Sponsored Content
Operating Systems AIX sudo - User privilege specification Post 302587045 by zaxxon on Wednesday 4th of January 2012 03:26:29 AM
Old 01-04-2012
I guess that granularity will be not possible with sudo. sudo will be used for a positive list, what they may do, not what they may not do. You might want to have a look into RBAC (Role Based Access Control). You can create a role with just the permissions your users need and assign that to them. There are some IBM Redbooks and IBM System Magazine articles about security handling RBAC.

Last edited by zaxxon; 01-04-2012 at 05:23 AM.. Reason: typo
 

9 More Discussions You Might Find Interesting

1. UNIX for Dummies Questions & Answers

Write privilege for user

Is it possible to grant write privileges to a user on a directory with out having to add the user to a group or make the user the owner of the directory? My background is in Windows and in Windows you can grant specific privileges to a user without having to put the user in a group or making the... (3 Replies)
Discussion started by: here2learn
3 Replies

2. AIX

[Help] Give privilege to an ordinary user

I'm trying to give a non-root user the right to start IBM HTTP Server, the web server is listening on port 80, but for AIX, ports under 1024 are privilege ports which can be used only by root. /usr/IBMIHS/bin# ./apachectl start (13)Permission denied: make_sock: could not bind to address :::80... (1 Reply)
Discussion started by: ibmer414
1 Replies

3. Solaris

Root privilege for user

Can anyone please tell how to give root privilege to a normal user in solaris 10? (5 Replies)
Discussion started by: nicktrix
5 Replies

4. UNIX for Dummies Questions & Answers

How to create/restrict a user with to have no privilege from other group

Hello experts I am new to Unix. Env : HPUX I need to create a user say testuser such that it does not have access to file/directories from the other group i.e the last 3 digits . How do I do that. Reason for such a request :- I have an existing user oracle which has default umask... (3 Replies)
Discussion started by: simonsimon
3 Replies

5. AIX

User Privilege

How to assign superuser privilege to an ordinary user temporarily (1 Reply)
Discussion started by: udtyuvaraj
1 Replies

6. Red Hat

Save sudo privilege for session

I have setup public key based login to my CentOS VPS. I wish to disable direct root login and have created an admin user under wheel group and have modified /etc/sudoers file and gave Wheel group all privileges. But now I am being prompted for password whenever I type sudo. I do not wish to... (4 Replies)
Discussion started by: JoyceBabu
4 Replies

7. Cybersecurity

sudo - AIX - User privilege specification

I am planning to implement sudo for users. Under , it looks I have to put the users who need to have sudo access: What are the recommended for users? I don't think I need to give the ALL privilege (i.e ) to AIX users. I'd like to know the commonly used privilege specification for sudo... (1 Reply)
Discussion started by: Daniel Gate
1 Replies

8. Shell Programming and Scripting

Create user with different privilege

Hi , I want to create 3 different user with below privilege in Solaris and Linux. 1) Read Only 2)Read and Write Only 3) Admin user Can you guys help me on this . (3 Replies)
Discussion started by: Naveen Pathak
3 Replies

9. Solaris

Assigning proc_owner privilege to particular user in RBAC

Hi I need to assign proc_owner privilege to particular user through RBAC. How can I assign this privilege to user, I need help on this. Further I need to understand if I give this proc_owner privilege to particular user, what kind of control user will get on other user or system processes... (7 Replies)
Discussion started by: sb200
7 Replies
scprivipadm(1M) 					  System Administration Commands					   scprivipadm(1M)

NAME
scprivipadm - administer the private IP address range SYNOPSIS
scprivipadm -c netaddr=netaddr[,netmask=netmask] scprivipadm -c netaddr=netaddr[,maxnodes=nodes,maxprivatenets=privnets] scprivipadm -c netaddr=netaddr[,netmask=netmask,maxnodes=nodes,maxprivatenets=privnets] scprivipadm -p scprivipadm -R DESCRIPTION
Note - Beginning with the Sun Cluster 3.2 release, Sun Cluster software includes an object-oriented command set. Although Sun Cluster software still supports the original command set, Sun Cluster procedural documentation uses only the object-oriented command set. For more infor- mation about the object-oriented command set, see the Intro(1CL) man page. The scprivipadm command modifies the current IP address range that is assigned to the Sun Cluster private interconnect. All nodes in the cluster must be in noncluster mode before you run any form of this command. Run this command from one node in the cluster. The scprivipadm command takes as input the private network address. Optionally, the command also takes one or both of the following: o The netmask o The maximum number of nodes and the maximum number of private networks that are ever expected to be in the cluster The command then performs the IP address assignment for the physical adapters and the per-node IP addresses. You can use this command only in the global zone. OPTIONS
The following options are supported: -c Modifies the IP address range that is currently assigned to the cluster. Run the -c option on each node of the cluster. You can use this option only in the global zone. The -c option supports the following suboptions: netaddr=netaddr Specifies the private network address netmask=netmask Specifies the netmask maxnodes=nodes Specifies the maximum expected number of nodes in the cluster maxprivatenets=privnets Specifies the maximum expected number of private networks in the cluster The -c option performs the following tasks for each combination of suboptions: o If you specify the netaddr suboption alone, the command assigns the default netmask, 255.255.248.0, to the private interconnect. The default IP address range accommodates a maximum of 64 nodes and 10 private networks. o If you also specify the netmask suboption, the value that you specify must be equal to or greater than the default netmask. If the specified netmask is less than the default netmask, the command fails and exits with an error. If the specified netmask is equal to or greater than the default netmask, the command assigns the specified netmask to the private interconnect. The resulting IP address range can accommodate a maximum of 64 nodes and 10 private net- works. To assign a smaller IP address range than the default, specify the maxnodes and maxprivatenets suboptions. o If you also specify the maxnodes and maxprivatenets suboptions, the command calculates the minimum netmask to sup- port the specified number of nodes and private networks. The command then assigns the calculated netmask to the private interconnect. The maximum value for nodes is 64 and the minimum value is 2. The maximum value for privnets is 128 and the minimum value is 2. o If you also specify the netmask suboption as well as the maxnodes and maxprivatenets suboptions, the command calcu- lates the minimum netmask that supports the specified number of nodes and private networks. The command compares that calculation to the specified netmask. If the specified netmask is less than the calculated netmask, the com- mand fails and exits with an error. If the specified netmask is equal to or greater than the calculated netmask, the command assigns the specified netmask to the private interconnect. The maximum value for nodes is 64 and the minimum value is 2. The maximum value for privnets is 128 and the minimum value is 2. If the -c option fails, you must run the -R option on each node to repair the configuration before you rerun the -c option. Users other than superuser require solaris.cluster.modify Role-Based Access Control (RBAC) authorization to use this subcom- mand. See the rbac(5) man page. -R Repairs the cluster configuration. Use this option if the command fails while modifying the IP address range on the cluster nodes and the failure results in inconsistent cluster configuration on the nodes. You can use this option only in the global zone. Run the -R option on each node of the cluster. The -R option repairs the cluster configuration and removes any inconsistencies that were caused by a failure to modify the IP address range on all nodes. If you attempt to rerun the -c option without first running the -R option, the configuration change might again fail. Users other than superuser require solaris.cluster.modify Role-Based Access Control (RBAC) authorization to use this subcom- mand. See the rbac(5) man page. -p Displays the current private network address that is assigned to the private interconnect. Run the -p option from any node. You can use this option only in the global zone. The -p option prints the following information: o The private network address o The IP address range in the form of a netmask o The maximum number of nodes and the maximum number of private networks that can be supported by the IP address range Users other than superuser require solaris.cluster.read Role-Based Access Control (RBAC) authorization to use this subcommand. See the rbac(5) man page. To display the current private network address from a node that is in cluster mode, instead run the scconf -p command or the cluster show-netprops command. EXAMPLES
Example 1 Calculating a Custom Private IP Address Range The following command specifies the private network address 172.16.0.0 and calculates the netmask. The command specifies that the calcu- lated netmask must support up to sixteen nodes and up to four private networks in the cluster. # scprivipadm -c netaddr=172.16.0.0,maxnodes=16,maxprivatenets=4 Example 2 Specifying a Private Network Address and Netmask The following command specifies the private network address 172.16.0.0 and the netmask 255.255.248.0. # scprivipadm -c netaddr=172.16.0.0,netmask=255.255.248.0 EXIT STATUS
The scprivipadm command returns with a non-zero value if either of the following conditions occur: o Invalid arguments were provided. o The command was unable to successfully modify the IP address range on all nodes of the cluster. ATTRIBUTES
See attributes(5) for descriptions of the following attributes: +-----------------------------+-----------------------------+ | ATTRIBUTE TYPE | ATTRIBUTE VALUE | +-----------------------------+-----------------------------+ |Availability |SUNWscu | +-----------------------------+-----------------------------+ |Interface Stability |Evolving | +-----------------------------+-----------------------------+ SEE ALSO
Intro(1CL), cluster(1CL), scconf(1M), scinstall(1M), netmasks(4), networks(4), rbac(5) Sun Cluster Software Installation Guide for Solaris OS, Sun Cluster System Administration Guide for Solaris OS, System Administration Guide: IP Services NOTES
The superuser can run all forms of this command. Users other than superuser require RBAC authorizations. See the following table. +-------+---------------------------------------------------------+ |Option | RBAC Authorization | +-------+---------------------------------------------------------+ |-c | solaris.cluster.modify | +-------+---------------------------------------------------------+ |-R | solaris.cluster.modify | +-------+---------------------------------------------------------+ |-p | solaris.cluster.read | +-------+---------------------------------------------------------+ Sun Cluster 3.2 23 Jun 2006 scprivipadm(1M)
All times are GMT -4. The time now is 06:02 AM.
Unix & Linux Forums Content Copyright 1993-2022. All Rights Reserved.
Privacy Policy