Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Partially restricting root access

Status
Not open for further replies.

phorbiuz

Technical User
Jul 22, 2004
67
0
0
GB
Hi all

One of our customers has a number of AIX 5.3 TL9 lpars. Access is via ssh only, and by default I'd like to deny direct root access. People would log in as themselves before su'ing to root. Pretty standard stuff really.

This would be done in the /etc/ssh/sshd_config file by enabling the 'PermitRootLogin no' line.

However our DBA's insist that, for Oracle RAC using GPFS (General Parallel File System), we have to have direct root login allowed.

This is against my better judgement as we have no accountability of who was logged in as root. Does anyone know of a way to have direct root login disabled, UNLESS the session is initiated by the other node in the cluster?

Thanks.

 
You can write a login script that will disable (deny) direct root access.

Regards,
Khalid
 
I know nothing about GPFS, but "PermitRootLogin no" is only for direct logins over ssh. I don't see how it would affect it. Are your dba's talking about rlogin?
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top