1 |
On Friday 06 October 2006 01:07, Miguel Figueiredo Mascarenhas Sousa Filipe |
2 |
wrote: |
3 |
> Hi all, |
4 |
> |
5 |
> What do you guys think of: |
6 |
> |
7 |
> - reduce the number of setuid to the maximum |
8 |
> - reduce the number of daemons running has root. |
9 |
|
10 |
Sounds good. |
11 |
|
12 |
> has example, openbsd and openwall (among others) both try to have sane |
13 |
> setuids and setguids for things like: |
14 |
> - cron/at service |
15 |
> - syslog and klogd |
16 |
> - passwd (on openwall, not shure about openbsd) |
17 |
> and much more.. |
18 |
> |
19 |
> those are the things I miss most, a sane default filesystem system |
20 |
> permissions and a lot of services that can be running without root |
21 |
> privileges.. |
22 |
> |
23 |
> One interesting Idea would be to use the /etc/shadow replacement that |
24 |
> is present in openwall |
25 |
|
26 |
Not something I've looked at. Could you describe this a bit more? |
27 |
|
28 |
> anyone knows if any of these things/ideas is being followed, if so, |
29 |
> were can I find pointers to it? |
30 |
|
31 |
for the suid/daemons its generally up to each package maintainer. |
32 |
|
33 |
What I'd suggest is to put in a bug report on how to make each package not |
34 |
suid or root daemon. |
35 |
|
36 |
Also look for a place in the gentoo documentation to put these desireable |
37 |
qualities and put some suggested text. |
38 |
|
39 |
> I |
40 |
> |
41 |
> |
42 |
> best regards, |
43 |
> |
44 |
> |
45 |
> -- |
46 |
> Miguel Sousa Filipe |
47 |
|
48 |
-- |
49 |
Daniel Black <dragonheart@g.o> |
50 |
Gentoo Foundation |
51 |
-- |
52 |
gentoo-hardened@g.o mailing list |