[HPADM] SUMMARY: permissions on swapinfo

From: bill.thompson@goodyear.com
Date: Wed Jan 29 2003 - 13:44:28 EST


Thanks for the responses from Bill Hassell, Mark Schupsky, Thomas V Myers,
David Lodge, Robert Brinkley, and Alex Vinson.

Setting swapinfo to 555 should not be a problem and is not a security risk.

Some people have a problem with setting the SUID bit others had a problem
with setting the read attribute for group and others. You can make your own
decisions with regards to this. The program should work fine with 511
permissions.

It was suggested that the same information can get obtained from glance or
sar. While this is true it is in my opinion much more cumbersome especially
when our users just want to know the percentage of swap currently in use.
e.g.: swapinfo -t

Original question follows:

> All,
>
> Does anybody see a problem with changing the permissions of
> /usr/sbin/swapinfo from 0544 to 0555? What about to 4555 (suid bit set)?
>
> I have a number of users who do not have root access but would like to be
> able to see paging space information. I'd rather not set up a sudo entry
> just for swapinfo.
>
> It looks to me like it's a query only command. Anybody know why it's
> restricted?

Bill Thompson
The Goodyear Tire & Rubber Company

--
             ---> Please post QUESTIONS and SUMMARIES only!! <---
        To subscribe/unsubscribe to this list, contact majordomo@dutchworks.nl
       Name: hpux-admin@dutchworks.nl     Owner: owner-hpux-admin@dutchworks.nl
 
 Archives:  ftp.dutchworks.nl:/pub/digests/hpux-admin       (FTP, browse only)
            http://www.dutchworks.nl/htbin/hpsysadmin   (Web, browse & search)


This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 11:02:25 EDT