From owner-freebsd-questions@FreeBSD.ORG Thu Nov 29 04:28:27 2007 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 0CBFA16A420 for ; Thu, 29 Nov 2007 04:28:27 +0000 (UTC) (envelope-from on@cs.ait.ac.th) Received: from mail.cs.ait.ac.th (mail.cs.ait.ac.th [192.41.170.16]) by mx1.freebsd.org (Postfix) with ESMTP id 9E72113C447 for ; Thu, 29 Nov 2007 04:28:26 +0000 (UTC) (envelope-from on@cs.ait.ac.th) Received: from banyan.cs.ait.ac.th (banyan.cs.ait.ac.th [192.41.170.5]) by mail.cs.ait.ac.th (8.13.1/8.12.11) with ESMTP id lAT4SO0Q035373 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO) for ; Thu, 29 Nov 2007 11:28:24 +0700 (ICT) Received: (from on@localhost) by banyan.cs.ait.ac.th (8.13.6/8.12.11) id lAT4SOLd065598; Thu, 29 Nov 2007 11:28:24 +0700 (ICT) Date: Thu, 29 Nov 2007 11:28:24 +0700 (ICT) Message-Id: <200711290428.lAT4SOLd065598@banyan.cs.ait.ac.th> From: Olivier Nicole To: freebsd-questions@freebsd.org X-Virus-Scanned: on CSIM by amavisd-milter (http://www.amavis.org/) Subject: Secure remote shell X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 29 Nov 2007 04:28:27 -0000 Hi, Part of (un)registerings users on my system consists in connecting to various servers to add the user account to some services: Registering users is done wia a web page, and the web server will remote execute a script on the mail server to add the users in the aliases and run newaliases, remote execute a script to the radius server to add the user in the radius tables and restart radius, etc. Of course all the remote execution should be done as root :( So far, one specific user from the web server can rsh -l root to the various other servers to do what needs to be done. But this is not quite satisfactory. What other solution would you suggest to execute a shell remotely as root, that could be automated in a script (no password required). Best regards, Olivier