Symantec IGA

 View Only
  • 1.  Solaris root account shell restrictions lifted

    Posted Jun 26, 2019 08:07 AM
    Edited by SOONSOUK CHOI Jun 26, 2019 08:08 AM

    Reason
    1.In Korea, the installation and setting of the sudo itself is violated
    2.CA im to connect to unix server with root account
    3.By default, the customer cannot change the root shell /bin/bash

    ------------------------------
    conductor
    eNsecure
    ------------------------------


  • 2.  RE: Solaris root account shell restrictions lifted
    Best Answer

    Broadcom Employee
    Posted Jun 26, 2019 11:45 AM
    Are docs state:
    https://docops.ca.com/ca-identity-manager-and-governance-connectors/1-0/EN/connectors/unix-connectors/unix-v2-connector

    Install and Configure Sudo
    The connector allows authentication using a root user or any non-root user for acquiring an endpoint. To allow a non-root user to have root permissions, you must install Sudo and configure the /etc/sudoers file.

    So you have to either. Set different shell for root, or explain what you mean by:
    1.In Korea, the installation and setting of the sudo itself is violated


    As we see it, there are really only 3 ways forward. 
    1) create an exception for this connector server to connect as root.
    2) create an exception for this endpoint to allow one user to have sudo access in the sudores file.
    3) You will need a product enhancement and ask for certification of another form of endpoint management.


    Bill Patton