself install OS and they get root access. Users are using su from root account to NIS user accounts without Passwords they are able to enter other NIS accounts easily. Is there any way we restrict this option? I don't want allow any root user to login other users nis account.
 
Old 03-24-2016, 04:23 AM   #2
pan64
LQ Addict
 
Registered: Mar 2012
Location: Hungary
Distribution: debian/ubuntu/suse ...
Posts: 21,782

Rep: Reputation: 7304Reputation: 7304Reputation: 7304Reputation: 7304Reputation: 7304Reputation: 7304Reputation: 7304Reputation: 7304Reputation: 7304Reputation: 7304Reputation: 7304
do not use nis on those hosts.
 
Old 03-24-2016, 10:36 PM   #3
asteroid4u
Member
 
Registered: Jun 2015
Posts: 58

Original Poster
Rep: Reputation: Disabled
Hi Pan,

We can do it but they need to mount their home directories for testing their applications that is the challenge. Moreover Users knows NIS server IP they itself configure it.

Thanks,
 
Old 03-25-2016, 01:07 AM   #4
pan64
LQ Addict
 
Registered: Mar 2012
Location: Hungary
Distribution: debian/ubuntu/suse ...
Posts: 21,782

Rep: Reputation: 7304Reputation: 7304Reputation: 7304Reputation: 7304Reputation: 7304Reputation: 7304Reputation: 7304Reputation: 7304Reputation: 7304Reputation: 7304Reputation: 7304
looks like what you want is not possible. Either you give them full access or not, but root cannot be restricted. You can configure nis to not allow those test servers to join (or even more secure to put test servers behind a firewall) and you can mount one single drive which is accessible from anywhere. So users can copy their stuff onto that central disk and that will be available on test machines too (or you can try sshfs, rsync or whatever you prefer)
 
Old 03-26-2016, 10:30 AM   #5
asteroid4u
Member
 
Registered: Jun 2015
Posts: 58

Original Poster
Rep: Reputation: Disabled
Hi Pan,

At least can we enable password when adding client to NIS server. I mean even though users has local root access when adding test machine to NIS server. It has ask password. So this way we can protect atleast.

Thanks
 
  


Reply

Tags
authentication, linux, nis, root, sudo


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] SSH - How can I only allow a key pair login for my user account not root account? shanekelly Linux - Security 5 01-25-2013 09:45 AM
restrict root account mr_aliagha Linux - Security 13 07-20-2011 10:19 AM
how to restrict a user in NIS from logging on to a particular server dbmacartney Linux - Server 6 07-28-2010 08:31 AM
is it legitimate and allowed and can be done to make another user account set uid and gid to null 0 to make another root account with different name and possibly not damage the debian system creating and using that new account BenJoBoy Linux - Newbie 12 01-29-2006 10:02 AM
restrict ssh logins by ip by user account Beans0063 Linux - Security 4 10-04-2004 01:29 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 07:37 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration