gabriel rosenkoetter on Mon, 8 Jul 2002 01:58:26 -0400 |
On Sun, Jul 07, 2002 at 09:40:55PM -0400, Samantha wrote: > But couldn't they also be able to delete these records? If the user makes > an honest mistake in doing something as root, he could very well just > admit it, or delete all traces of him becoming root. How are these things not true when you pass out the root password? In any case, they're not problems I was suggesting this solved. > Also, floppies can be lost, damaged, swapped(?) Yep. And, as I pointed out, should that happen, *someone* does know the root password, can remove the lost keys, and the loser generate new ones to be put in. The point is not to withold knowledge from those with root access, but to allow them to be root remotely without passing the shared secret over the wire. -- gabriel rosenkoetter gr@eclipsed.net Attachment:
pgpkMJXD3XPLp.pgp
|
|