Re: manager sudo file

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



That you for your suggestions.  I didn't know I could use NIS for sudo, had never thought of it.  Most of the sites I support use NIS while others use local accounts.  I would like to LDAP but it left a bad taste the last time I used it, HP-UX 10.20 and LDAP to NIS gateways don't work very well, at least they didn't 3 years ago.

Have any advice for using LDAP to manage sudo (privileged) access?



On Mon, Mar 15, 2010 at 6:06 PM, Rick Stevens <ricks@xxxxxxxx> wrote:
On 03/15/2010 04:04 PM, Tom H wrote:
>>> Rather than create different /etc/sudoers for each box, can't you use
>>> a name service (with>1500 boxes you must already have one running)
>>> and set up netgroups for users, commands, boxes, and auths?
>
>> Yes, name service (DNS) is running but not supported by my department.
>> This infrastructure has grown into what it is now for long time. I am
>> trying to straighten it out.
>
> By "name service," I meant NIS, NIS+, LDAP.

I second that.  You have to join the 21st century sometime.  LDAP is
a good choice AND you can manage the sudo file from it as well (a thing
I've found VERY useful).

NIS was invented by Sun, NIS+ expanded upon it.  Almost all Unixish
systems will support NIS/NIS+.  Most will support LDAP (Solaris, Linux,
FreeBSD, HP/UX for sure).
----------------------------------------------------------------------
- Rick Stevens, Systems Engineer, C2 Hosting          ricks@xxxxxxxx -
- AIM/Skype: therps2        ICQ: 22643734            Yahoo: origrps2 -
-                                                                    -
- If at first you don't succeed, quit. No sense being a damned fool! -
----------------------------------------------------------------------



--
Jamie Bohr
-- 
users mailing list
users@xxxxxxxxxxxxxxxxxxxxxxx
To unsubscribe or change subscription options:
https://admin.fedoraproject.org/mailman/listinfo/users
Guidelines: http://fedoraproject.org/wiki/Mailing_list_guidelines
[Index of Archives]     [Older Fedora Users]     [Fedora Announce]     [Fedora Package Announce]     [EPEL Announce]     [Fedora Magazine]     [Fedora News]     [Fedora Summer Coding]     [Fedora Laptop]     [Fedora Cloud]     [Fedora Advisory Board]     [Fedora Education]     [Fedora Security]     [Fedora Scitech]     [Fedora Robotics]     [Fedora Maintainers]     [Fedora Infrastructure]     [Fedora Websites]     [Anaconda Devel]     [Fedora Devel Java]     [Fedora Legacy]     [Fedora Desktop]     [Fedora Fonts]     [ATA RAID]     [Fedora Marketing]     [Fedora Management Tools]     [Fedora Mentors]     [SSH]     [Fedora Package Review]     [Fedora R Devel]     [Fedora PHP Devel]     [Kickstart]     [Fedora Music]     [Fedora Packaging]     [Centos]     [Fedora SELinux]     [Fedora Legal]     [Fedora Kernel]     [Fedora OCaml]     [Coolkey]     [Virtualization Tools]     [ET Management Tools]     [Yum Users]     [Tux]     [Yosemite News]     [Gnome Users]     [KDE Users]     [Fedora Art]     [Fedora Docs]     [Asterisk PBX]     [Fedora Sparc]     [Fedora Universal Network Connector]     [Libvirt Users]     [Fedora ARM]

  Powered by Linux