[prev in list] [next in list] [prev in thread] [next in thread] 

List:       rsbac
Subject:    Re: AW: [rsbac] Problem with /bin/login
From:       Amon Ott <ao () rsbac ! org>
Date:       2002-05-06 9:16:32
[Download RAW message or body]

On Monday, 6. May 2002 11:04, Toggweiler Stephan wrote:
> Thank you it works now.
> 
> When I login as root (on the console or ssh) the role will not be changed to
> System_Admin, is that the problem that there is no real setuid() when you
> login as root?

Right. You might patch login to do that, it will also give you more control 
over who can login. With RSBAC 1.1.2, there is also no control if you setuid 
to the same uid. 1.2.0 always checks.
 
> I have now disallowed root to login vom console or per ssh, and su from
> secoff to get root privileges.

That will do.

Amon.
--
http://www.rsbac.org
_______________________________________________
rsbac mailing list
rsbac@rsbac.org
http://www.rsbac.org/mailman/listinfo/rsbac
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic