From owner-freebsd-security@FreeBSD.ORG Tue May 27 12:31:25 2003 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id CC02E37B430 for ; Tue, 27 May 2003 12:31:25 -0700 (PDT) Received: from aphrodite.gwi.net (aphrodite.gwi.net [207.5.128.164]) by mx1.FreeBSD.org (Postfix) with ESMTP id B213243F75 for ; Tue, 27 May 2003 12:31:24 -0700 (PDT) (envelope-from ah60@httpsite.com) Received: from andy.gwi.net (blake.gwi.net [207.5.142.8]) by aphrodite.gwi.net (8.12.6p2/8.12.6) with ESMTP id h4RJVOPh079773 for ; Tue, 27 May 2003 15:31:24 -0400 (EDT) (envelope-from ah60@httpsite.com) Message-ID: X-Mailer: XFMail 1.5.4 on FreeBSD X-Priority: 3 (Normal) Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: 8bit MIME-Version: 1.0 In-Reply-To: <3ED3BA9B.5020008@centtech.com> X-System-Info-OS: FreeBSD 4.8-STABLE #0 X-System-Info-httpd: apache-1.3.27 X-System-Info-WM: windowmaker-0.80.2 X-System-Info-RT: rt-3-0-2 X-System-Info-DB: PostgreSQL-7.3.2 X-System-Info-Perl: v5.8.0 X-Homepage: http://www.nachoz.com X-PGP-Key: RSA-1024 http://www.nachoz.com/andy.pub Date: Tue, 27 May 2003 15:31:39 -0400 (EDT) Sender: aharriso@andy.gwi.net From: Andy Harrison To: FreeBSD Security Subject: Re: multihost master.passwd sync X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Security issues [members-only posting] List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 27 May 2003 19:31:26 -0000 -----BEGIN PGP SIGNED MESSAGE----- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ On 27-May-2003, Eric Anderson wrote message "Re: multihost master.passwd sync" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ >> Because we don't allow root login remotely, mandated from above. > > so you scp the file to a directory owned by a user designated to only do > this function.. then have a cron job that fires up every so often that > snags that file and updates the running master.passwd file.. Root can't scp a file from one host to another where remote root login is not allowed. ~~ Andy Harrison ah##@httpsite.com ICQ: 123472 AIM/Y!: AHinMaine [full headers for details] -----BEGIN PGP SIGNATURE----- Version: PGP 6.5.8 iQCVAwUBPtO9GVPEkLgodAWVAQGVWgP+O0w5w/uSb12xEcgXnmwEYT7qMfG/TpOr 1fVcZECg+B0YYD1E3zZRA2iJJruaq0VZ1ZQAEu3BFJ5dNLVMsUWFTfDX0ah3V1ob NoGeyjlYsOEZqxR1ShTPa/GhfcV/EgSb7uaCbh93fisdGeuog+vV7AJhdPEdtufr 2sx/YUgNm3I= =GUvW -----END PGP SIGNATURE-----