Gentoo Archives: gentoo-user

From: Peter Humphrey <peter@××××××××××××.uk>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] BOINC on a hardened system?
Date: Fri, 28 Jul 2017 08:39:06
Message-Id: 1546352.onZEvfgyeo@peak
In Reply to: Re: [gentoo-user] BOINC on a hardened system? by Gregory Woodbury
1 On Thursday 27 Jul 2017 11:02:45 Gregory Woodbury wrote:
2 > Depending on which BOINC projects you choose to run, BOINC may or may
3 > not need continual access to the Internet.
4 > Most of the projects I run only need intermittent access to upload and
5 > receive new workunits, but CERN projects need
6 > continuous access while running.
7
8 It's only the incoming access from the Big Bad World that would be shut most
9 of the time, only opened for particular purposes.
10
11 > Also, BOINC will run if the certificates are not owned by BOINC, but
12 > will complain in the logs when they are updated, and then
13 > you could update them by hand.
14
15 I haven't experienced that so far.
16
17 But I get lots of "gr-sec: denied following symlink /home/prh/boinc/ca-
18 bundle.crt since owner 1000 does not match target owner 0" errors. Also,
19 today I see "denied untrusted exec (due to being in untrusted group and file
20 in non-root-owned directory)" errors as well. (I hope I've transcribed those
21 right.)
22
23 It looks as though it has to run as root, which doesn't bode well. I'll
24 experiment with running BOINC with the default ownerships, though.
25
26 > So far as I know, there have not been any vectors propagated via BOINC.
27
28 That's good - thanks.
29
30 --
31 Regards
32 Peter

Replies

Subject Author
Re: [gentoo-user] BOINC on a hardened system? Gregory Woodbury <redwolfe@×××××.com>
Re: [gentoo-user] BOINC on a hardened system? Peter Humphrey <peter@××××××××××××.uk>