Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
Restricting roots access to files on file server
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
c8a7w
n00b
n00b


Joined: 06 Oct 2005
Posts: 62

PostPosted: Sat Aug 07, 2010 1:14 am    Post subject: Restricting roots access to files on file server Reply with quote

we have recently setup a file server in the office. its running and everything is good ... except for one request made of me by the MD.


he is not "comfortable" with members of the system administrators team (myself and 3 or 4 others) can access HR files and other confidential files. so looking for a way to restrict access to these without limiting the administrators power. i had thought about sudo but I cant picture in my head how the configuration would work without getting in the way of normal backups and other admin tasks.

one thought i had was encyption. True crypt would allow me to install the decryption on there individual machines and then they would be able to access it. we would be able to move the (encrypted) files around and perform backups etc and the MD can be happy that we cannot access the confidential data.

any ideas or better suggestions?
Back to top
View user's profile Send private message
phajdan.jr
Retired Dev
Retired Dev


Joined: 23 Mar 2006
Posts: 1777
Location: Poland

PostPosted: Sat Aug 07, 2010 2:47 am    Post subject: Reply with quote

I think it's going to be complicated. With encryption you still probably want to keep some way to recover the keys if HR or somebody else loses their keys.

sudo is one way you can consider, provided that you only need to run a limited set of commands.

If you need a more complex solution, you may want to try SELinux or some other kind of Mandatory Access Control.
_________________
http://phajdan-jr.blogspot.com/
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum