<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Changing root password in Administration and Deployment</title>
    <link>https://communities.sas.com/t5/Administration-and-Deployment/Changing-root-password/m-p/210030#M3140</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;EM&gt;My specific request is Linux SAS 9.4 (Grid, HPA, in-DB, etc) spread across 30+ servers, but the question is more generic.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;While most SAS-related passwords may remain under the control (or at least the influence) of the SAS Platform Administrator, one that may not is the &lt;STRONG&gt;root&lt;/STRONG&gt; password, where support policies (beyond the scope of "application administration") may mandate periodic updates of critical passwords.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a "hit list" of what in a SAS platform requires updating if the O/S admin updates the root password?&amp;nbsp; For example:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Run the Deployment Manager to update passwords on each server (although I thought this mainly applies to "SAS" internal passwords - sasadm, sassrv, sastrust, etc.)&lt;/LI&gt;&lt;LI&gt;Update config files X, Y, &amp;amp; Z&lt;/LI&gt;&lt;LI&gt;Regenerate keys&lt;/LI&gt;&lt;LI&gt;etc.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My main concern are the LSF daemons, but may extend to other SAS services.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm reviewing System Admin Guide (bisag), Install &amp;amp; Config Guide (biig) &amp;amp; Security Admin Guide (bisecag) support docs, but looking specifically for impact of &lt;STRONG&gt;root&lt;/STRONG&gt; password changes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 06 May 2015 05:19:10 GMT</pubDate>
    <dc:creator>AndrewHowell</dc:creator>
    <dc:date>2015-05-06T05:19:10Z</dc:date>
    <item>
      <title>Changing root password</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Changing-root-password/m-p/210030#M3140</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;EM&gt;My specific request is Linux SAS 9.4 (Grid, HPA, in-DB, etc) spread across 30+ servers, but the question is more generic.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;While most SAS-related passwords may remain under the control (or at least the influence) of the SAS Platform Administrator, one that may not is the &lt;STRONG&gt;root&lt;/STRONG&gt; password, where support policies (beyond the scope of "application administration") may mandate periodic updates of critical passwords.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a "hit list" of what in a SAS platform requires updating if the O/S admin updates the root password?&amp;nbsp; For example:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Run the Deployment Manager to update passwords on each server (although I thought this mainly applies to "SAS" internal passwords - sasadm, sassrv, sastrust, etc.)&lt;/LI&gt;&lt;LI&gt;Update config files X, Y, &amp;amp; Z&lt;/LI&gt;&lt;LI&gt;Regenerate keys&lt;/LI&gt;&lt;LI&gt;etc.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My main concern are the LSF daemons, but may extend to other SAS services.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm reviewing System Admin Guide (bisag), Install &amp;amp; Config Guide (biig) &amp;amp; Security Admin Guide (bisecag) support docs, but looking specifically for impact of &lt;STRONG&gt;root&lt;/STRONG&gt; password changes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 May 2015 05:19:10 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Changing-root-password/m-p/210030#M3140</guid>
      <dc:creator>AndrewHowell</dc:creator>
      <dc:date>2015-05-06T05:19:10Z</dc:date>
    </item>
    <item>
      <title>Re: Changing root password</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Changing-root-password/m-p/210031#M3141</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'd think that, after using the root password during installation to set the uid bit on the necessary modules, the root user is not used any further.&lt;/P&gt;&lt;P&gt;All the SAS internal config files are owned by the installation user.&lt;/P&gt;&lt;P&gt;I'd be VERY surprised if SAS had done the utter stupidity of storing the root password (encrypted or not) anywhere within their own realm.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 May 2015 08:49:12 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Changing-root-password/m-p/210031#M3141</guid>
      <dc:creator>Kurt_Bremser</dc:creator>
      <dc:date>2015-05-06T08:49:12Z</dc:date>
    </item>
    <item>
      <title>Re: Changing root password</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Changing-root-password/m-p/210032#M3142</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes.&amp;nbsp; In fact, SAS encourages you not to use the root account when installing.&amp;nbsp; As Kurt mentions, root permission is only needed to run the setuid scripts as part of the install, and even that can be done as sudo.&amp;nbsp; Changing the root password should have no negative repercussions on a SAS deployment.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 May 2015 12:40:43 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Changing-root-password/m-p/210032#M3142</guid>
      <dc:creator>Mark_sas</dc:creator>
      <dc:date>2015-05-06T12:40:43Z</dc:date>
    </item>
    <item>
      <title>Re: Changing root password</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Changing-root-password/m-p/210033#M3143</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Kurt, Mark - concur not to use root account when installing.&lt;/P&gt;&lt;P&gt;Mark - if services are started as sudo, then should be fine. However (in my case, anyway) in the HA config tab of the RTM client, there are services (such as the &lt;STRONG&gt;GridManagementService, ProcessManager&lt;/STRONG&gt;) which are configured to start as root and contain the root user id and the (masked) password. Clearly this must be changed, as any other HA services which must be run as root.&lt;/P&gt;&lt;P&gt;That covers those services requiring root usage with the HA config tab of the RTM client, but what about other (if any) other "non-HA" services requiring root usage?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 May 2015 23:54:00 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Changing-root-password/m-p/210033#M3143</guid>
      <dc:creator>AndrewHowell</dc:creator>
      <dc:date>2015-05-06T23:54:00Z</dc:date>
    </item>
    <item>
      <title>Re: Changing root password</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Changing-root-password/m-p/210034#M3144</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Putting any reference (masked or not) of the root passwort in a place where a non-root user can read it is a SERIOUS security breach and should be fixed since Dec 12, 1969 in case of UNIX.&lt;/P&gt;&lt;P&gt;So I hope that the file containing the root PW is readable only by root. If not, open a bug report of priority "critical" with the respective developers.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 May 2015 05:46:39 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Changing-root-password/m-p/210034#M3144</guid>
      <dc:creator>Kurt_Bremser</dc:creator>
      <dc:date>2015-05-07T05:46:39Z</dc:date>
    </item>
    <item>
      <title>Re: Changing root password</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/Changing-root-password/m-p/210035#M3145</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333330154419px;"&gt;The two services you mention (GGridManagementService and ProcessManager) are from IBM Platform Computing, and do indeed need to be run as root.&amp;nbsp; Ordinarily they are started under root at boot time, which avoids the issue.&amp;nbsp; However, if you are managing these services with the RTM client, it requires you to supply the execution user and password.&amp;nbsp; As you alluded earlier, you should be able to use a non-root user in RTM who has sudo permissions to start the services as root if you've configured sudo for the services.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333330154419px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333330154419px;"&gt;I've checked around and have found no SAS processes which require you to persist root credentials anywhere.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 May 2015 21:37:01 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/Changing-root-password/m-p/210035#M3145</guid>
      <dc:creator>Mark_sas</dc:creator>
      <dc:date>2015-05-07T21:37:01Z</dc:date>
    </item>
  </channel>
</rss>

