Re: login as 'root' vs 'su root'

From: Green, Simon (Simon.Green_at_EU.ALTRIA.COM)
Date: 06/07/04

  • Next message: Leyden, Joseph: "Re: login as 'root' vs 'su root'"
    Date:         Mon, 7 Jun 2004 20:00:57 +0200
    To: aix-l@Princeton.EDU
    
    

    Audit trail. It's particularly important if you've got people logging in
    from PCs or workstations using DHCP, which can make it very tough to
    identify which individuals are actually logged in.

    It also helps to prevent files building up in /, if administrators have
    their own smit.* and history. (Though that can be alleviated by giving root
    a proper home directory.)

    There's something to be said for permitting local logins by root, on the
    main console but nowhere else.

    The only disadvantage is that administrators have to take the extra time to
    login then su. That's trivial, and vastly outweighed by the audit
    advantages.

    It's theoretically possible that under some bizarre circumstances a login as
    root will work when one by a normal user will not. I can't remember this
    happening except when non-standard authentication methods were being used:
    BoKS/Keon in our case, and then it was easy enough to work round the problem
    without resorting to a direct login as root.

    What we used to do was bar all direct logins as root, but have a second UID
    0 user, with a secret password, known to no man. (Get one person to enter
    half the password and write it down; fold the paper over to cover that and
    get someone else to enter the second half. Seal it in an envelope and put
    it in a secure location. This also has to be audited periodically. You
    also need to audit and report on any attempted logins by this emergency
    userid, so it helps if you're running the audit system in stream mode,
    generating alerts somewhere.)

    --
    Simon Green
    Altria ITSC Europe Ltd
    AIX-L Archive at https://new-lists.princeton.edu/listserv/aix-l.html
    New to AIX? http://publib-b.boulder.ibm.com/redbooks.nsf/portals/UNIX
    N.B. Unsolicited email from vendors will not be appreciated.
    Please post all follow-ups to the list.
    > -----Original Message-----
    > From: Leyden, Joseph [mailto:LeydenJ@METRO.NET]
    > Sent: 07 June 2004 18:29
    > To: aix-l@Princeton.EDU
    > Subject: login as 'root' vs 'su root'
    >
    >
    > What's the major difference?
    > advantages/disadvantages?
    

  • Next message: Leyden, Joseph: "Re: login as 'root' vs 'su root'"

    Relevant Pages

    • Re: Help with audit/password needs on Solaris 8
      ... > consecutive unsuccessful attempts to login. ... But the disabling works for "root" as well as any other ... We run a minimal auditing and repeated unsuccessful attempts will ... See the man page on "audit" to learn how to enable, control, and process ...
      (comp.unix.solaris)
    • SUMARY: Cant login as root
      ... As a result, i was not able to log in as root, neither create a new ... Asunto: RE: Can't login as root ... > console. ... > If we log as any other user everythig is ok, but we cannot either do su-. ...
      (Tru64-UNIX-Managers)
    • RE: Urgent help needed with Login problems after installation of FC1
      ... symptom trying to su back to root. ... After another minimal install, I was able to add my user and su to it and su ... I was unable to boot using the boot floppy. ... I did a minimal install and was able to login as root, ...
      (Fedora)
    • Re: BSM, SSH, and Session ID
      ... Are you logging in as root through ssh or is that just the way it is ... Sun SSH/OpenSSH should fork off before the login because the sshd ... It should always be a different session, ...
      (Focus-SUN)
    • Re: Urgent help needed with Login problems after installation of FC1
      ... login would do anything but loop back to the Login: ... >From Gnome desktop, I was able to logout user, login root, over and ... Am able to boot from floppy. ... >After another minimal install, I was able to add my user and su to ...
      (Fedora)