Great Circle Associates Firewalls
(August 1994)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: root account and routine work
From: Ron Kuris <rk @ Unify . Com>
Date: Tue, 23 Aug 94 18:45:25 -0700
To: Firewalls @ greatcircle . com

For root work behind a firewall, we use 'priv'.  It gives someone
root access for one command (an alternative to 'sudo' I believe).

It originally appeared in Unix World back in 1988.  If anyone
wants it, I just uploaded the current copy to
ftp.unify.com:/ietf/etc/priv.c
(you may also want priv.fig and priv.txt for an explanation).

The nice thing about this is that it keeps a log file of all the
commands you run, so when you have a big mix between SA and
engineers who want/need root access and you want to find the
last user who changed /etc/rc (grep 'vi /etc/rc' /etc/priv.log).

Of course, I wouldn't use this on a firewall.  And I would
discourage using it on machines with high security requirements.
But it's great for a single-user system or low-security hub.


Follow-Ups:
Indexed By Date Previous: .
From: Sean . Reigle @ f203 . n103 . z1 . fidonet . org (Sean Reigle)
Next: Re: Hacker Site List
From: strick @ netcom . com (henry strickland -- strick @ netcom . com)
Indexed By Thread Previous: Re: root account and routine work
From: tog @ lan . nsc . com (Todd Glassey - Lan Systems Administrator )
Next: Re: root account and routine work
From: Steve Simmons <scs @ lokkur . dexter . mi . us>

Google
 
Search Internet Search www.greatcircle.com