nv-l

[nv-l] Root Authority

2002-06-27 19:05:39
Subject: [nv-l] Root Authority
From: "Gavin Newman" <NEWMANGJ AT banksa.com DOT au>
To: <nv-l AT lists.tivoli DOT com>
Date: Fri, 28 Jun 2002 08:35:39 +0930
Leslie

In your second paragraph you say that sites add a "non-root user with a uid of 
0"

They should be aware that it is not the name "root" that has the magic powers 
but the uid number 0. You can have any number of names, each with a UID of 0, 
and they all have "root power" so if the sites you refer to think they have 
circumvented the root "problem" then they are probably in for a surprise....

Cheers - Gavin

>>> "Leslie Clark" <lclark AT us.ibm DOT com> 27/06/2002 21:27:07 >>>
Of the one hundred or so sites where I have implemented Netview, I have
encountered only three that absolutely would not give root to the Netview
administrator. In all three cases those customers followed a policy of
pushing out a common /etc/passwd file to all AIX systems, so a common
root password was in use for all systems.  Not a fashionable approach,
but not all that uncommon.

Some sites add a non-root userid with an effective uid of 0, allowing
most function without the user needing to know root's password. I have
not seen this lately and don't know what the limitations might be if any.
The sudo approach is pretty common and seems to work well.

Many sites with strict AIX support teams simply opt out of AIX support.
They would rather go it alone than put up with the delays involved in
getting someone to come over and type something in for them.

I personally always put it right in the contract that I will have root
access
while I am onsite implementing Netview. Time is money, after all.

Cordially,


<Prev in Thread] Current Thread [Next in Thread>