Fedora Linux Support Community & Resources Center

Go Back   FedoraForum.org > Fedora 17/18 > Security and Privacy
FedoraForum Search

Forgot Password? Join Us!

Security and Privacy Sadly, malware, spyware, hackers and privacy threats abound in today's world. Let's be paranoid and secure our penguins, and slam the doors on privacy exploits.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 7th September 2011, 07:33 PM
satheeshkumar Offline
Registered User
 
Join Date: Aug 2011
Location: Chennai, India
Posts: 43
windows_7ie
Limited sudo previlage

I installed tomcat server in RHEL and the ownership of that is tomcat user. For a user name as guest i want to give limited access to control it.

I want to give limited sudo access. Means i want to give previlage to guest as "sudo to tomcat only and not sudo to root".

If i add the below line in /etc/sudousers file, guest is able to sudo as root.

guest ALL=/bin/su

can someone tell me how to do this.
Reply With Quote
  #2  
Old 7th September 2011, 09:52 PM
bodhi.zazen's Avatar
bodhi.zazen Offline
Registered User
 
Join Date: Jul 2006
Location: Montana
Posts: 731
windows_xp_2003firefox
Re: Limited sudo previlage

You do not need to run su as root.

Simply su tomcat , enter pw for tomcat.

Or if you configure sudo, configure it to allow the commands you need the tomcat user to run and not su.
__________________
If it is not broken, tweak it... If you break Fedora you get to keep both pieces :p
Reply With Quote
  #3  
Old 7th September 2011, 10:01 PM
satheeshkumar Offline
Registered User
 
Join Date: Aug 2011
Location: Chennai, India
Posts: 43
symbiansafari
Re: Limited sudo previlage

i want to give tomcat access to guest, but not to share tomcat password. I think sudo only can do this. But if i add the line /bin/su in sudoers list, it is allowing sudo to root as well. Can you tell me how to customize only to sudo as tomcat only and not as other users
Reply With Quote
  #4  
Old 8th September 2011, 05:32 AM
bodhi.zazen's Avatar
bodhi.zazen Offline
Registered User
 
Join Date: Jul 2006
Location: Montana
Posts: 731
linuxfirefox
Re: Limited sudo previlage

What are you trying to do exactly ? What commands do you want the guest to run and / or what files do you want the guest user to be able to access ?

As I said, if it is a list of commands you would list those commands specifically in sudoers.

See : http://www.gratisoft.us/sudo/sudoers.man.html

You can specify many things, such as Runas_Spec and SELinux_Spec
__________________
If it is not broken, tweak it... If you break Fedora you get to keep both pieces :p
Reply With Quote
  #5  
Old 8th September 2011, 08:11 AM
satheeshkumar Offline
Registered User
 
Join Date: Aug 2011
Location: Chennai, India
Posts: 43
windows_xp_2003firefox
Re: Limited sudo previlage

I want to give all permissions to guest as tomcat users are having... using sudo access without sharing tomcat password, so that if any time i feel guest should not have it, i can revoke it..
Reply With Quote
  #6  
Old 8th September 2011, 04:02 PM
bodhi.zazen's Avatar
bodhi.zazen Offline
Registered User
 
Join Date: Jul 2006
Location: Montana
Posts: 731
windows_xp_2003firefox
Re: Limited sudo previlage

Sounds like you want the Runas_Spec so your guest can then

sudo -u tomcat foo
__________________
If it is not broken, tweak it... If you break Fedora you get to keep both pieces :p
Reply With Quote
Reply

Tags
sudo access

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Cannot open /var/db/sudo after sudo package upgrade Replicant10000 Security and Privacy 1 16th September 2010 01:25 PM
Sudo limited commands casket88 Security and Privacy 2 23rd October 2007 03:32 AM
Limited Or No Connectivity jonis330 Servers & Networking 1 4th February 2007 01:53 PM
limited or no connectivity jonis330 Servers & Networking 2 3rd May 2006 04:35 PM
Limited Space john3883 Servers & Networking 1 7th March 2005 03:15 AM


Current GMT-time: 14:44 (Wednesday, 19-06-2013)

TopSubscribe to XML RSS for all Threads in all ForumsFedoraForumDotOrg Archive
logo

All trademarks, and forum posts in this site are property of their respective owner(s).
FedoraForum.org is privately owned and is not directly sponsored by the Fedora Project or Red Hat, Inc.

Privacy Policy | Term of Use | Posting Guidelines | Archive | Contact Us | Founding Members

Powered by vBulletin® Copyright ©2000 - 2012, vBulletin Solutions, Inc.

FedoraForum is Powered by RedHat