Re: [root user] How to disable root account?

From: Maxim Vexler (hq4ever_at_gmail.com)
Date: 11/25/05

  • Next message: Rogério Brito: "Re: Debian 1.3.1 (Bo) ISO files"
    Date: Fri, 25 Nov 2005 13:33:34 +0200
    To: Robert Brockway <rbrockway@opentrend.net>
    
    

    On 11/25/05, Robert Brockway <rbrockway@opentrend.net> wrote:
    > On Thu, 24 Nov 2005, Björn Lindström wrote:
    >
    > > passwd -l simply sets the password to a value matching no
    > > passwords. sudo works by running SUID root, and so does not depend on a
    > > root password in any way.
    >
    > Actually that depends on how sudo is configured. In some configurations
    > sudo does depend on the root password (rather than the user a/c password)
    > for authentication.
    >
    > Anyone wanting to lock the root account (not a good idea IMHO) should have
    > a root enabled session (sudo, su or whatever) put to the side and not
    > touched during the procedure. This session would be used only to reverse
    > the procedure if it was found that establishing superuser privs was no
    > longer possible in new sessions.
    >
    > Rob
    >
    > --
    > Robert Brockway B.Sc. Phone: +1-416-669-3073
    > Senior Technical Consultant Email: support@opentrend.net
    > OpenTrend Solutions Ltd. Web: www.opentrend.net
    > We are open 24x365 for technical support. Call us in a crisis.
    >

    In the worst case, couldn't someone just boot from a livecd, run
    [passwd root], then [cat /etc/shadow | grep root] on the livecd and
    finally simply copying that entry into the locked out system shadow
    file ?

    --
    Cheers,
    Maxim Vexler (hq4ever).
    Do u GNU ?
    

  • Next message: Rogério Brito: "Re: Debian 1.3.1 (Bo) ISO files"

    Relevant Pages

    • Re: debian and ubuntu - answer from user not pretending to be guru
      ... convenient, for most things, and I do not like the sudo that Ubuntu uses; ... prefer su - root. ... I'm not looking to criticize your choice, but the setting on Ubuntu to lock ... If you want to use a root password on Ubuntu, ...
      (Debian-User)
    • Re: Firefox 1.5.0.7 RPM
      ... I need root password to sudo. ... because sudoers can do just as stupid things as root. ...
      (alt.os.linux.suse)
    • RE: SUDO
      ... Allowing sudo su - is a bad idea, ... If the user knows the root password, ... the user can already run the needed commands. ...
      (RedHat)
    • Re: Linux. Ubuntu using 35 GB?
      ... on a folder basis. ... sudo du> ~/myfolders.txt ... "become root". ... That would elevate that terminal session, ...
      (alt.comp.hardware.pc-homebuilt)
    • Re: su(do) while in graphical mode?
      ... I normally use sudo to avoid having to input the root ... In X desktops I would need the possibility to "launch icons" with sudo, ... I have sudo rights for them before asking for root password. ...
      (linux.redhat)