Re: ACL



There are other ways of doing this than what has been discribed.

Have you not heard of a "secure network".

I know; I work at such a place.

Even on the "secure network", the sysadmins have tremendous access
privileges.

And they can make more privileges for themselves if needed or wanted.


Your response to my comment appears to be theoretical and doesn't fly in the
real world that I inhabit.


If you look at the recommendations for setting up a "business"secure Oracle
Financials environment (devlopment, disaster recovery, production) you will
gain insights about practical security.


Even in a "secure network", respect is paramount. Respect and trust are two
of the essentials in creating a "secure" anything.

If you distrust your people, either quit (the preferred option) or fire your
people.
If you don't respect your people, you have bigger problems than simple
"security".



On Mon, Jul 28, 2008 at 11:19 AM, Laszlo BERES <beres.laszlo@xxxxxxxxxxxx>wrote:

hike wrote:

It is unethical for sysadmins to access this data without a specific
reason
and approval.
If you cannot trust your sysadmins to act in an ethical fashion, YOU have
screwed up big-time.

YOU hire trustworthy people.
YOU train trustworthy people.


Well, you're right, but imagine a world, where your sysadmins _cannot_
access the data for legal or national security or other reasons. There's no
place for trustworthiness or 'I swear I won't touch anything', you _have_ to
restrict the access rights.

--
Laszlo BERES RHCE, RHCX
senior IT engineer, trainer

--
redhat-list mailing list
unsubscribe mailto:redhat-list-request@xxxxxxxxxx?subject=unsubscribe
https://www.redhat.com/mailman/listinfo/redhat-list

--
redhat-list mailing list
unsubscribe mailto:redhat-list-request@xxxxxxxxxx?subject=unsubscribe
https://www.redhat.com/mailman/listinfo/redhat-list



Relevant Pages

  • Re: What security package for SBS?
    ... I have a secure Windows network. ... I also have a secure MacMini and on occasion a secure Ubuntu. ... With a business class firewall stripping crap off all incoming traffic and properly implemented security policies in addition to giving your users absolutely no admin rights, there is no reason to believe you can't create a secure Microsoft Network. ...
    (microsoft.public.windows.server.sbs)
  • Re: Wifi Security
    ... Then add in good practices and secure those endpoints! ... I have changed the security to WPA2 with a 128bit ... and attempt to break into her wireless internet connection. ... part of her network cannot do WPA2 but you actually want her network to ...
    (microsoft.public.security)
  • RE: One computer two different networks
    ... Internet connection and one an internal secure connection tempts one ... You have a private network with no Internet for the reason that you ... in Information Security. ...
    (Security-Basics)
  • RE: Business Thoughts
    ... We work in a very secure network with unbelievable constraints. ... online retail business because of "security." ... and very limited internet site exploration. ...
    (microsoft.public.windowsxp.network_web)
  • Re: Questions on secure remote access to Fedora Core 2
    ... not secure at all, because hostnames can be forged. ... The users should generate themselves key pairs for SSH access. ... on the server, work on it, and then send it back. ... Linux-based, then Network Block Devices are a good idea, too. ...
    (comp.os.linux.security)