[6293] in RedHat Linux List

home help back first fref pref prev next nref lref last post

Re: More redhat-4.0 security

daemon@ATHENA.MIT.EDU (Jeremy)
Tue Nov 26 16:28:57 1996

To: redhat-list@redhat.com
cc: heffner@medinah.televiso.com
In-reply-to: Your message of "Tue, 26 Nov 1996 14:35:35 EST."
             <Pine.SUN.3.91.961126142623.17018C-100000@bigbang.phy.duke.edu> 
Date: Tue, 26 Nov 1996 14:12:45 -0700
From: Jeremy <heffner@medinah.televiso.com>
Resent-From: redhat-list@redhat.com
Reply-To: redhat-list@redhat.com

In message <Pine.SUN.3.91.961126142623.17018C-100000@bigbang.phy.duke.edu>
Kyle 
Ferrio mumbled
>> Whereas I certainly don't, some sites allow people to install their own
>> binaries/other stuff under /usr/local. This might open up trojan
>> possibilities.
>Doesn't a site that gives normal users write privliges on /usr/local/bin
>deserve whatever happens, good or bad?  This seems like a really bad 
plan. 
>A better approach might be to create a (small) group for trusted
>maintainers of local packages, and chown /usr/local/bin to them.  [This is
>more flexibly done with afs acls than plain unix, of course.] But the
>general idea is that if a lot of users need a binary, someone trustworthy
>should volunteer to maintain it.  If a binary isn't needed by a lot of
>users, it probably doesn't belong in /usr/local/bin. This is arguable, to
>be sure. 

I tottally agree. In general, you dont want any 'normal' user to be able 
to affect any of the other users (including the priviliged users) in any 
way.  If someone wants their own version of whatever, they can just make a 
directory ~/bin and ~/lib, and add that to their path.  It works just 
fine, is used rather commonly.

As for having other people with more privilaged access, that is also a 
good idea, as long as you dont give them the root passwd, use SUDO!  
Everyone should be using sudo, its heaven for finding out what the hell 
someone did so you can go back and fix it.

Just my 2 cents..
-jeremy
-------------------------------------------------------------------------
      Jeremy Heffner             |  Televiso.com System Administration   
  Finger for PGP public-key      |  My thoughts, my brains, noone else's
-------------------------------------------------------------------------



--
  PLEASE read the Red Hat FAQ, Tips, Errata and the MAILING LIST ARCHIVES!
  ________________________________________________________________________
  http://www.redhat.com/RedHat-FAQ   http://www.redhat.com/RedHat-Errata
  http://www.redhat.com/RedHat-Tips  http://www.redhat.com/mailing-lists
  ------------------------------------------------------------------------
To unsubscribe: mail -s unsubscribe redhat-list-request@redhat.com < /dev/null


home help back first fref pref prev next nref lref last post