Gentoo Archives: gentoo-user

From: Vladimir Rusinov <vladimir@×××××××××.info>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] rescrict command to certain dirs
Date: Sat, 04 Aug 2007 13:57:29
Message-Id: f6fdfb550708040651r40c66efcj59402c9bcebbde7c@mail.gmail.com
In Reply to: [gentoo-user] rescrict command to certain dirs by Martin Gysel
1 On 8/2/07, Martin Gysel <m.gysel@×××.ch> wrote:
2 >
3 > it should do something like jail the user to
4 > /var/www/vhosts/DOMAIN/httpdocs/DIRtoFILES and let him perform some
5 > commands (rm, less, nano, etc) there as user WEBSERVER.
6 >
7 > AFAIK this isn't possible with sudo because I think it's not possible to
8 > restrict it to certain files or dirs.
9
10
11 %% from /etc/sudoers
12
13 # Users in group www are allowed to edit httpd.conf using sudoedit, or
14 # sudo -e, without a password.
15 # %www ALL=(ALL) NOPASSWD: sudoedit /etc/httpd.conf
16
17 --
18 Vladimir Rusinov
19 GreenMice Solutions: IT-решения на базе Linux
20 http://greenmice.info/