public inbox for gentoo-user@lists.gentoo.org
 help / color / mirror / Atom feed
From: Neil Bothwick <neil@digimed.co.uk>
To: gentoo-user@lists.gentoo.org
Subject: Re: [gentoo-user] Block root user from login on xorg GUI
Date: Sun, 15 Nov 2009 13:37:41 +0000	[thread overview]
Message-ID: <20091115133741.601d0f24@digimed.co.uk> (raw)
In-Reply-To: <200911151252.41474.alan.mckinnon@gmail.com>

[-- Attachment #1: Type: text/plain, Size: 697 bytes --]

On Sun, 15 Nov 2009 12:52:41 +0200, Alan McKinnon wrote:

> > Why not use sudo to give the customer's account almost full root
> > access? Not only does this allow you to restrict which damaging
> > commands he can run but sudo logs each command it runs, so you have
> > CYA insurance.  
> 
> Double CYA insurance:
> 
> Send all logs to a remote syslog server. The user with sudo permissions
> can still disable logging, but you have untouchable evidence that he
> did :-) 

That's one approach. The other is to give sudo access only for what he
needs, which doesn't include disabling logging or many other things.


-- 
Neil Bothwick

Top Oxymorons Number 39: Almost exactly

[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 198 bytes --]

  reply	other threads:[~2009-11-15 14:08 UTC|newest]

Thread overview: 35+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2009-11-12 20:01 [gentoo-user] Block root user from login on xorg GUI Mick
2009-11-12 20:39 ` Dirk Heinrichs
2009-11-12 20:56   ` Mick
2009-11-12 21:08     ` Dirk Heinrichs
2009-11-12 21:34 ` Paul Hartman
2009-11-12 21:46   ` Mick
2009-11-12 21:56     ` Alan McKinnon
2009-11-12 22:15       ` Mick
2009-11-13 15:39     ` Paul Hartman
2009-11-12 22:09 ` Alan McKinnon
2009-11-12 22:18   ` Mick
2009-11-12 23:08     ` Iain Buchanan
2009-11-13  2:45       ` Zeerak Waseem
2009-11-14  0:24       ` Mick
2009-11-14  7:01         ` Joshua Murphy
2009-11-14  7:07           ` Joshua Murphy
2009-11-14 19:32           ` Mick
2009-11-14 20:46             ` Alan McKinnon
2009-11-15  5:15               ` Stroller
2009-11-15  7:44                 ` Dale
2009-11-15  8:26                 ` Alan McKinnon
2009-11-15 12:47                   ` Stroller
2009-11-15 15:11                     ` Alan McKinnon
2009-11-15  8:52                 ` Neil Bothwick
2009-11-15 10:52                   ` Alan McKinnon
2009-11-15 13:37                     ` Neil Bothwick [this message]
2009-11-14  9:21 ` [gentoo-user] " Nikos Chantziaras
2009-11-14 10:12   ` Dirk Heinrichs
2009-11-14 15:13     ` Nikos Chantziaras
2009-11-14 19:30       ` Alan McKinnon
2009-11-14 20:46       ` Dirk Heinrichs
2009-11-14 22:50         ` Alan McKinnon
2009-11-15  9:22           ` Dirk Heinrichs
2009-11-15 14:40             ` Nikos Chantziaras
2009-11-15 16:12               ` Alan McKinnon

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20091115133741.601d0f24@digimed.co.uk \
    --to=neil@digimed.co.uk \
    --cc=gentoo-user@lists.gentoo.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox