1 |
It is my understanding that dhcpcd client requires root or a |
2 |
privileged user. Am presently running dhcpcd in a chroot jail (ssp and |
3 |
grsecurity-hardened kernel) as user root (ugh). (This is a laptop used |
4 |
at hotspots, so I think I need to use dhcp). |
5 |
|
6 |
Other distributions distribute dhcpcd with a "paranoia" patch incorporated |
7 |
|
8 |
<http://www.episec.com/people/edelkind/patches/dhcp/dhcp-2.0+paranoia.patch> |
9 |
|
10 |
which allows the dropping of privilege and changing of user/group after startup. |
11 |
|
12 |
Questions: |
13 |
|
14 |
1 Does Gentoo have an "official" way to apply this patch. |
15 |
|
16 |
2 Presuming that it doesn't, I guess that I'll ebuild unpack: patch |
17 |
the source manually; ebuild merge !? |
18 |
|
19 |
3. Are there other ways to deal with this potential vulnerability |
20 |
(privileged process listening on an open port (68) )? (e.g. using |
21 |
selfdhcp and effecting a manual connection?) |
22 |
|
23 |
TIA, newbie |
24 |
-- |
25 |
gentoo-hardened@g.o mailing list |