1 |
On Mon, 1 Mar 2010 01:07:21 +0200, Alan McKinnon wrote: |
2 |
|
3 |
> Don't read my post as literally meaning they must type the 7 characters |
4 |
> "sudo su". Read it more as "use any feature of sudo you feel like to |
5 |
> get a root shell, but you must use sudo. As opposed to using su alone". |
6 |
|
7 |
The problem with this in your situation is that you only get a log entry |
8 |
when the user switches to root, not for whatever they do in that root |
9 |
shell, whereas having them run each command with sudo logs every action |
10 |
they take as root. Or do you have a way of auditing the commands run from |
11 |
the root shell? |
12 |
|
13 |
|
14 |
-- |
15 |
Neil Bothwick |
16 |
|
17 |
Press button to test: release to detonate. |