[6293] in RedHat Linux List
Re: More redhat-4.0 security
daemon@ATHENA.MIT.EDU (Jeremy)
Tue Nov 26 16:28:57 1996
To: redhat-list@redhat.com
cc: heffner@medinah.televiso.com
In-reply-to: Your message of "Tue, 26 Nov 1996 14:35:35 EST."
<Pine.SUN.3.91.961126142623.17018C-100000@bigbang.phy.duke.edu>
Date: Tue, 26 Nov 1996 14:12:45 -0700
From: Jeremy <heffner@medinah.televiso.com>
Resent-From: redhat-list@redhat.com
Reply-To: redhat-list@redhat.com
In message <Pine.SUN.3.91.961126142623.17018C-100000@bigbang.phy.duke.edu>
Kyle
Ferrio mumbled
>> Whereas I certainly don't, some sites allow people to install their own
>> binaries/other stuff under /usr/local. This might open up trojan
>> possibilities.
>Doesn't a site that gives normal users write privliges on /usr/local/bin
>deserve whatever happens, good or bad? This seems like a really bad
plan.
>A better approach might be to create a (small) group for trusted
>maintainers of local packages, and chown /usr/local/bin to them. [This is
>more flexibly done with afs acls than plain unix, of course.] But the
>general idea is that if a lot of users need a binary, someone trustworthy
>should volunteer to maintain it. If a binary isn't needed by a lot of
>users, it probably doesn't belong in /usr/local/bin. This is arguable, to
>be sure.
I tottally agree. In general, you dont want any 'normal' user to be able
to affect any of the other users (including the priviliged users) in any
way. If someone wants their own version of whatever, they can just make a
directory ~/bin and ~/lib, and add that to their path. It works just
fine, is used rather commonly.
As for having other people with more privilaged access, that is also a
good idea, as long as you dont give them the root passwd, use SUDO!
Everyone should be using sudo, its heaven for finding out what the hell
someone did so you can go back and fix it.
Just my 2 cents..
-jeremy
-------------------------------------------------------------------------
Jeremy Heffner | Televiso.com System Administration
Finger for PGP public-key | My thoughts, my brains, noone else's
-------------------------------------------------------------------------
--
PLEASE read the Red Hat FAQ, Tips, Errata and the MAILING LIST ARCHIVES!
________________________________________________________________________
http://www.redhat.com/RedHat-FAQ http://www.redhat.com/RedHat-Errata
http://www.redhat.com/RedHat-Tips http://www.redhat.com/mailing-lists
------------------------------------------------------------------------
To unsubscribe: mail -s unsubscribe redhat-list-request@redhat.com < /dev/null