Lee Eric <openlinuxsou...@gmail.com> writes:

> Thanks Russ. So it looks like I don't need to leak my root password to
> client users, right?

Right, to me that's the main feature of ksu.  (Of course, if they're root,
they have other ways of getting the root password if they're sufficiently
devious, but usually for me the issue is policy and procedure and inherent
risk of more people knowing something, not actually untrusted users.)

-- 
Russ Allbery (r...@stanford.edu)             <http://www.eyrie.org/~eagle/>
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

Reply via email to