All of lore.kernel.org
 help / color / mirror / Atom feed
* pam_namespace improvements ..
@ 2006-05-22  0:48 Janak Desai
  2006-05-22  1:05 ` Russell Coker
  0 siblings, 1 reply; 6+ messages in thread
From: Janak Desai @ 2006-05-22  0:48 UTC (permalink / raw)
  To: Russell Coker, tmraz, sds, valdis.kletnieks; +Cc: serue, klaus, selinux


Hi Russell,

After going thorugh the pam_namespace thread again and after talking to
some of my peeps, I do see that a mode 000 instance parent can thwart
attacks by non-root daemons and non-polyinstanted users on polyinstanted
users.

The current implementation of pam_namespace already depends on the
existance of the instance parent and allows the admin to configure the names
of different instances. I will update the namespace.conf man page, and
the comment text in the namespace.conf file to guide admins to
appropriately create a different instance parent (and not use the poly
dir itself, like the current example suggests). That way, an admin can
create an intermediate directory like .inst with 000 or create a whole
different directory with 000.

Thanks.

-Janak



--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2006-06-01 16:52 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2006-05-22  0:48 pam_namespace improvements Janak Desai
2006-05-22  1:05 ` Russell Coker
2006-05-22 13:18   ` Janak Desai
2006-05-31 21:32     ` [PATCH] pam_namespace : option to check instance parent mode and man page(s) updates Janak Desai
     [not found]       ` <1149167654.3514.16.camel@perun.kabelta.loc>
2006-06-01 15:33         ` Janak Desai
2006-06-01 16:52       ` [PATCH] pam_namespace : option to check instance parent mode and man page(s) updates - v2 Janak Desai

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.