Re: make world and setuid bits

From: Crist J. Clark (cjc@FreeBSD.ORG)
Date: 03/29/02


Date: Thu, 28 Mar 2002 20:40:53 -0800
From: "Crist J. Clark" <cjc@FreeBSD.ORG>
To: Garrett Wollman <wollman@lcs.mit.edu>

On Thu, Mar 28, 2002 at 09:55:52PM -0500, Garrett Wollman wrote:
> <<On Thu, 28 Mar 2002 17:43:04 -0800, "Crist J. Clark" <cjc@FreeBSD.ORG> said:
>
> > Some sites may use this policy, but I would never like it. It requires
> > direct logins as root.
>
> It may make some sense in limited circumstances. For example, my
> Kerberos KDC has only one interactive user (root), does not support
> network login (duh!), and is locked in a box in one of my machine
> rooms. *Any* escalation of privilege on that machine represents a
> serious security problem.

Again, personally, if more than one user has access to the machine, I
prefer to have people individual accounts and su(1) to root for the
sake of an audit trail (Obviously, people who have root and physical
access can almost certinly tamper with the logs, but it is still
useful). YMMV.

-- 
Crist J. Clark                     |     cjclark@alum.mit.edu
                                   |     cjclark@jhu.edu
http://people.freebsd.org/~cjc/    |     cjc@freebsd.org
To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message


Relevant Pages

  • Re: make world and setuid bits
    ... > direct logins as root. ... Kerberos KDC has only one interactive user (root), ... process which normally runs login is getty. ...
    (FreeBSD-Security)
  • Re: Password Aging and System Accounts
    ... > have a policy where they don't age their root passwords? ... the Policy of password aging apply to the root account, ... Logins from the system console as root are ...
    (comp.unix.admin)
  • Re: Password Aging and System Accounts
    ... > have a policy where they don't age their root passwords? ... the Policy of password aging apply to the root account, ... Logins from the system console as root are ...
    (comp.security.unix)
  • Re: GPO Limts
    ... The exception to these rules is block policy inheritance, ... The Computer section of a GPO is applied during boot-up. ... Computer OU (diffrent GP applied with same entrys) ... same entrys as both root and computer) ...
    (microsoft.public.windows.server.active_directory)
  • Re: [kde-linux] Hotplug (USB) Problem with KDE 3.5.5 - dbus/hal - SOLVED
    ... Not by adding ALL users to the group 'plugdev' ... ... dbus and hal. ... If you look at the config file '/etc/dbus-1/system.d/hal.conf' you can find the following policy ... # Xstartup - run as root before session starts ...
    (KDE)

Loading