[j-nsp] shell-based users

Jason Rowley jason.rowley.lists at gmail.com
Thu Jun 30 15:26:14 EDT 2005


I was asked to create a new user for non-engineers to have access to a
few simple commands such as ping and telnet. We don't want to give
them access to anything else, and we really don't want them exploring
on the routers.

My idea was to see if we could create a script-based menu to only give
them access to what they need. I understand we can limit their
permissions, but want to be able to dump them right into the script
when they login.

I thought I'd be able to add our script to /etc/shells, and create a
user with that shell in the master.passwd, however when we do anything
to rebuild the passwd database, something changes their shell back to
/usr/sbin/cli.

Is there anyway to do this? Or do I have to create a new login class
and only permit them to access to shell?

Thanks!
-j



More information about the juniper-nsp mailing list