THIS IS ALSO POSTED IN THE SECURITY & HACKERS FORUM BUT HAD NO RESPONSE>
Hi,
Senior management wish to remove root access for everyone, including the sys admin team of which I am a member. We have,already, in recent weeks removed super-user access for the DBAs and using sudo has allowed us to do the same for the operators.
The problem we are having is trying to find a sensible way we can prevent us (the sys admins)having routine root access but still be able to manage, support and adminster the systems. They are all using Solaris 8 or 9.
Does anyone else work at a place that has managed to achieve this to any exent.
This has to happen, the directive to remove root for everyone, has come the very top! Due to a sys admin at another bank being wrongly acused of stealing but no logs to prove his innoncence!
Hi,
Senior management wish to remove root access for everyone, including the sys admin team of which I am a member. We have,already, in recent weeks removed super-user access for the DBAs and using sudo has allowed us to do the same for the operators.
The problem we are having is trying to find a sensible way we can prevent us (the sys admins)having routine root access but still be able to manage, support and adminster the systems. They are all using Solaris 8 or 9.
Does anyone else work at a place that has managed to achieve this to any exent.
This has to happen, the directive to remove root for everyone, has come the very top! Due to a sys admin at another bank being wrongly acused of stealing but no logs to prove his innoncence!