Disallow root to su on a user which is not listed in /etc/passwd

Posted by marc.riera on Server Fault See other posts from Server Fault or by marc.riera
Published on 2010-12-23T15:42:24Z Indexed on 2010/12/23 15:55 UTC
Read the original article Hit count: 347

Filed under:
|
|
|

Hello,

on linux we autenticate users against AD. The AD users are not listed on /etc/passwd.

We are about to deploy a NFS solution to mount some extra space for each group of users.

If a user(A) with sudo su privileges goes to root, then he can impersonate user(B) just by su user(B) and going to the NFS.

Is there any way to disallow root to su user if the user is not listed on /etc/passwd ?

Thanks.

© Server Fault or respective owner

Related posts about security

Related posts about nfs