remote access to the redhat linux server

Posted on 2007-12-06
Last Modified: 2013-12-06
Dear Sir/Madam:

I have redhat linux enterprise version 5 as network opearating system  in my lan which can be accessed from the remote by ssh , we have software development team in the remote place now they have to login to this server from remote install and test the developed application , application is developed using java , mysql and apache  this is fine , problem is i do not want to give the  ssh root access to login from the remote place but if given ordinary ssh login they will not able able to install , remove packages of apache , mysql and java packages also they cannot start or stop the services , please suggest me how to give them the full access for these work and deny other access, please help me step by step.

Please help me on this

Question by:D_wathi
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
LVL 19

Accepted Solution

alextoft earned 500 total points
ID: 20420305
You're asking how you can give them root access without giving them root access... interesting.

How about giving them a virtual machine to play with? RedHat 5 comes with Xen, or there is the free VMware server option. Then they can have a server to test on with root access.
LVL 88

Expert Comment

ID: 20420444
Standard operation is that SSH doesn't have root rights anyway. Once you have logged in as a standard user you can use su or sudo to allow the logged in user to install things or administrate the system. You just have to add the user to the /etc/sudoer file, or add him to the group that is allowed to su.

Expert Comment

ID: 20420729
Sudo is the way, but you might want to give restricted permissions. It is possible to define a precise list of executables which your users will be able to access without entering a password. Once your sudoers are configured, users must use 'sudo' to call the executables.

Example /etc/sudoers

# /etc/sudoers : edit only as root with 'visudo'
# Define aliases
User_Alias	OPERATORS  = a, b, c
Cmnd_Alias	OPERATIONS = /usr/sbin/command_a /sbin/command_b
# Default permissions for root and admin user group
root		ALL = (ALL) ALL
%admin		ALL = (ALL) ALL
# Special permissions for OPERATORS, can execute all OPERATIONS without password

Open in new window

LVL 14

Expert Comment

ID: 20420881
Just to clarify what other's have said "sudo" stands for "super-user do".  It allows a normal user to "do" things are a "super user".  This access is controlled by a configuration file, /etc/sudoers, that tells the sudo command who can run what.  You should always edit the sudoers file by typing "visudo", not directly.  You can customize it up the wazoo... see the man page or your system may have come with a good example (redhat does).

I would really suggest, as alextoft suggested, that they do their actual testing in a virtual machine.  Or another physical machine that you give them root access to.  They're going to screw it up and change an unknown billion options.  They should give you precise step-by-step instructions on how to install it on a staging server.  This is a good exercise that ALL software/development companies should do.  Otherwise you're going to have to re-load this later and you'll be SOL.

Featured Post

Microsoft Certification Exam 74-409

Veeam® is happy to provide the Microsoft community with a study guide prepared by MVP and MCT, Orin Thomas. This guide will take you through each of the exam objectives, helping you to prepare for and pass the examination.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

I have seen several blogs and forum entries elsewhere state that because NTFS volumes do not support linux ownership or permissions, they cannot be used for anonymous ftp upload through the vsftpd program.   IT can be done and here's how to get i…
Have you ever been frustrated by having to click seven times in order to retrieve a small bit of information from the web, always the same seven clicks, scrolling down and down until you reach your target? When you know the benefits of the command l…
Although Jacob Bernoulli (1654-1705) has been credited as the creator of "Binomial Distribution Table", Gottfried Leibniz (1646-1716) did his dissertation on the subject in 1666; Leibniz you may recall is the co-inventor of "Calculus" and beat Isaac…
How to Install VMware Tools in Red Hat Enterprise Linux 6.4 (RHEL 6.4) Step-by-Step Tutorial

730 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question