Darren has got a job working on Trusted Solaris: he sometimes has time to
contribute comment to the list now...
> I ask because I have the number of suid binaries on my system down to a
> very low number, and the following remaining are just begging for a subset
> of root privs:
>
> ping, traceroute: priv = open raw socket
> ssh,rlogin,rcp,r<etc> priv = open socket num < 1024
>
> Other useful privilege subsets would of course be read any file, tty
> chowning/chmoding, etc.
In the latest draft, privileges got renamed "capabilities" and happily they
are 99% implemented now. (Zefram and I finished up what Darren had
started a month or so ago.)
Work is still progressing. It is hampered by the fact that few have a copy
of the draft standard. If you want to get on the list, subscribe to
linux-privs-request@mit.edu
(which is manually maintained by Ted Ts'o).
For patches against 2.0.30
http://parc.power.net/morgan/Orange-Linux/linux-privs/index.html
I am currently working on the auditing component. Remy Card is reportadly
working on the ACL stuff although this has been somewhat delayed because of
a Linux book he has been writing.
Best wishes
Andrew
-- Linux-PAM, libpwdb, Orange-Linux and Linux-GSS http://parc.power.net/morgan/index.html