OT? Philosophical Question on SA responsibilities

From: Bruntel, Mitchell L, ALABS (mbruntel_at_att.com)
Date: 01/30/04

  • Next message: Miller Alan: "SunFire 6800/15K How many CPUs"
    Date: Fri, 30 Jan 2004 08:46:53 -0600
    To: <sunmanagers@sunmanagers.org>
    
    

    Here's a question for other administrators:

    Question:
    Presume the following:
    15 remotely located machines (all solaris)
    3 people allowed to use root password.

    New admin joins group.
    Told to install XYZ software on machines.
    Told Reboot, if necessary is ok.
    Told install ok to install additional pre-requisites if needed...

    OH, and there are NO users on the box, just those administrators.

    Here are the questions:
    As a experienced SA logging into the machine for the first time:

    a) would you go thru the 14,600 messages in root and admin mailboxes,
    and delete them?
    b) Would you presume your charge also includes "doing the right thing"
    to tighten the security on the box?
    c) If you do b, and find security vulnerabilities, would you shut them
    down, (fix them directly), or ask for permission to fix them.
    d) if you presume b, is correct, would you install a cron job that does
    the following?
             for all id's on system: do
            1) passwd -s userid (gets user password status
    (locked/nopassword,etc)
            2) crontab -l userid (sees if user is in cron.allow, deny, etc.)
            3) Log results to a file in /var/adm, automatically by day
    date/month/year (creating directories as necessary.

    Thanks: I'll summarize.
    PS: want the script? Email me. It's saved me a few times, and found a
    few unauthorized things in the past!
    _______________________________________________
    sunmanagers mailing list
    sunmanagers@sunmanagers.org
    http://www.sunmanagers.org/mailman/listinfo/sunmanagers


  • Next message: Miller Alan: "SunFire 6800/15K How many CPUs"

    Relevant Pages

    • Re: Licence caanot be authorised on new PC
      ... Microsoft has no de-activation system. ... install it on another computer. ... Office 2007 Ultimate working correctly on 3 machines, ... Can you please definitively clarify whether the licence covers 2 or 3 ...
      (microsoft.public.office.misc)
    • Re: Probes on Port 135 and 445 continue
      ... The house has a slow DSL connection, ... We removed more than 3000 viruses from their machines when they arrived ... about it, and you have to believe you need it, to install it. ... virus spammer infection - sending about 250 email's out from 6 infected ...
      (comp.security.misc)
    • Re: Firewall Suggestions
      ... > likely run into the same thing with most of the personal firewalls. ... I had ZA installed on all 3 machines. ... I still, however, have the install files, I suppose I could ... remove completely and reinstall clean because the ...
      (comp.security.firewalls)
    • Re: Probes on Port 135 and 445 continue
      ... The house has a slow DSL connection, ... We removed more than 3000 viruses from their machines when they arrived ... about it, and you have to believe you need it, to install it. ... virus spammer infection - sending about 250 email's out from 6 infected ...
      (comp.security.unix)
    • Re: Will .NET 2.0 Windows Services run under Windows 2000?
      ... Service, written in C# and .NET 2.0, that would install and run fine, on ... some machines, and would install, but would hang on startup, on other ... class SimpleService: ServiceBase ... protected override void OnStop() ...
      (microsoft.public.dotnet.framework.aspnet)