Re: Root can't delete files

From: Fabrice MARIE (fabrice@celestix.com)
Date: 10/11/01


Message-Id: <200110110752.f9B7qHe04476@fabrice.celestix.com>
From: Fabrice MARIE <fabrice@celestix.com>
To: Jose Nazario <jose@biocserver.BIOC.cwru.edu>, Nicolas Bock <nbock@buffalo.edu>
Subject: Re: Root can't delete files
Date: Thu, 11 Oct 2001 15:52:16 +0800


Hi,

On Thursday 11 October 2001 03:18, Jose Nazario wrote:
> thats very true, yes. however, LIDS can be used to prevent this, so that
> with kernel settings (which require a reboot to effect) even root cannot
> make modifications, no matter what they try, not until these kernel flags
> are cleared and the system rebooted. couple that to firmware/BIOS level
> passwords, and you're set. you can build up a trusted computing base this
> way. something to consider. and sorry for any confusion earlier, thanks for
> requesting the clarification.

I like very much RSBAC for it's desing/power :
http://www.rsbac.org/
You can administer your box using roles (among others
but roles are powerful and simple...) to prevent
fools from playing around or simply to prevent admin's typos from
becoming a disaster.

Have a nice day,

Fabrice.

-- 
Fabrice MARIE
Senior R&D Engineer
Celestix Networks
http://www.celestix.com/

"Silly hacker, root is for administrators" -Unknown



Relevant Pages

  • Re: Root cant delete files
    ... Subject: Root can't delete files ... > chattr -i prevent root from doing anything to a file? ... but not with the flag set. ... with kernel settings even root cannot ...
    (Focus-Linux)
  • Re: Root access
    ... >>> that a determined sysadmin with root access could get around it ... may be nice for an ISP who is selling "full root ... What is LIDS ... A kernel patch and admin tool to enhance the linux kernel security ...
    (comp.os.linux.security)
  • Re: AAARRRGGGGHHHH! How does one set up woody to talk to an HP Deskjet 882C printer?
    ... >Cups will let you administer your own printer. ... What's the difference between the 'root username' and 'root'? ... I don't really expect you to need to upgrade anything. ...
    (Debian-User)
  • Re: root password setting unoffered at install
    ... You are not supposed to administer Ubuntu as root. ... the way Ubuntu works is that you are asked to create one intial user. ... install. ...
    (Ubuntu)
  • Re: Directory permissions (keep root out)
    ... >> I work for a research entity which has some software that is not ... You can do it if you run an enhanced kernel such as LIDS. ... can even hide a file/directory/filesystem from root if that is your ...
    (comp.os.linux.security)