1 |
Am Samstag, 6. November 2004 16:27 schrieb Chris PeBenito: |
2 |
> On Sat, 2004-11-06 at 12:37 +0100, Christian Heim wrote: |
3 |
> > [ ... ] |
4 |
> |
5 |
> This is the expected behavior for all services... |
6 |
|
7 |
Didn't know this, so I asked ... |
8 |
|
9 |
> |
10 |
> > Is there a possibility to change this to the behaviour like sshd (which |
11 |
> > isn't asking after root's password to start/stop/restart) |
12 |
> |
13 |
> and this is a broken behavior. Service start/stop requires a SELinux |
14 |
> identity change to system_u, so the init scripts run in the right |
15 |
> context. Since SELinux identities are not supposed to change, it is a |
16 |
> privileged operation, and thats why the user is authenticated. You can |
17 |
> adjust the run_init pam settings to change the authentication behavior, |
18 |
> to make wheel group or root sufficient for example, but its not |
19 |
> suggested for production systems. |
20 |
|
21 |
Thank you two Chris & Richard |
22 |
-- |
23 |
-- |
24 |
Christian Thomas Heim |
25 |
Auszubildender im Rechenzentrum der Universität Greifswald |
26 |
Friedrich-Ludwig-Jahnstraße 14d |
27 |
17487 Greifswald |
28 |
Telefon: 03834/86-1407 |
29 |
eMail: heim@××××××××××××××.de |
30 |
|
31 |
-- |
32 |
gentoo-hardened@g.o mailing list |