Configuring a supplemental group for users permitted to switch to the root user prevents unauthorized users from accessing the root account, even with knowledge of the root credentials. Applicable, but permanent not-a-finding - Not a General Purpose (GP) OS. VMware's ESXi-v5 is a multi-user kernel where all users are "administrator" with either: Administrator with Full and partial (configurable) privileges, Read-only, or No Access. In this case, the file owner, group-owner and mode(s) have no meaning. The "su" command use is unrestricted. |