Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 14 Nov 2002 17:54:39 -0700 (MST)
From:      Ralph Forsythe <rf-list@centerone.com>
To:        Paul Schenkeveld <fb-isp@psconsult.nl>
Cc:        Lewis Watson <lists@visionsix.com>, <freebsd-isp@FreeBSD.ORG>
Subject:   Re: su and root password
Message-ID:  <Pine.LNX.4.44.0211141751240.8484-100000@blue.centerone.com>
In-Reply-To: <20021114231432.A51618@psconsult.nl>

next in thread | previous in thread | raw e-mail | index | archive | help
On Thu, 14 Nov 2002, Paul Schenkeveld wrote:

> Hi,
>
> If you want to use su behind ssh and did not succeed because su cannot
> read a password from /dev/tty then try the -t option of ssh to force
> sshd to allocate a pty even if this is not an interactive session:
>
<snip!>
>
> I use this construction all the time for things I want to execute as
> root on another machine because I don't want to set up sudo on every
> machine (I'm the only administrator on most machines anyway).
>
> Hope this helps you or someone else.

It's interesting for sure - but would this not then require that he put
the root password into a script, which would by nature be unencrypted?  I
would shoot anyone who did that on my servers.

There are ways to push sudo configs to multiple machines (not that this
guy needs it) in case you didn't know that - it was either discussed on
this list or openbsd-misc, I cannot remember where I saw it.  Either way a
search should find that info.

- Ralph


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-isp" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.LNX.4.44.0211141751240.8484-100000>