Uploaded image for project: 'Instrument control development'
  1. Instrument control development
  2. INSTRM-502

Settle on emergency and root access to pfs hosts

    XMLWordPrintable

    Details

    • Type: Task
    • Status: Open (View Workflow)
    • Priority: Normal
    • Resolution: Unresolved
    • Component/s: None
    • Labels:
      None

      Description

      As it stands, the pfs user at Subaru is not authenticated though LDAP, but though /etc/

      {passwd,group}

      . The ids do match (2085:2085).

      The reasoning is that we need some "emergency" login which depends as little as possible on network infrastructure. From that account, one can sudo.

      I, personally, do not like this. I believe we should allow remote root ssh logins (key only), and have the pfs user be like all others. If there is a problem bad enough that LDAP is not available, you want to do any work as root in any case. Requiring sudo with a password decreases security.

      Discuss. Decide.

        Attachments

          Activity

            People

            • Assignee:
              Unassigned
              Reporter:
              cloomis cloomis
            • Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

              • Created:
                Updated: