Gentoo Archives: gentoo-hardened

From: atoth@××××××××××.hu
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Problem with grsecurity
Date: Sun, 19 Nov 2006 12:13:17
Message-Id: 59515.62.165.243.164.1163938281.squirrel@atoth.sote.hu
In Reply to: [gentoo-hardened] Problem with grsecurity by kakou
1 My tip:
2
3 Check your "role root".
4 Does it look something like this:
5 >>>
6 role root uG
7 role_transitions admin
8 <<<
9
10 If not, than please read the manual.
11
12 Also check your "role admin"
13 It should contain someting like this:
14 >>>
15 role admin sA
16 subject / rvka
17 <<<
18
19 Please study the avaiable options.
20
21 Regards,
22 Dw.
23
24 --
25 dr Tóth Attila, Radiológus Szakorvos jelölt, 06-20-825-8057, 06-30-5962-962
26 Attila Toth MD, Radiologist in Training, +36-20-825-8057, +36-30-5962-962
27
28 On Szo, November 18, 2006 14:44, kakou wrote:
29 > Hello,
30 > I have installed grsecurity and obtained a policy with grlearn.
31 > When I use gradm -a admin, I have this error in log :
32 >
33 > (root:U:/sbin/gradm) use of CAP_SYS_ADMIN denied
34 > for /sbin/gradm[gradm:4373] uid/euid:0/0 gid/egid:0/0,
35 > parent /bin/bash[bash:10954] uid/euid:0/0 gid/egid:0/0
36 >
37 > I have no subject for "/sbin/gradm" for the role root and if I try to
38 > add this subject, I have an error because this subject already exist
39 > (???).
40 > Moerover any subject is a simlinks to "/sbin/gradm".
41 >
42 > I have this error (but all is running fine :)) on two server.
43 > The first one with a tweaked policy and the second one with the default
44 > policy obtained with grlearn.
45 >
46 > Someone has an idea?
47 >
48 >
49 > Kakou
50 >
51
52
53 --
54 gentoo-hardened@g.o mailing list

Replies

Subject Author
Re: [gentoo-hardened] Problem with grsecurity kakou <kakou@×××××.org>