[907] in athena10
Re: [athena10] sudo
daemon@ATHENA.MIT.EDU (Jonathan Reed)
Thu Jan 22 16:15:50 2009
Cc: Evan Broder <broder@mit.edu>, Robert Basch <rbasch@mit.edu>,
Quentin Smith <quentin@mit.edu>, Mitchell E Berger <mitchb@mit.edu>,
Greg Hudson <ghudson@mit.edu>, athena10@mit.edu
Message-Id: <86427876-2175-4FD7-8126-721FD8F11170@mit.edu>
From: Jonathan Reed <jdreed@MIT.EDU>
To: Sam Hartman <hartmans@mit.edu>
In-Reply-To: <tsl3afbrqvu.fsf@live.mit.edu>
Content-Type: text/plain; charset=US-ASCII; format=flowed; delsp=yes
Content-Transfer-Encoding: 7bit
Mime-Version: 1.0 (Apple Message framework v919.2)
Date: Thu, 22 Jan 2009 16:14:58 -0500
On Jan 22, 2009, at 4:07 PM, Sam Hartman wrote:
> 1) sudo may perhaps be useful in clusters. It definitely is not on
> other machines using Kerberos for authentication that do not have
> public root passwords.
>
> 2) In addition to the other reasons stated there may be concers about
> enabling sudo in the cluster environment if it enforces a user
> expectation that would be insecure elsewher.
I'm not sure what you mean by these two points.