Re: Sun Application Server Drop Privs



Regarding (b), even if you run the server as root, you can change the
owners &/or groups of the files so that non-root users can change them.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Haim (Howard) Roman
Computer Center, Jerusalem College of Technology
roman@xxxxxxxxx
Phone: 052-8-592-599 (6022 from within Machon Lev)



-------- Original Message --------
Subject: Sun Application Server Drop Privs
From: Crist J. Clark <cristclark@xxxxxxxxxxx>
To: focus-sun@xxxxxxxxxxxxxxxxx
Date: Tue 24 Apr 2007 03:11:02 AM IDT
We're using Sun Java System Application Server 8.1. I know
the software is designed so it can be run as a non-root user,
but right now, we have to run it as root since it binds to ports
80/tcp and 443/tcp.

I've hit SunSolve, docs.sun.com, and Google, but can't seem to
find out how to get it to drop privs to a non-root user after
grabbing the low-numbered ports. Anyone know how to do this?
I'd rather (a) not have this monster run as root if it doesn't
have to and (b) not have the web app developers have to get a
sys admin to make changes as root for them whenever they want
to tweak some file.




Relevant Pages

  • RE: Sun Application Server Drop Privs
    ... Have you tried creating a properties file or editing the existing properties ... I know for the Sun Proxy server you can create a properties ... the software is designed so it can be run as a non-root user, ... we have to run it as root since it binds to ports ...
    (Focus-SUN)
  • Re: [RFC] enhancing the kernels graphics subsystem
    ... The userspace X server SHOULD be running under a non-root user, ... "I need root to do graphics" is a myopic, ...
    (Linux-Kernel)
  • [UNIX] HP-UX Setuid RLPDaemon Illicit File Writes
    ... When run by a non-root user it can create/append a logfile owned ... supply data to add to files he chooses and thereby get root. ... HP's alert "Sec. Vulnerability in rlpdaemon" was released ...
    (Securiteam)
  • Sun Application Server Drop Privs
    ... We're using Sun Java System Application Server 8.1. ... the software is designed so it can be run as a non-root user, ... grabbing the low-numbered ports. ... I'd rather not have this monster run as root if it doesn't ...
    (Focus-SUN)
  • Re: system() with 2 commands
    ... I would love to do this as a non-root user, ... unsuccessful in the future in allow another user to execute a command ... Also, I do have ssh ... server I am not root, but I need to perform a useradd... ...
    (comp.lang.perl.misc)