Oracle Solaris System Administration (MOSC)

MOSC Banner

Roles without password

edited Jun 27, 2011 6:26PM in Oracle Solaris System Administration (MOSC) 6 commentsAnswered ✓
Hello,
I know that I can have a role without a password.
And I have to comment in the PASSREQ=YES on /etc/default/login.

Is that a real security risk?

I ask because in /etc/user_attr I can control who can assume the role.
In addition, assuming an standard "factory defaults" system installation, will the above change expose other accounts or system surface?

The interest on this is that an administrative group, such as DBAs, wouldn't have to share role password.
Also, it would be more attractive than sudo where one generally (although not always I know) have to repeat its own password.

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center