Skip to content
Snippets Groups Projects
Unverified Commit 5863adf9 authored by anarcat's avatar anarcat
Browse files

word wrap

parent b8ebb163
No related branches found
No related tags found
No related merge requests found
......@@ -18,9 +18,10 @@ There are multiple possible access levels, often conflated:
their SSH keys authorized to the root user (through Puppet, in the
`profile::admins::keys` Hiera field)
2. `sudo` to root: user has access to the `root` user through `sudo`,
using their `sudoPassword` defined in LDAP3. Puppet access: by virtue of being able to push to the Puppet git
repository, an admin necessarily gets `root` access everywhere,
because Puppet runs as root everywhere
using their `sudoPassword` defined in LDAP3. Puppet access: by
virtue of being able to push to the Puppet git repository, an
admin necessarily gets `root` access everywhere, because Puppet
runs as root everywhere
4. LDAP admin: a user member of the `adm` group in LDAP also gets
access everywhere through `sudo`, but also through being able to
impersonate or modify other users in LDAP
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment