Gentoo Archives: gentoo-hardened

From: atoth@××××××××××.hu
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Problem with grsecurity
Date: Sun, 19 Nov 2006 16:11:25
Message-Id: 64661.62.165.243.164.1163952576.squirrel@atoth.sote.hu
In Reply to: Re: [gentoo-hardened] Problem with grsecurity by kakou
1 On Vas, November 19, 2006 14:57, kakou wrote:
2 > I already have these options (and I already have read manuals ...).
3 Sorry for the RTFM. Just make sure, that you have all necessary options
4 for roles root and admin. Grsec should add the rules automatically to the
5 respective roles.
6
7 Regards,
8 Dw.
9
10 >
11 > It's not a blocking problem : I can authenticate to admin role ... but
12 > it's strange
13 >
14 > Le dimanche 19 novembre 2006 à 13:11 +0100, atoth@××××××××××.hu a
15 > écrit :
16 >> My tip:
17 >>
18 >> Check your "role root".
19 >> Does it look something like this:
20 >> >>>
21 >> role root uG
22 >> role_transitions admin
23 >> <<<
24 >>
25 >> If not, than please read the manual.
26 >>
27 >> Also check your "role admin"
28 >> It should contain someting like this:
29 >> >>>
30 >> role admin sA
31 >> subject / rvka
32 >> <<<
33 >>
34 >> Please study the avaiable options.
35 >>
36 >> Regards,
37 >> Dw.
38 >>
39 >> --
40 >> dr Tóth Attila, Radiológus Szakorvos jelölt, 06-20-825-8057,
41 >> 06-30-5962-962
42 >> Attila Toth MD, Radiologist in Training, +36-20-825-8057,
43 >> +36-30-5962-962
44 >>
45 >> On Szo, November 18, 2006 14:44, kakou wrote:
46 >> > Hello,
47 >> > I have installed grsecurity and obtained a policy with grlearn.
48 >> > When I use gradm -a admin, I have this error in log :
49 >> >
50 >> > (root:U:/sbin/gradm) use of CAP_SYS_ADMIN denied
51 >> > for /sbin/gradm[gradm:4373] uid/euid:0/0 gid/egid:0/0,
52 >> > parent /bin/bash[bash:10954] uid/euid:0/0 gid/egid:0/0
53 >> >
54 >> > I have no subject for "/sbin/gradm" for the role root and if I try to
55 >> > add this subject, I have an error because this subject already exist
56 >> > (???).
57 >> > Moerover any subject is a simlinks to "/sbin/gradm".
58 >> >
59 >> > I have this error (but all is running fine :)) on two server.
60 >> > The first one with a tweaked policy and the second one with the
61 >> default
62 >> > policy obtained with grlearn.
63 >> >
64 >> > Someone has an idea?
65 >> >
66 >> >
67 >> > Kakou
68 >> >
69 >>
70 >>
71 >
72
73
74 --
75 gentoo-hardened@g.o mailing list

Replies

Subject Author
Re: [gentoo-hardened] Problem with grsecurity kakou <kakou@×××××.org>