Re: root password and su (maybe)

From: Gordon Messmer (yinyang_at_eburg.com)
Date: 09/11/03

  • Next message: Jack Byers: "Re: Prefered backup method?"
    To: redhat-list@redhat.com
    Date: Thu, 11 Sep 2003 12:23:30 -0700
    
    

    Kelerion wrote:
    > small world.. you must know my boss.. a) describes him perfectly!! :)
    >
    > whats even more ironic.. is when I approached him about this.. he said
    > "but changing the password on a regular basis sounds like a good idea
    > for security.."

    My suggestion to appease your "security minded" boss:

    Configure SSH to allow only key-authenticated logins. Once you've done
    so, the root password is useless for anything except logins at the
    physical console (at least, that's so unless you've done something else
    to weaken security) and "su". You can also change "su"s pam
    configuration if you don't trust users who have ssh access, and don't
    want the root password to work with that command either (there's an
    example in the default file that will restrict access to users in the
    "wheel" group, like most other Unix systems)

    With the root password only useful at the physical console, your weak
    point becomes the physical access to the box, and you can mostly
    disregard your root password as a security concern. (Be absolutely
    certain that all of your pam configurations prevent root logins, except
    for the "login" program)

    -- 
    redhat-list mailing list
    unsubscribe mailto:redhat-list-request@redhat.com?subject=unsubscribe
    https://www.redhat.com/mailman/listinfo/redhat-list
    

  • Next message: Jack Byers: "Re: Prefered backup method?"

    Relevant Pages

    • ssh in a script? (auto-send the password) WITHOUT expect / public keys
      ... root password in a browser and hit submit, this will then use php to spawn ... a bash script that calls a perl command that uses the ... are there any other options to send a password to ssh in a scripted ... and please save your lectures on security for someone ...
      (comp.unix.shell)
    • Re: su password
      ... It is not the canonical way because it is attrocious from a security point ... You are placing your root password into a file readable by an ... ssh root@ ...
      (comp.os.linux.misc)
    • Re: Need urgent help regarding security
      ... There is plenty of security info out there ... email from even a dozen servers is small. ... an OS version upgrade should not be taken lightly. ... Given that your root password was apparently found on the servers, ...
      (freebsd-questions)
    • [NEWS] Cisco MARS Default Administrative Password
      ... Get your security news from a reliable source. ... Analysis and Response System (CS-MARS) is "a ... password set for the undocumented administrative account root". ... combined with a Cisco controlled component to form a new root password. ...
      (Securiteam)
    • Re: Running top without a shell -- more questions
      ... there are HUGE security concerns. ... But it's shell escapes that generally create the security concerns, ... I am not suggesting changing the standard software! ... J> top on the ttyv on which logins are no-longer allowed. ...
      (freebsd-questions)