Root access

James Brigman ncsa-discussion@ncsysadmin.org
Thu, 27 Feb 2003 22:18:16 -0500


John;

> I am taking a quick survey as to who gets root access. I am only
> interested in places that have Unix admins, developers, DBAs. If people
> have dual roles then it doesn't apply.
>

He who has root access owns the box. Root access never goes to anyone not
responsible for bringing the box back if it dies.

Sudo for users/programmers/dba's, sure. Sometimes I have given a trusted
Oracle DBA the root password to do a fast Oracle install, but I change the
password after the install is done.

> Also if anyone has references to online documents on why wide spread
> root access is a bad thing that would be great.

I'd be curious if anyone turns up a document such as this: it's axiomatic
that widespread root access is a bad thing. You might phrase it another way:
why not give widespread administrator passwords to the windows server, and
watch everyone recoil in horror.

JKB