Gentoo Archives: gentoo-hardened

From: Daniel Black <dragonheart@g.o>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Reducing the number of setuids, root user daemons..et al
Date: Sat, 07 Oct 2006 23:29:59
Message-Id: 200610080941.39007.dragonheart@gentoo.org
In Reply to: [gentoo-hardened] Reducing the number of setuids, root user daemons..et al by Miguel Figueiredo Mascarenhas Sousa Filipe
1 On Friday 06 October 2006 01:07, Miguel Figueiredo Mascarenhas Sousa Filipe
2 wrote:
3 > Hi all,
4 >
5 > What do you guys think of:
6 >
7 > - reduce the number of setuid to the maximum
8 > - reduce the number of daemons running has root.
9
10 Sounds good.
11
12 > has example, openbsd and openwall (among others) both try to have sane
13 > setuids and setguids for things like:
14 > - cron/at service
15 > - syslog and klogd
16 > - passwd (on openwall, not shure about openbsd)
17 > and much more..
18 >
19 > those are the things I miss most, a sane default filesystem system
20 > permissions and a lot of services that can be running without root
21 > privileges..
22 >
23 > One interesting Idea would be to use the /etc/shadow replacement that
24 > is present in openwall
25
26 Not something I've looked at. Could you describe this a bit more?
27
28 > anyone knows if any of these things/ideas is being followed, if so,
29 > were can I find pointers to it?
30
31 for the suid/daemons its generally up to each package maintainer.
32
33 What I'd suggest is to put in a bug report on how to make each package not
34 suid or root daemon.
35
36 Also look for a place in the gentoo documentation to put these desireable
37 qualities and put some suggested text.
38
39 > I
40 >
41 >
42 > best regards,
43 >
44 >
45 > --
46 > Miguel Sousa Filipe
47
48 --
49 Daniel Black <dragonheart@g.o>
50 Gentoo Foundation
51 --
52 gentoo-hardened@g.o mailing list

Replies

Subject Author
Re: [gentoo-hardened] Reducing the number of setuids, root user daemons..et al Miguel Figueiredo Mascarenhas Sousa Filipe <miguel.filipe@×××××.com>