[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: sudoers - permettere comando user@host



On Mon, 14 Feb 2011 08:03:50 +0000 (UTC), hjubal wrote:

> Da "hosta" mi autentico con certificato su "hostb" ed eseguo il seguente 
> comando:
> 
>   backuppc@hosta:~$ /usr/bin/ssh -q -x -n -t -l backuppc hostb \
>   /usr/bin/sudo /bin/tar
> 
> Se su "hostb" configuro '/etc/sudoers' cosi', in modo tale da permettere 
> l'esecusione di '/bin/tar' solo per 'backuppc@marte':
> 
>   User_Alias      BACKUPUSERS, backuppc
>   Host_Alias      BACKUPSERVERS=marte, 10.1.1.134
>   Defaults visiblepw
>   BACKUPUSERS BACKUPSERVERS=(ALL) NOPASSWD: /bin/tar
> 
> ottengo:
> 
>   backuppc@marte:~$ /usr/bin/ssh -q -x -n -t -l backuppc ldp038 /usr/bin/
> sudo /bin/tar
>   [sudo] password for backuppc: Sorry, try again.
>   [sudo] password for backuppc: Sorry, try again.
>   [sudo] password for backuppc: Sorry, try again.
>   sudo: 3 incorrect password attempts

Direi che BACKUPSERVERS dev'essere "hostb", non "marte" (o "hosta", a quanto ho
capito).

Prova, e facci sapere ;)

Ciao,
David

-- 
 . ''`.   Debian developer | http://wiki.debian.org/DavidPaleino
 : :'  : Linuxer #334216 --|-- http://www.hanskalabs.net/
 `. `'`  GPG: 1392B174 ----|---- http://deb.li/dapal
   `-   2BAB C625 4E66 E7B8 450A C3E1 E6AA 9017 1392 B174

Attachment: signature.asc
Description: PGP signature


Reply to: