Conversation
Notices
-
drymer #en proceso de migrar (drymervieja@quitter.se)'s status on Tuesday, 28-Feb-2017 13:00:43 UTC drymer #en proceso de migrar @clacke Not sure if I understand. Do you mean that sudo can be limited to certain commands? @camby -
drymer #en proceso de migrar (drymervieja@quitter.se)'s status on Tuesday, 28-Feb-2017 08:34:01 UTC drymer #en proceso de migrar What you people thing about using sudo without password for automating purposes (like ansible)? -
drymer #en proceso de migrar (drymervieja@quitter.se)'s status on Tuesday, 28-Feb-2017 08:38:31 UTC drymer #en proceso de migrar cc !sysadmin -
drymer #en proceso de migrar (drymervieja@quitter.se)'s status on Tuesday, 28-Feb-2017 08:40:12 UTC drymer #en proceso de migrar @clacke That's what I was thinking. I don't like it, since it's another security layer. But ansible is not useful if you don't do it. -
drymer #en proceso de migrar (drymervieja@quitter.se)'s status on Tuesday, 28-Feb-2017 08:42:18 UTC drymer #en proceso de migrar @camby Yes, but it's not about commands. What if every server has different passwords? Having to type them all it's a lot of effort. @clacke -
Christmas Personified as a Catgirl (moonman@shitposter.club)'s status on Tuesday, 28-Feb-2017 08:45:29 UTC Christmas Personified as a Catgirl @drymer I have a separate user for that that is only used for ansible/deployment, that can sudo without password. drymer #en proceso de migrar repeated this. -
drymer #en proceso de migrar (drymervieja@quitter.se)'s status on Tuesday, 28-Feb-2017 08:50:05 UTC drymer #en proceso de migrar @moonman Yeah, that's what I was looking for. Match use ansible and PasswordAuthentication no. -
drymer #en proceso de migrar (drymervieja@quitter.se)'s status on Tuesday, 28-Feb-2017 12:38:02 UTC drymer #en proceso de migrar @clacke It's not that big. If someone is able to log in a server, it's pretty easy to install a keylogger that will capture the pswd. @camby -
Charles Dexter (irae@quitter.is)'s status on Tuesday, 28-Feb-2017 13:04:37 UTC Charles Dexter @drymer @camby @clacke or even replace sudo / other elf files to achieve the same goal -
Charles Dexter (irae@quitter.is)'s status on Tuesday, 28-Feb-2017 13:08:03 UTC Charles Dexter @drymer env_reset option in sudoers @camby @clacke https://quitter.is/attachment/799184 drymer #en proceso de migrar likes this.
-