Gentoo Archives: gentoo-hardened

From: kakou <kakou@×××××.org>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Problem with grsecurity
Date: Sun, 19 Nov 2006 16:47:24
Message-Id: 1163954716.31459.24.camel@po-briffaut.kakou.org
In Reply to: Re: [gentoo-hardened] Problem with grsecurity by atoth@atoth.sote.hu
1 ok.
2 Another question, why the new gradm (10/2006) is not present in portage?
3 I have tried it and It works well.
4
5 Morover, I have tried the complementary learning mode on subject after
6 created a policy.
7 => on the first host, It produce nothing and take 100% CPU during long
8 hour
9 => on the second host, It produce new rules. But when I had it, the
10 system is broken.
11 Do you have testing it ?
12
13 Le dimanche 19 novembre 2006 à 17:09 +0100, atoth@××××××××××.hu a
14 écrit :
15 > On Vas, November 19, 2006 14:57, kakou wrote:
16 > > I already have these options (and I already have read manuals ...).
17 > Sorry for the RTFM. Just make sure, that you have all necessary options
18 > for roles root and admin. Grsec should add the rules automatically to the
19 > respective roles.
20 >
21 > Regards,
22 > Dw.
23 >
24 > >
25 > > It's not a blocking problem : I can authenticate to admin role ... but
26 > > it's strange
27 > >
28 > > Le dimanche 19 novembre 2006 ŕ 13:11 +0100, atoth@××××××××××.hu a
29 > > écrit :
30 > >> My tip:
31 > >>
32 > >> Check your "role root".
33 > >> Does it look something like this:
34 > >> >>>
35 > >> role root uG
36 > >> role_transitions admin
37 > >> <<<
38 > >>
39 > >> If not, than please read the manual.
40 > >>
41 > >> Also check your "role admin"
42 > >> It should contain someting like this:
43 > >> >>>
44 > >> role admin sA
45 > >> subject / rvka
46 > >> <<<
47 > >>
48 > >> Please study the avaiable options.
49 > >>
50 > >> Regards,
51 > >> Dw.
52 > >>
53 > >> --
54 > >> dr Tóth Attila, Radiológus Szakorvos jelölt, 06-20-825-8057,
55 > >> 06-30-5962-962
56 > >> Attila Toth MD, Radiologist in Training, +36-20-825-8057,
57 > >> +36-30-5962-962
58 > >>
59 > >> On Szo, November 18, 2006 14:44, kakou wrote:
60 > >> > Hello,
61 > >> > I have installed grsecurity and obtained a policy with grlearn.
62 > >> > When I use gradm -a admin, I have this error in log :
63 > >> >
64 > >> > (root:U:/sbin/gradm) use of CAP_SYS_ADMIN denied
65 > >> > for /sbin/gradm[gradm:4373] uid/euid:0/0 gid/egid:0/0,
66 > >> > parent /bin/bash[bash:10954] uid/euid:0/0 gid/egid:0/0
67 > >> >
68 > >> > I have no subject for "/sbin/gradm" for the role root and if I try to
69 > >> > add this subject, I have an error because this subject already exist
70 > >> > (???).
71 > >> > Moerover any subject is a simlinks to "/sbin/gradm".
72 > >> >
73 > >> > I have this error (but all is running fine :)) on two server.
74 > >> > The first one with a tweaked policy and the second one with the
75 > >> default
76 > >> > policy obtained with grlearn.
77 > >> >
78 > >> > Someone has an idea?
79 > >> >
80 > >> >
81 > >> > Kakou
82 > >> >
83 > >>
84 > >>
85 > >
86 >
87 >

Attachments

File name MIME type
signature.asc application/pgp-signature