Re: how to restrict user from running some downloaded prgm?

From: James T (turajb_at__NOSPAM_hoflink.com)
Date: 08/14/05

  • Next message: jayjwa: "Re: HELP WITH FTP"
    Date: Sat, 13 Aug 2005 22:21:59 -0400
    
    

    On Fri, 12 Aug 2005 09:48:22 -0700, Guagua wrote:

    > For example, user can download another version of some program (like
    > mozilla), and install in their own directory(like run
    > ./mozilla-install-bin). But I don't want them to do that, since they
    > should really use the shared one in /usr directory. One way to do that
    > is to restrict them from running the installation program. How could I
    > do that? Or any other ways?
    >
    > Thanks a lot.

    Maybe I'm missing something here, but wouldn't SELinux (secured enabled
    linux) do that? It is designed to enforce security policies and restrict
    the system to allowed programs.

    I believe that if you setup SELinux to restrict your system to only
    allowed/registered applications, that should do it.

    Then if you want to further lock down the usage on your system, mix that
    with removing execute ability on /home, enabling disk quotas, and removing
    shell access to those users which do not need it. At least this is where
    I would begin if I have to do this.

    I also however agree with the other posts, that you should talk with your
    users about their needs, before you start putting extreme security
    measures in place.

    I hope this helps...


  • Next message: jayjwa: "Re: HELP WITH FTP"

    Relevant Pages

    • Re: What Linux distro to use for old Intel machine, that fits on CDs?
      ... faster download speeds from this site". ... click install is what you want then either the Fedora 9 or Ubuntu Live CDs ... if LiveCD supports a dialup modem, ... I'll just reinstall Windows 2000 on this old system and maybe restrict ...
      (comp.os.linux.misc)
    • Re: Novell hits homerun
      ... should keep Novell from being sued by someone in the entertainment industry. ... If you write s..t, write shit, or don't write it at all. ... In no way doe SUSE attempt to restrict you to install anything. ...
      (alt.os.linux.suse)
    • Re: Restrict Install Privelidges
      ... Moving them to a different group will restrict their ... abilities to install infected garbage. ... install useful apps, ... Sounds like moving the users into different groups is the solution to your ...
      (microsoft.public.win2000.security)
    • Re: Novell hits homerun
      ... That attempt is a crock of s..t but should keep Novell from being sued by someone in the entertainment industry. ... In no way doe SUSE attempt to restrict you to install anything. ... I have tried several times to install video players, including following the directions given in other posts, and it has never worked, even when it completed the install successfully - it still would not open most small videos freely available on the web and not at all related to DVD. ... a few minutes ago and used their process to send additional letters. ...
      (alt.os.linux.suse)
    • Re: Can I use Group Policy to deny software installation?
      ... In AD's GPO you have the option to restrict what software should be run. ... There's very long and trial-and-error path, ... > msi install will have no impact on an exe install that does not use the ... > Windows installer technology. ...
      (microsoft.public.win2000.security)