Ad Widget

Collapse

Need Feedback for Zabbix

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • rajveer.singh
    Junior Member
    • May 2011
    • 2

    #1

    Need Feedback for Zabbix

    Hello All,

    I am new to this zabbix, I have seen a quick overview, screenshot and it seems very appealing. I am just planning to evaluate it's features. I wanted to know if it is deployed on one server and running with non root user but full administration access of zabbix available to other team. I am just curious to know, if they can get the administrative/priviliged access of the system using zabbix. Thanks in advance for you time and help.

    Regards,
    Rajveer Singh
  • tzn
    Junior Member
    • Apr 2011
    • 19

    #2
    Originally posted by rajveer.singh
    Hello All,

    I am new to this zabbix, I have seen a quick overview, screenshot and it seems very appealing. I am just planning to evaluate it's features. I wanted to know if it is deployed on one server and running with non root user but full administration access of zabbix available to other team. I am just curious to know, if they can get the administrative/priviliged access of the system using zabbix. Thanks in advance for you time and help.

    Regards,
    Rajveer Singh
    I'm not quite sure what do you mean, but I will try to answer your questions

    1. It may be installed on one server
    2. It uses separate user and doesn't need elevated privileges
    3. It does not need administrative access
    4. Default configuration is quite safe and does not allow administrative access.
    5. Zabbix code is OS so I assume (considering it's popularity) it' is quite well audited

    Comment

    • rajveer.singh
      Junior Member
      • May 2011
      • 2

      #3
      Originally posted by tzn
      I'm not quite sure what do you mean, but I will try to answer your questions

      1. It may be installed on one server
      2. It uses separate user and doesn't need elevated privileges
      3. It does not need administrative access
      4. Default configuration is quite safe and does not allow administrative access.
      5. Zabbix code is OS so I assume (considering it's popularity) it' is quite well audited
      Thanks TZN for the information.

      Sorry for not making myself more precise earlier. Let me try to explain it again.

      There is one user admin which has full administrative access on zabbix but he don't have any root access on the Operating System(RHEL). As being zabbix admin user, he has full control on zabbix. So I wanted to know, can he get the OS level privileged access using his zabbix admin access whereas zabbix is running as normal user not root.

      I have this question, because, the team who will manage zabbix will be different than who manages the OS.

      Thanks

      Comment

      • qix
        Senior Member
        Zabbix Certified SpecialistZabbix Certified Professional
        • Oct 2006
        • 423

        #4
        Hi,

        Zabbix uses it's own user database (in the MySQL DB) which is completely independent from the OS.
        So, it should be quite safe in the deployment situation mentioned.

        Alternatively you can use LDAP to consolidate useraccounts if you wish.
        With kind regards,

        Raymond

        Comment

        • tzn
          Junior Member
          • Apr 2011
          • 19

          #5
          In Zabbix security model Zabbix administrator cannot gain administrative access on monitored hosts. Of course, there always might be some security flow, but we are considering ideal scenario.

          Comment

          Working...