1 |
On Sun, 15 Nov 2009 12:52:41 +0200, Alan McKinnon wrote: |
2 |
|
3 |
> > Why not use sudo to give the customer's account almost full root |
4 |
> > access? Not only does this allow you to restrict which damaging |
5 |
> > commands he can run but sudo logs each command it runs, so you have |
6 |
> > CYA insurance. |
7 |
> |
8 |
> Double CYA insurance: |
9 |
> |
10 |
> Send all logs to a remote syslog server. The user with sudo permissions |
11 |
> can still disable logging, but you have untouchable evidence that he |
12 |
> did :-) |
13 |
|
14 |
That's one approach. The other is to give sudo access only for what he |
15 |
needs, which doesn't include disabling logging or many other things. |
16 |
|
17 |
|
18 |
-- |
19 |
Neil Bothwick |
20 |
|
21 |
Top Oxymorons Number 39: Almost exactly |