Gentoo Archives: gentoo-hardened

From: Richard Simpson <richard.simpson@×××××.com>
To: Peter Buettner <pb@××××××××××××.de>, gentoo-hardened@l.g.o
Subject: RE: [gentoo-hardened] su and newrole do not work from normal user account
Date: Thu, 09 Sep 2004 16:21:43
Message-Id: BJENLMGHDPAAAGKKPOFOIEBGCFAA.richard.simpson@wgint.com
In Reply to: [gentoo-hardened] su and newrole do not work from normal user account by Peter Buettner
1 > -----Original Message-----
2 > From: Peter Buettner [mailto:pb@××××××××××××.de]
3 > Sent: Thursday, September 09, 2004 9:43 AM
4 > To: gentoo-hardened@l.g.o
5 > Subject: [gentoo-hardened] su and newrole do not work from normal user
6 > account
7 >
8 >
9 > Hello,
10 >
11 > I performed a stage1 install from the hardened gentoo CD.
12 > Installation works fine and without problems.
13 >
14 > But with the loaded policy it is not possible to do newrole -r or
15 > su - from normal user account.
16 >
17
18 I believe you would need to allow the role transition. See staff.te. The
19 default policy seems to only allow role transitions between staff and
20 sysadm. Rather than allowing a role transition to/from the unprivileged
21 user_r, it would be more secure to instead grant additional privileges to an
22 individual user, or create a new role with privileges applicable for a group
23 of users. See staff.te for ideas on this.
24
25 Richard.
26
27
28 --
29 gentoo-hardened@g.o mailing list

Replies