|
My customer (a bank) is happy with the following environment (AIX 5.2):
- root login is disabled
- telnet, ftp and all r-commands are disabled in /etc/inetd.conf
- sudo is used exclusively and based on groups people are allowed to do some tasks which classically are roots tasks (packaging installp-packages i.e.)
- admins (myself included) are allowed a "sudo su -" to become root
- login and file transfer solely via ssh
bakunin
|