Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #248104

Re: Unlocking (remote/local), was Re: Help with suid (bash)

Path csiph.com!weretis.net!feeder8.news.weretis.net!news.mixmin.net!aioe.org!bofh.it!news.nic.it!robomod
From <tomas@tuxteam.de>
Newsgroups linux.debian.user
Subject Re: Unlocking (remote/local), was Re: Help with suid (bash)
Date Wed, 11 May 2022 20:30:01 +0200
Message-ID <ElZfX-eOoI-9@gated-at.bofh.it> (permalink)
References <ElwGZ-exjv-3@gated-at.bofh.it> <Elz29-eyP5-1@gated-at.bofh.it> <ElAAV-ezOV-3@gated-at.bofh.it> <ElHj3-eDJa-1@gated-at.bofh.it> <ElKTE-eFZj-1@gated-at.bofh.it> <ElMLL-eH9t-35@gated-at.bofh.it> <ElX4t-eNbJ-5@gated-at.bofh.it>
X-Original-To debian-user@lists.debian.org
X-Mailbox-Line From debian-user-request@lists.debian.org Wed May 11 18:26:34 2022
Old-Return-Path <tomas@tuxteam.de>
X-Amavis-Spam-Status No, score=-12.21 tagged_above=-10000 required=5.3 tests=[BAYES_00=-2, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, LDO_WHITELIST=-5, PGPSIGNATURE=-5, T_SCC_BODY_TEXT_LINE=-0.01] autolearn=ham autolearn_force=no
X-Policyd-Weight using cached result; rate: -4.6
MIME-Version 1.0
Content-Type multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="UvX5Ell5A1WyAKjP"
Content-Disposition inline
X-Mailing-List <debian-user@lists.debian.org> archive/latest/789011
List-ID <debian-user.lists.debian.org>
List-URL <https://lists.debian.org/debian-user/>
List-Archive https://lists.debian.org/msgid-search/Ynv/zLJp6jlmNoZL@tuxteam.de
Approved robomod@news.nic.it
Lines 51
Organization linux.* mail to news gateway
Sender robomod@news.nic.it
X-Original-Date Wed, 11 May 2022 20:26:20 +0200
X-Original-Message-ID <Ynv/zLJp6jlmNoZL@tuxteam.de>
X-Original-References <202205100750.18645.rhkramer@gmail.com> <20220510082100.1aebbee2@jhegaala.localdomain> <YnqN99ZJChEXctnt@axis.corp> <20220510171225.5d3dd5d6@ideapc> <YnsopAchZEjJ+9HD@axis.corp> <YntEK2cKyIvKR9V1@tuxteam.de> <YnvfLV95rehOxrYV@axis.corp>
Xref csiph.com linux.debian.user:248104

Show key headers only | View raw


[Multipart message — attachments visible in raw view] - view raw

On Wed, May 11, 2022 at 11:07:09AM -0500, David Wright wrote:

[...]

> But after two posts about background information on setuid shell
> scripts, you now write "the worst antipattern is to misuse tech
> to force people to follow some nonsensical rituals". Strong words.

Sorry if I was unclear. The point I was trying to make is that
OpenSSH allows you to change the behaviour we are discussing
if you wish so. So it /doesn't/ follow that antipattern.

As to the other points? Well:

 0. if you want to be able to login directly as root, /and/
   with a password, change the server's /etc/sshd_config
 1. if you can be bothered to set up a key for root, use
   that (generally preferrable to 0.)
 1a. you can even limit what a private key owner is able to
   do: e.g. "only backup". So even if someone manages to
   steal your remote backup's private key, (s)he'll only
   able to trigger a backup
 2. if you don't like 0..1a, there's still sudo. You can
   fine-tune what commands (and what parameters go with
   those) each (local or remote) user is allowed to invoke,
   and even whether they're supposed to issue a password
   for that or they get it "password-less".

What's not to like? What's missing?

Cheers
-- 
t

Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

Help with suid (bash) rhkramer@gmail.com - 2022-05-10 14:00 +0200
  Re: Help with suid (bash) <tomas@tuxteam.de> - 2022-05-10 14:20 +0200
  Re: Help with suid (bash) Charles Curley <charlescurley@charlescurley.com> - 2022-05-10 16:30 +0200
    Unlocking (remote/local), was Re: Help with suid (bash) David Wright <deblis@lionunicorn.co.uk> - 2022-05-10 18:10 +0200
      Re: Unlocking (remote/local), was Re: Help with suid (bash) Greg Wooledge <greg@wooledge.org> - 2022-05-10 21:10 +0200
        Re: Unlocking (remote/local), was Re: Help with suid (bash) David Wright <deblis@lionunicorn.co.uk> - 2022-05-10 21:30 +0200
      Re: Unlocking (remote/local), was Re: Help with suid (bash) Charles Curley <charlescurley@charlescurley.com> - 2022-05-11 01:20 +0200
        Re: Unlocking (remote/local), was Re: Help with suid (bash) Greg Wooledge <greg@wooledge.org> - 2022-05-11 03:10 +0200
        Re: Unlocking (remote/local), was Re: Help with suid (bash) David Wright <deblis@lionunicorn.co.uk> - 2022-05-11 05:10 +0200
          Re: Unlocking (remote/local), was Re: Help with suid (bash) <tomas@tuxteam.de> - 2022-05-11 07:10 +0200
            Re: Unlocking (remote/local), was Re: Help with suid (bash) David Wright <deblis@lionunicorn.co.uk> - 2022-05-11 18:10 +0200
              Re: Unlocking (remote/local), was Re: Help with suid (bash) <tomas@tuxteam.de> - 2022-05-11 20:30 +0200
                Re: Unlocking (remote/local), was Re: Help with suid (bash) David Wright <deblis@lionunicorn.co.uk> - 2022-05-12 01:00 +0200
        Re: Unlocking (remote/local), was Re: Help with suid (bash) Dan Ritter <dsr@randomstring.org> - 2022-05-11 14:10 +0200
    Re: Help with suid (bash) rhkramer@gmail.com - 2022-05-10 18:50 +0200

csiph-web