4 ms·
We have an ever changing group of about 60 engineers who need the ability to do rooty style things on about 500 different machines (very few of which are the sa
by isostatic 7y ago
We have an ever changing group of about 60 engineers who need the ability to do rooty style things on about 500 different machines (very few of which are the same, so things like ansible don't work too well). While only a handful actually do, the rest need to be able to, and they're trusted to make the call.
However we still want to know what's going on, and sudo fires back a message to syslog with who did it and what they did. Far more useful than "joebloggs went to root at 03:14 and logged out at 09:15"
- jlgaddis 7y agoIf you take the time (once) to configure it correctly, auditd can tell you much, much more than just what commands were executed (and "hiding" the commands you ran via sudo is fairly trivial, if one is so inclined).
- isostatic 7y agoWouldn't that simply say "root did this at this time", and maybe "on this pts", and then I'd have to marry that up with who was logged on at the given pts at that time? Either way we don't sue sudo to enforce security -- anyone could go and reboot the machine physically in any case, we use sudo so we remember what we did, or can quickly find the person who did it. Same with physical security, we don't stop people from pulling the plug, but if the plug is pulled we can see who was probably in the room at the time. You can work around it (by going in with a colleague) if you wanted to hide your tracks, but people don't hide their tracks. Of course the other benefit of sudo is to reduce the number of terminals logged in as root, where accidents can easilly happen.