From owner-freebsd-security@FreeBSD.ORG Tue May 27 12:34:31 2003 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 246C637B425 for ; Tue, 27 May 2003 12:34:31 -0700 (PDT) Received: from otter3.centtech.com (moat3.centtech.com [207.200.51.50]) by mx1.FreeBSD.org (Postfix) with ESMTP id 8BD3E43FBF for ; Tue, 27 May 2003 12:34:30 -0700 (PDT) (envelope-from anderson@centtech.com) Received: from centtech.com (dhcp-218.centtech.com [204.177.173.218]) by otter3.centtech.com (8.12.3/8.12.3) with ESMTP id h4RJYU56064619; Tue, 27 May 2003 14:34:30 -0500 (CDT) (envelope-from anderson@centtech.com) Message-ID: <3ED3BDA1.5020605@centtech.com> Date: Tue, 27 May 2003 14:33:53 -0500 From: Eric Anderson User-Agent: Mozilla/5.0 (X11; U; Linux i386; en-US; rv:1.0.1) Gecko/20020823 Netscape/7.0 X-Accept-Language: en-us, en MIME-Version: 1.0 To: Andy Harrison References: Content-Type: text/plain; charset=us-ascii; format=flowed Content-Transfer-Encoding: 7bit cc: FreeBSD Security Subject: Re: multihost master.passwd sync X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Security issues [members-only posting] List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 27 May 2003 19:34:31 -0000 Andy Harrison wrote: >>>Because we don't allow root login remotely, mandated from above. >> >>so you scp the file to a directory owned by a user designated to only do >>this function.. then have a cron job that fires up every so often that >>snags that file and updates the running master.passwd file.. > > > Root can't scp a file from one host to another where remote root login is not > allowed. as root on localbox: % scp /etc/master.passwd genericuser@remotebox: works fine.. you just need to set the keys correctly.. Eric -- ------------------------------------------------------------------ Eric Anderson Systems Administrator Centaur Technology Attitudes are contagious, is yours worth catching? ------------------------------------------------------------------