Gentoo Archives: gentoo-hardened

From: Christian Heim <heim@××××××××××××××.de>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] mysql-4.0.22 asking to "Authenticating root"
Date: Sat, 06 Nov 2004 15:56:35
Message-Id: 200411061700.05977.heim@uni-greifswald.de
In Reply to: Re: [gentoo-hardened] mysql-4.0.22 asking to "Authenticating root" by Chris PeBenito
1 Am Samstag, 6. November 2004 16:27 schrieb Chris PeBenito:
2 > On Sat, 2004-11-06 at 12:37 +0100, Christian Heim wrote:
3 > > [ ... ]
4 >
5 > This is the expected behavior for all services...
6
7 Didn't know this, so I asked ...
8
9 >
10 > > Is there a possibility to change this to the behaviour like sshd (which
11 > > isn't asking after root's password to start/stop/restart)
12 >
13 > and this is a broken behavior. Service start/stop requires a SELinux
14 > identity change to system_u, so the init scripts run in the right
15 > context. Since SELinux identities are not supposed to change, it is a
16 > privileged operation, and thats why the user is authenticated. You can
17 > adjust the run_init pam settings to change the authentication behavior,
18 > to make wheel group or root sufficient for example, but its not
19 > suggested for production systems.
20
21 Thank you two Chris & Richard
22 --
23 --
24 Christian Thomas Heim
25 Auszubildender im Rechenzentrum der Universität Greifswald
26 Friedrich-Ludwig-Jahnstraße 14d
27 17487 Greifswald
28 Telefon: 03834/86-1407
29 eMail: heim@××××××××××××××.de
30
31 --
32 gentoo-hardened@g.o mailing list