Multiple Root ID's considered evil?

Doug Gwyn gwyn at smoke.BRL.MIL
Tue Sep 12 20:42:25 AEST 1989


In article <1723 at convex.UUCP> tchrist at convex.com (Tom Christiansen) writes:
>Some site are known to have multiple uid 0 accounts so not 
>everyone needs to know the root password.  I seem to recall
>that this is considered a poor idea for security reasons.
>Could someone please explain why?

The main thing is that it doesn't make sense.  It is UID 0 that has
privileges, not username "root".

In any case, nobody should be logging in as "root".  You should set
up your system so that system administration can be done by some
nonprivileged UID.  UID 0 should only be assumed by carefully-checked
utilities that apply access controls.



More information about the Comp.unix.wizards mailing list