The UNIX and Linux Forums  

Go Back   The UNIX and Linux Forums > Top Forums > UNIX for Advanced & Expert Users
Google UNIX.COM


UNIX for Advanced & Expert Users Advanced UNIX and Linux questions go here. Expert-to-Expert.

More UNIX and Linux Forum Topics You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
sudoers tjmannonline UNIX for Dummies Questions & Answers 4 05-13-2008 06:45 PM
sudoers file questions hemangjani UNIX for Dummies Questions & Answers 2 04-21-2008 10:35 AM
sudoers on HP 11.11 dhlopomo UNIX for Dummies Questions & Answers 2 01-18-2008 03:03 AM
sudoers syntax chuckuykendall UNIX for Advanced & Expert Users 1 11-11-2005 12:22 PM
sudoers file whatisthis Linux 4 12-02-2004 02:59 PM

Reply
 
Submit Tools LinkBack Thread Tools Search this Thread Display Modes
  #1  
Old 04-04-2008
Registered User
 

Join Date: May 2007
Location: Roanoke, VA
Posts: 11
Sudoers problems.

Hi!

I'm trying to come up with a way for me to automate some processes. I have to do this via ssh. What I'm trying to do is have "box A" connect to "box B" as "user A" and execute a command as "user B" (sudoer). It needs to be done this way because of auditing and security policy. This is on Solaris 8

Here's how I have it setup now:

Box A has connectivity to box B
User A has logins on both box A and box B
User A connects to box B from box A and sudo's to user B

Here's what I have in the sudoers file:

User_Alias USERA = userA
Cmnd_Alias SU_USERA = /usr/bin/su - userB
USERA ALL = NOPASSWD: SU_USERA


So, I connect to box A and type:
ssh -t boxB "sudo su - userB /opt/rah/rah/rah/command.sh" >> /some/log/dir

It either doesn't change the user or it asks for a password. The script keeps a log in a directory owned by userB and, if it doesn't change the user, it says "cannot create, permission denied". Otherwise it sits there asking for a password. I've tried putting the full command in sudoers and that doesn't work. Anyone have ideas? Btw, this will eventually be put under Autosys control.

Thanks!

Last edited by blane; 04-04-2008 at 10:57 AM.
Reply With Quote
Forum Sponsor
  #2  
Old 04-05-2008
RTM's Avatar
RTM RTM is offline
Hog Hunter
 
Join Date: Apr 2002
Location: On my motorcycle
Posts: 3,039
Suggest you set the log to go to a directory either user A OR user B can write to (just to get around that issue of permissions). Also, run a ssh as user A from box A to box B that doesn't run sudo to user B, just to make sure the password it's asking for isn't for the actual ssh versus the change of ID.

Try giving the full path to your su command:
change "sudo su - userB /opt/rah/rah/rah/command.sh"
to "sudo /usr/bin/su - userB /opt/rah/rah/rah/command.sh"
Reply With Quote
  #3  
Old 04-05-2008
Registered User
 

Join Date: May 2007
Location: Roanoke, VA
Posts: 11
Hi! Thanks for the response.

User A is autosys' login.
User B is weblogic.

Unfortunately the command is to start a weblogic process and, if it's started by the autosys id, it won't work correctly. The logs also have to have weblogic:bea permissions so that the weblogic group can read them.

I've also setup a ssh-key from box a to box b so that no password is needed for autosys to connect..works fine.

Sorry for not clarifying all of this earlier.

I will try the full path to su and see if that works.
Reply With Quote
  #4  
Old 04-07-2008
Registered User
 

Join Date: May 2007
Location: Roanoke, VA
Posts: 11
Okay, I got a chance to try those things and it didn't work.

If I just ssh to box b from the autosys id and then sudo from there it works wonderfully - no password needed for either.

It seems as though the problem is occurring only when you try to combine ssh, sudo and a command.

I'm stumped.
Reply With Quote
  #5  
Old 04-09-2008
Registered User
 

Join Date: Jul 2007
Posts: 110
I setup the same scenario and it worked for me on Solaris 8 but with small change.

1. Setup password-less ssh for user "user-A" from box-A to box-B

2. setup the sudoers (/usr/local/etc/sudoers as sudo installed from SMCsudo) on box-B as below:

User_Alias USERA = user-A
Cmnd_Alias SU_USERA = /bin/test_scr.sh
USERA ALL = (ALL) NOPASSWD: SU_USERA

where "/bin/test_scr.sh" would have the below line (root must be the owner of this script)

su - user-B -c "/opt/rah/rah/rah/command.sh"

3. run the below command from box-A as user user-A

ssh box-B "/usr/local/bin/sudo /bin/test_scr.sh"

Note: On box-B, /bin/test_scr.sh will be run as "root" user who in turn "su" to user-B (root -to- user-B does not require any password)

DONE

Prvn
Reply With Quote
  #6  
Old 04-09-2008
Registered User
 

Join Date: May 2007
Location: Roanoke, VA
Posts: 11
Oh man. I really wish I'd tried this when I thought of it. Instead of running a specific command via ssh you're just running a script which does all the work. I gotcha.

Trying and will let you know the results.
Reply With Quote
Google The UNIX and Linux Forums
Reply

Tags
autosys, solaris

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes




All times are GMT -7. The time now is 09:14 AM.


Powered by: vBulletin, Copyright ©2000 - 2006, Jelsoft Enterprises Limited.
The UNIX and Linux Forums Content Copyright ©1993-2008. All Rights Reserved.Ad Management by RedTyger Visit The Complex Event Processing Blog

Content Relevant URLs by vBSEO 3.2.0