1 |
-----BEGIN PGP SIGNED MESSAGE----- |
2 |
Hash: SHA1 |
3 |
|
4 |
On Thursday 18 September 2003 11:13 am, Martin Bene wrote: |
5 |
- --SNIP-- |
6 |
|
7 |
> Definitely true, but I don't think I'm that far wrt my configuration. First |
8 |
> I need to really understand how the system works and what's going on -only |
9 |
> then does it make sense to start tuning. |
10 |
> |
11 |
> I think the default grsecurity policies could use some updates to make them |
12 |
> a really useful starting point instead of a source of pitfalls for the |
13 |
> unwary |
14 |
|
15 |
I would have to botagree and disagree with this. We do want it to be easy for |
16 |
people to not "fall in the pit". However, grsecurity is a "security" |
17 |
enhancement. We do want the defaults to be secure. Where does one draw the |
18 |
line between these goals? I am certain I would recieve agreement if I said |
19 |
that we all have a different viewpoint on the "correct" or "appropriate" |
20 |
answer to that one. :-) |
21 |
|
22 |
> Back to the log entries: the sshd entry is obvious now, I had overlooked |
23 |
> the "o" subject in the sshd acl and /dev/urandom is not explicitely listet |
24 |
> in the sshd acl. |
25 |
|
26 |
Ah, I missed that, too. |
27 |
|
28 |
> Understanding WHY it's not a good idea to let sshd inherit the default acls |
29 |
> is another matter. |
30 |
|
31 |
Because sshd is a tool to open a hole into your machine that allows people to |
32 |
remotely run whatever they want to. Under WinNT/2000/etc. ACLs on filesystem |
33 |
object (i.e.directories) are far to easy to abuse this way without realizing |
34 |
it. I could give examples, but I will hold off unless someone is really |
35 |
confused about this. |
36 |
|
37 |
> Could the /dev/urandom message for gradm -R be an artefact of reloading the |
38 |
> ruleset? |
39 |
|
40 |
That sounds reasonable to me (but I do not know that this is "the" truth). |
41 |
- -- |
42 |
Sincerely, |
43 |
Lamont R. Peterson <lrp@××××××××.com> |
44 |
-----BEGIN PGP SIGNATURE----- |
45 |
Version: GnuPG v1.2.2-rc1-SuSE (GNU/Linux) |
46 |
|
47 |
iD8DBQE/aeveg5LkF3+ZgzARAsNsAJwKlyNe+VpjairMtlExpmtEVWeSVwCeMB4d |
48 |
ICOxBhO2DiLXGjKWGucMkuo= |
49 |
=7cyq |
50 |
-----END PGP SIGNATURE----- |
51 |
|
52 |
|
53 |
-- |
54 |
gentoo-hardened@g.o mailing list |