[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Single-use root account?



On Fri, 2003-11-07 at 09:30, Tom wrote:
> * [07/11/2003 16:25] J. Bruce Fields <bfields@fieldses.org>:
> 
> > > The all-privilege sudo is the best idea, since the actions are
> > > audited.
> > 
> > Though note that the auditing is there to keep the honest honest--surely
> > the audit trail isn't truly secure against an user with "all-privilege
> > sudo". 
> 
> Also, I read the word(s) "single-use" in the subject line as "one-time
> use". Not sure if that's what he meant, but if it is, I guess sudo isn't
> exactly what he wanted either.

The OP can enable sudo privs only when he's going to be gone for
any appreciable amount of time.

-- 
-----------------------------------------------------------------
Ron Johnson, Jr. ron.l.johnson@cox.net
Jefferson, LA USA

"Python is executable pseudocode; Perl is executable line noise"



Reply to: