Root access loggin

Tom Evans tevans.uk at googlemail.com
Mon Jul 30 11:13:42 UTC 2007


On Tue, 2007-07-24 at 13:18 -0400, Ian Lord wrote:
> Hi,
> 
>  
> 
> A Zend technician asked me to have a root access on one of my box to
> troubleshoot something wrong in Zend Platform installation that doesn't work
> on Freebsd.
> 
>  
> 
> He will need root access naturally to install and debug remotely.
> 
>  
> 
> Is there a way to log all the commands he will type and send them in a
> logfile ?
> 
>  
> 
> Or is there a better solution than granting him root access from ssh ?
> 
>  
> 
> Thanks
> 
>  

sudosh (sudo shell) is an idea here. It gives them a root shell they can
do anything in, but everything is logged. It can even play back the logs
at any speed up you like (I like to watch.)

This seems great in principle, but of course, you just gave them a root
shell, and so they can delete their log file easily enough...
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 187 bytes
Desc: This is a digitally signed message part
Url : http://lists.freebsd.org/pipermail/freebsd-questions/attachments/20070730/727386b4/attachment.pgp


More information about the freebsd-questions mailing list