Gentoo Archives: gentoo-hardened

From: kakou <kakou@×××××.org>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Problem with grsecurity
Date: Sun, 19 Nov 2006 14:00:20
Message-Id: 1163944663.31459.18.camel@po-briffaut.kakou.org
In Reply to: Re: [gentoo-hardened] Problem with grsecurity by atoth@atoth.sote.hu
1 I already have these options (and I already have read manuals ...).
2
3 It's not a blocking problem : I can authenticate to admin role ... but
4 it's strange
5
6 Le dimanche 19 novembre 2006 à 13:11 +0100, atoth@××××××××××.hu a
7 écrit :
8 > My tip:
9 >
10 > Check your "role root".
11 > Does it look something like this:
12 > >>>
13 > role root uG
14 > role_transitions admin
15 > <<<
16 >
17 > If not, than please read the manual.
18 >
19 > Also check your "role admin"
20 > It should contain someting like this:
21 > >>>
22 > role admin sA
23 > subject / rvka
24 > <<<
25 >
26 > Please study the avaiable options.
27 >
28 > Regards,
29 > Dw.
30 >
31 > --
32 > dr Tóth Attila, Radiológus Szakorvos jelölt, 06-20-825-8057, 06-30-5962-962
33 > Attila Toth MD, Radiologist in Training, +36-20-825-8057, +36-30-5962-962
34 >
35 > On Szo, November 18, 2006 14:44, kakou wrote:
36 > > Hello,
37 > > I have installed grsecurity and obtained a policy with grlearn.
38 > > When I use gradm -a admin, I have this error in log :
39 > >
40 > > (root:U:/sbin/gradm) use of CAP_SYS_ADMIN denied
41 > > for /sbin/gradm[gradm:4373] uid/euid:0/0 gid/egid:0/0,
42 > > parent /bin/bash[bash:10954] uid/euid:0/0 gid/egid:0/0
43 > >
44 > > I have no subject for "/sbin/gradm" for the role root and if I try to
45 > > add this subject, I have an error because this subject already exist
46 > > (???).
47 > > Moerover any subject is a simlinks to "/sbin/gradm".
48 > >
49 > > I have this error (but all is running fine :)) on two server.
50 > > The first one with a tweaked policy and the second one with the default
51 > > policy obtained with grlearn.
52 > >
53 > > Someone has an idea?
54 > >
55 > >
56 > > Kakou
57 > >
58 >
59 >

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies

Subject Author
Re: [gentoo-hardened] Problem with grsecurity atoth@××××××××××.hu