1 |
On Monday 01 March 2010 03:47:12 Neil Bothwick wrote: |
2 |
> On Mon, 1 Mar 2010 01:07:21 +0200, Alan McKinnon wrote: |
3 |
> > Don't read my post as literally meaning they must type the 7 characters |
4 |
> > "sudo su". Read it more as "use any feature of sudo you feel like to |
5 |
> > get a root shell, but you must use sudo. As opposed to using su alone". |
6 |
> |
7 |
> The problem with this in your situation is that you only get a log entry |
8 |
> when the user switches to root, not for whatever they do in that root |
9 |
> shell, whereas having them run each command with sudo logs every action |
10 |
> they take as root. Or do you have a way of auditing the commands run from |
11 |
> the root shell? |
12 |
|
13 |
|
14 |
We just log the fact of running sudo. The admins are trusted to not cock |
15 |
things up, and if they do, to not try and hide it. The philosophy is simple - |
16 |
if we feel we can't trust you, we would not have hired you. |
17 |
|
18 |
Editing root's history after the fact to hide your tracks is considered a |
19 |
heinous crime of unimaginable proportions. Anyone caught doing it is sentenced |
20 |
to buy cake for the entire technical team. That's about 100 people. And when I |
21 |
saw cake I don't mean a teeny weeny jam tart each, I mean cake - chocolate |
22 |
filled croissants, black forest and my personal favourite: 4 inch high carrot |
23 |
cake. |
24 |
|
25 |
People only buy cake once around here :-) |
26 |
|
27 |
-- |
28 |
alan dot mckinnon at gmail dot com |