04-06-2012
Sudo to delegate permission from non-root user to another non-root user
I've been through many threads before i decide to create a separate thread.
I can't really find the solution to my (simple) problem.
Here's what I'm trying to achieve:
As "canar" user I want to run a command, let's say "/opt/ocaml/bin/ocaml" as "duck" user.
The only to achieve this is to give "canar" user root permission in sudoers, see below:
Host_Alias LAB = linuxbox
User_Alias LABTRUSTED = canar
Cmnd_Alias LABADMIN = /bin/bash, /bin/su, /bin
LABTRUSTED LAB=(ALL) NOPASSWD: LABADMIN
And run any command:
canar@linuxbox$ sudo -i -u duck 'id'
But basically, this is a huge security hole since canar can run whatever he wants as anyone (including root)
I want to restrict canar user to be able to login as duck user (or as anyone from a given group) without providing root access
Edit: want to restrict canar user to be able to run an identified command as duck user (or as anyone from a given group) without providing root access
Any help would be welcome!
~canar
10 More Discussions You Might Find Interesting
1. Solaris
Hi
my directory not accepting any commands. its simply telling permission denied. i tried ( cp, mv, rm ) as roor
i want to set default permissons to this DIR
please find the Logs below.
dr-xr-xr-x 1 root root 1 Jun 1 09:04 AP1_ROP ( original dir)
root> chmod 777... (5 Replies)
Discussion started by: vijayq8
5 Replies
2. UNIX for Dummies Questions & Answers
hi
i am new to unix and i have abig task. i have to \run particular commands having root privileges from a non root user. i know sudo is one of the way but i need sum other approach kindly help
Thanks (5 Replies)
Discussion started by: suryashikha
5 Replies
3. Shell Programming and Scripting
I've been bashing my head on the desk for 2 days trying to get this to work, but I've had no luck. I'll try to be as clear as possible in my explanation without dragging out the details. I'm trying to set up a cron job for user "john" which runs a script. This script initiates an ssh connection to... (5 Replies)
Discussion started by: eh3civic
5 Replies
4. Shell Programming and Scripting
Hi,
I have a shell script file which is set to access permission 000. When I login as root (sudo su) and try to run this script, I am getting the Permission denied error. I have read somewhere that root admin user can execute any kind of permission script. Then why this behavior? However, I can... (1 Reply)
Discussion started by: royalibrahim
1 Replies
5. Solaris
hi guys..
how to give root permission for particular user
tel me step by step (2 Replies)
Discussion started by: coolboys
2 Replies
6. UNIX for Advanced & Expert Users
Hi!! one strange problem occurred with my RHEL 5 box.
i'm having logs folder with ownership of non-root user. Created some files with root user under logs folder.
here is the scene:
-rw-r----- 1 root root 1048227 Feb 28 12:34 SystemOut_13.02.28_12.34.10.log
-rw-r----- 1 root root ... (6 Replies)
Discussion started by: sukhdip
6 Replies
7. Shell Programming and Scripting
Currently in my system Red Hat is installed. And Many user connect to my machine via SSH Techia Terminal.
I want to give some users a root level access.
Can anyone please help me how to make it possible. I too searched on the Google but didn't find the correct way
Regards
ADI (4 Replies)
Discussion started by: adisky123
4 Replies
8. UNIX for Dummies Questions & Answers
Hi All,
I need to give an user sudo ability to root.
We have also generated RSA key but unable to proceed further.
For example after a user logs into the server normally and when he executes below command
$ssh root@server_name
This should take you to root prompt #
Please help me.... (3 Replies)
Discussion started by: Rockyc3400
3 Replies
9. Red Hat
I have a set of RHEL 5 boxes running our ERP software on Oracle databases. I need to allow my DBA's to su to oracle and one other account (banner) without knowing the oracle or banner password. But I need to prevent them from su'ing to any other user especially root. I only want them to be able to... (1 Reply)
Discussion started by: westmoreland
1 Replies
10. Solaris
Hello,
It is Solaris-10. There is a file as /opt/vpp/dom1.2/pdd/today_23. It is always generated by root, so owned by root only.
This file has to be deleted as part of application restart always and that is done by app_user and SA is always involved to do rm on that file.
Is it possible to give... (9 Replies)
Discussion started by: solaris_1977
9 Replies
GKSU(1) User Commands GKSU(1)
NAME
gksu - GTK+ frontend for su and sudo
SYNOPSIS
gksu
gksu [-u <user>] [options] <command>
gksudo [-u <user>] [options] <command>
DESCRIPTION
This manual page documents briefly gksu and gksudo
gksu is a frontend to su and gksudo is a frontend to sudo. Their primary purpose is to run graphical commands that need root without the
need to run an X terminal emulator and using su directly.
Notice that all the magic is done by the underlying library, libgksu. Also notice that the library will decide if it should use su or sudo
as backend using the /apps/gksu/sudo-mode gconf key, if you call the gksu command. You can force the backend by using the gksudo command,
or by using the --sudo-mode and --su-mode options.
If no command is given, the gksu program will display a small window that allows you to type in a command to be run, and to select what
user the program should be run as. The other options are disregarded, right now, in this mode.
OPTIONS
--debug, -d
Print information on the screen that might be useful for diagnosing and/or solving problems.
--user <user>, -u <user>
Call <command> as the specified user.
--disable-grab, -g
Disable the "locking" of the keyboard, mouse, and focus done by the program when asking for password.
--prompt, -P
Ask the user if they want to have their keyboard and mouse grabbed before doing so.
--preserve-env, -k
Preserve the current environments, does not set $HOME nor $PATH, for example.
--login, -l
Make this a login shell. Beware this may cause problems with the Xauthority magic. Run xhost to allow the target user to open win-
dows on your display!
--description <description|file>, -D <description|file>
Provide a descriptive name for the command to be used in the default message, making it nicer. You can also provide the absolute
path for a .desktop file. The Name key for will be used in this case.
--message <message>, -m <message>
Replace the standard message shown to ask for password for the argument passed to the option. Only use this if --description does
not suffice.
--print-pass, -p
Ask gksu to print the password to stdout, just like ssh-askpass. Useful to use in scripts with programs that accept receiving the
password on stdin.
--su-mode, -w
Force gksu to use su(1) as its backend for running the programs.
--sudo-mode, -S
Force gksu to use sudo(1) as its backend for running the programs.
SEE ALSO
su(1), sudo(1)
gksu version 2.0.x August 2006 GKSU(1)