Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #248104

Re: Unlocking (remote/local), was Re: Help with suid (bash)

From <tomas@tuxteam.de>
Newsgroups linux.debian.user
Subject Re: Unlocking (remote/local), was Re: Help with suid (bash)
Date 2022-05-11 20:30 +0200
Message-ID <ElZfX-eOoI-9@gated-at.bofh.it> (permalink)
References (2 earlier) <ElAAV-ezOV-3@gated-at.bofh.it> <ElHj3-eDJa-1@gated-at.bofh.it> <ElKTE-eFZj-1@gated-at.bofh.it> <ElMLL-eH9t-35@gated-at.bofh.it> <ElX4t-eNbJ-5@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

On Wed, May 11, 2022 at 11:07:09AM -0500, David Wright wrote:

[...]

> But after two posts about background information on setuid shell
> scripts, you now write "the worst antipattern is to misuse tech
> to force people to follow some nonsensical rituals". Strong words.

Sorry if I was unclear. The point I was trying to make is that
OpenSSH allows you to change the behaviour we are discussing
if you wish so. So it /doesn't/ follow that antipattern.

As to the other points? Well:

 0. if you want to be able to login directly as root, /and/
   with a password, change the server's /etc/sshd_config
 1. if you can be bothered to set up a key for root, use
   that (generally preferrable to 0.)
 1a. you can even limit what a private key owner is able to
   do: e.g. "only backup". So even if someone manages to
   steal your remote backup's private key, (s)he'll only
   able to trigger a backup
 2. if you don't like 0..1a, there's still sudo. You can
   fine-tune what commands (and what parameters go with
   those) each (local or remote) user is allowed to invoke,
   and even whether they're supposed to issue a password
   for that or they get it "password-less".

What's not to like? What's missing?

Cheers
-- 
t

Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

Help with suid (bash) rhkramer@gmail.com - 2022-05-10 14:00 +0200
  Re: Help with suid (bash) <tomas@tuxteam.de> - 2022-05-10 14:20 +0200
  Re: Help with suid (bash) Charles Curley <charlescurley@charlescurley.com> - 2022-05-10 16:30 +0200
    Unlocking (remote/local), was Re: Help with suid (bash) David Wright <deblis@lionunicorn.co.uk> - 2022-05-10 18:10 +0200
      Re: Unlocking (remote/local), was Re: Help with suid (bash) Greg Wooledge <greg@wooledge.org> - 2022-05-10 21:10 +0200
        Re: Unlocking (remote/local), was Re: Help with suid (bash) David Wright <deblis@lionunicorn.co.uk> - 2022-05-10 21:30 +0200
      Re: Unlocking (remote/local), was Re: Help with suid (bash) Charles Curley <charlescurley@charlescurley.com> - 2022-05-11 01:20 +0200
        Re: Unlocking (remote/local), was Re: Help with suid (bash) Greg Wooledge <greg@wooledge.org> - 2022-05-11 03:10 +0200
        Re: Unlocking (remote/local), was Re: Help with suid (bash) David Wright <deblis@lionunicorn.co.uk> - 2022-05-11 05:10 +0200
          Re: Unlocking (remote/local), was Re: Help with suid (bash) <tomas@tuxteam.de> - 2022-05-11 07:10 +0200
            Re: Unlocking (remote/local), was Re: Help with suid (bash) David Wright <deblis@lionunicorn.co.uk> - 2022-05-11 18:10 +0200
              Re: Unlocking (remote/local), was Re: Help with suid (bash) <tomas@tuxteam.de> - 2022-05-11 20:30 +0200
                Re: Unlocking (remote/local), was Re: Help with suid (bash) David Wright <deblis@lionunicorn.co.uk> - 2022-05-12 01:00 +0200
        Re: Unlocking (remote/local), was Re: Help with suid (bash) Dan Ritter <dsr@randomstring.org> - 2022-05-11 14:10 +0200
    Re: Help with suid (bash) rhkramer@gmail.com - 2022-05-10 18:50 +0200

csiph-web