Re: Proposal "LUID"

From: Jamie Lokier (lk@tantalophile.demon.co.uk)
Date: Sat Apr 15 2000 - 12:30:09 EST


Linda Walsh wrote:
> I'm not talking about limits. I'm talking about an
> auditting ID that needs to be based on a when a user logs in
> and stays with them over any SUID or 'su' commands.

"telnet localhost" subverts this if you allow it (but you probably wouldn't).

This shows that you have to audit and possibly restrict all daemons that
permit uid changes anyway.

So why not just use the time-honoured "real user id"?

- Jamie

-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.rutgers.edu
Please read the FAQ at http://www.tux.org/lkml/



This archive was generated by hypermail 2b29 : Sat Apr 15 2000 - 21:00:26 EST