Project

General

Profile

Actions

tickets #116710

closed

Gather missing root passwords

Added by crameleon about 2 years ago. Updated about 2 years ago.

Status:
Closed
Priority:
Normal
Category:
Core services and virtual infrastructure
Target version:
-
Start date:
2022-09-18
Due date:
% Done:

0%

Estimated time:

Description

Hi,

Our policy (https://en.opensuse.org/openSUSE:Infrastructure_policy#openSUSE_infrastructure_policy) suggests service administrators should store the root passwords of machines in our pass repository.
Currently only a fraction of root passwords is available there, causing the repair of service disruptions to be delayed due to having to inquire multiple people about access to various systems.

I propose we compare the passwords in the repository with the list of machines in our administration (Salt pillar?), and add the missing ones as part of the next Heroes meeting.
If a machine does not allow for a shared root password (be it technical or compliance reasons), the reason should be documented, with information on whom to contact instead.

As an alternative solution, which may be preferable as it helps with auditing, we could change the policy to demand sudo root access for all administrators in a certain LDAP group.

What do you think?

Best,
Georg

Actions

Also available in: Atom PDF