<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What part of SAS or Grid process runs as ROOT rather than the User? in Administration and Deployment</title>
    <link>https://communities.sas.com/t5/Administration-and-Deployment/What-part-of-SAS-or-Grid-process-runs-as-ROOT-rather-than-the/m-p/386407#M9975</link>
    <description>&lt;P&gt;The SSH port is a so-called privileged port (&amp;lt;1024), which can only be used by the superuser. Therefore the master sshd daemon runs as root and spawns children for every connection (which stay under userid 0); once login is completed (either by password or public/private key), another child running with the login user's identity is spawned. This child then starts the shell.&lt;/P&gt;
&lt;P&gt;12073 should be your master sshd with parent process 1.&lt;/P&gt;</description>
    <pubDate>Tue, 08 Aug 2017 20:17:08 GMT</pubDate>
    <dc:creator>Kurt_Bremser</dc:creator>
    <dc:date>2017-08-08T20:17:08Z</dc:date>
    <item>
      <title>What part of SAS or Grid process runs as ROOT rather than the User?</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/What-part-of-SAS-or-Grid-process-runs-as-ROOT-rather-than-the/m-p/386400#M9974</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;Recently we have been observing that our users have processes that are shown as ROOT as the process owner. In contacting the User they say that they are only running Grid processes. What part of SAS or Grid could this process be? For example this is what we are seeing:&lt;/P&gt;
&lt;P&gt;root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5819 12073&amp;nbsp; 0 Jul28 ?&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 00:00:00 sshd:&amp;nbsp;userid [priv]&lt;BR /&gt;userid&amp;nbsp;&amp;nbsp; 6231&amp;nbsp; 5819&amp;nbsp; 0 Jul28 ?&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 00:00:02 sshd: userid@pts/2&lt;BR /&gt;userid&amp;nbsp;&amp;nbsp; 6232&amp;nbsp; 6231&amp;nbsp; 0 Jul28 pts/2&amp;nbsp;&amp;nbsp;&amp;nbsp; 00:00:00 -ksh&lt;BR /&gt;root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 26386 12073&amp;nbsp; 0 Jul28 ?&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 00:00:00 sshd:&amp;nbsp;userid [priv]&lt;BR /&gt;thisisme&amp;nbsp;26989 25006&amp;nbsp; 0 14:55 pts/4&amp;nbsp;&amp;nbsp;&amp;nbsp; 00:00:00 grep userid&lt;BR /&gt;userid&amp;nbsp; 29603&amp;nbsp; 4321&amp;nbsp; 0 Jul28 ?&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 01:11:46 /sas/sys/sasconfig_prod/lsf9/9.1/linux2.6-glibc2.3-x86_64/etc/res -d /sas/sys/sasconfig_prod/lsf9/conf -m svcksa69901mpk.us.bank-dns.com /home/userid/.lsbatch/1501098689.316759&lt;BR /&gt;userid&amp;nbsp; 29650 29603&amp;nbsp; 0 Jul28 ?&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 00:00:00 /bin/sh /home/userid/.lsbatch/1501098689.316759&lt;BR /&gt;userid&amp;nbsp; 29689 29650&amp;nbsp; 5 Jul28 ?&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 17:02:15 /sas/sys/sasinstall_prod/compute/SASFoundation/9.4/sasexe/sas -noterminal -netencryptalgorithm TripleDES -metaserver svcksa69901mpk.us.bank-dns.com -metaport 8561 -metarepository Foundation -locale en_US -objectserver -objectserverparms delayconn sph=svcksa69901mpk.us.bank-dns.com protocol=bridge spawned spp=12832 cid=3470 pb classfactory=440196D4-90F0-11D0-9F41-00A024BB830C server=OMSOBJ:SERVERCOMPONENT/A51QZNX6.AY00000B cel=everything lb recon grid keepalive=500 -METAUSER&lt;BR /&gt;userid&amp;nbsp; 31582 26386&amp;nbsp; 0 Jul28 ?&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 00:00:26 sshd: userid@pts/0&lt;BR /&gt;userid&amp;nbsp; 31654 31582&amp;nbsp; 0 Jul28 pts/0&amp;nbsp;&amp;nbsp;&amp;nbsp; 00:00:00 -ksh&lt;BR /&gt;userid&amp;nbsp; 31853 31654&amp;nbsp; 0 Jul28 pts/0&amp;nbsp;&amp;nbsp;&amp;nbsp; 01:03:41 top&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It is line 1 and 3 we are concerned about. Did we just stumble across this user logged in as ROOT or is this a SAS process creating this process?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for your insight.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2017 20:07:22 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/What-part-of-SAS-or-Grid-process-runs-as-ROOT-rather-than-the/m-p/386400#M9974</guid>
      <dc:creator>DJWanna</dc:creator>
      <dc:date>2017-08-08T20:07:22Z</dc:date>
    </item>
    <item>
      <title>Re: What part of SAS or Grid process runs as ROOT rather than the User?</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/What-part-of-SAS-or-Grid-process-runs-as-ROOT-rather-than-the/m-p/386407#M9975</link>
      <description>&lt;P&gt;The SSH port is a so-called privileged port (&amp;lt;1024), which can only be used by the superuser. Therefore the master sshd daemon runs as root and spawns children for every connection (which stay under userid 0); once login is completed (either by password or public/private key), another child running with the login user's identity is spawned. This child then starts the shell.&lt;/P&gt;
&lt;P&gt;12073 should be your master sshd with parent process 1.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Aug 2017 20:17:08 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/What-part-of-SAS-or-Grid-process-runs-as-ROOT-rather-than-the/m-p/386407#M9975</guid>
      <dc:creator>Kurt_Bremser</dc:creator>
      <dc:date>2017-08-08T20:17:08Z</dc:date>
    </item>
    <item>
      <title>Re: What part of SAS or Grid process runs as ROOT rather than the User?</title>
      <link>https://communities.sas.com/t5/Administration-and-Deployment/What-part-of-SAS-or-Grid-process-runs-as-ROOT-rather-than-the/m-p/386504#M9983</link>
      <description>&lt;P&gt;Indeed, as&amp;nbsp;&lt;a href="https://communities.sas.com/t5/user/viewprofilepage/user-id/11562"&gt;@Kurt_Bremser&lt;/a&gt;&amp;nbsp;wisely said. On simple words: the initial process must be always be spawned as root, but just for connections to protected ports. Afterwards, any other process will be owned by the appropiate user.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On Linux there are many applications that run on the same way, and it is due to Linux security policies. A very common example are the web servers (such as Apache). If you want a web server to provide service on default ports 80 (http) or 443 (https), the inital process to listen on those ports must be owned by root. Any other child process will be owner by the user assigned to thr web server.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Aug 2017 07:30:56 GMT</pubDate>
      <guid>https://communities.sas.com/t5/Administration-and-Deployment/What-part-of-SAS-or-Grid-process-runs-as-ROOT-rather-than-the/m-p/386504#M9983</guid>
      <dc:creator>JuanS_OCS</dc:creator>
      <dc:date>2017-08-09T07:30:56Z</dc:date>
    </item>
  </channel>
</rss>

