Re: Capabilities


From: Stanislav Ievlev <inger@altlinux.ru>
Subject: Re: Capabilities
Date: Wed, 18 Jul 2001 11:09:46 +0400

Next Article (by Date): RE: Planning v1.2.0 - update "Kaladis"
Previous Article (by Date): Re: rsbac-v1.1.2-pre8 uploaded Stanislav Ievlev
Top of Thread: Capabilities "Kaladis"
Articles sorted by: [Date] [Author] [Subject]


Kaladis wrote:

>Hey guys, just a quick one.
>
>Is it possible to delegate certain capabilities to individual users so that
>for example user "inetd" can get the capability CAP_NET_BIND (open ports <
>1024)?
>
>This is because I want to chroot xinetd and run it with changed UID/GID
>
>Thanks
>
>Jörg Lübbert (aka Kaladis)
>- Core Developer of Kaladix Hyper-Secure Linux Distribution
>(www.maganation.com/~kaladix)
>
>-
>To unsubscribe from the rsbac list, send a mail to
>majordomo@rsbac.org with
>unsubscribe rsbac
>as single line in the body.
>
>.
>
You will have to use LIDS for it. RSBAC doesn't support it, as I know.

If you use RSBAC you can use an RC instead capabilities.
------------------------
Stanislav Ievlev


-
To unsubscribe from the rsbac list, send a mail to
majordomo@rsbac.org with
unsubscribe rsbac
as single line in the body.

Next Article (by Date): RE: Planning v1.2.0 - update "Kaladis"
Previous Article (by Date): Re: rsbac-v1.1.2-pre8 uploaded Stanislav Ievlev
Top of Thread: Capabilities "Kaladis"
Articles sorted by: [Date] [Author] [Subject]


Go to Compuniverse LWGate Home Page.