Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #248104
| Path | csiph.com!weretis.net!feeder8.news.weretis.net!news.mixmin.net!aioe.org!bofh.it!news.nic.it!robomod |
|---|---|
| From | <tomas@tuxteam.de> |
| Newsgroups | linux.debian.user |
| Subject | Re: Unlocking (remote/local), was Re: Help with suid (bash) |
| Date | Wed, 11 May 2022 20:30:01 +0200 |
| Message-ID | <ElZfX-eOoI-9@gated-at.bofh.it> (permalink) |
| References | <ElwGZ-exjv-3@gated-at.bofh.it> <Elz29-eyP5-1@gated-at.bofh.it> <ElAAV-ezOV-3@gated-at.bofh.it> <ElHj3-eDJa-1@gated-at.bofh.it> <ElKTE-eFZj-1@gated-at.bofh.it> <ElMLL-eH9t-35@gated-at.bofh.it> <ElX4t-eNbJ-5@gated-at.bofh.it> |
| X-Original-To | debian-user@lists.debian.org |
| X-Mailbox-Line | From debian-user-request@lists.debian.org Wed May 11 18:26:34 2022 |
| Old-Return-Path | <tomas@tuxteam.de> |
| X-Amavis-Spam-Status | No, score=-12.21 tagged_above=-10000 required=5.3 tests=[BAYES_00=-2, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, LDO_WHITELIST=-5, PGPSIGNATURE=-5, T_SCC_BODY_TEXT_LINE=-0.01] autolearn=ham autolearn_force=no |
| X-Policyd-Weight | using cached result; rate: -4.6 |
| MIME-Version | 1.0 |
| Content-Type | multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="UvX5Ell5A1WyAKjP" |
| Content-Disposition | inline |
| X-Mailing-List | <debian-user@lists.debian.org> archive/latest/789011 |
| List-ID | <debian-user.lists.debian.org> |
| List-URL | <https://lists.debian.org/debian-user/> |
| List-Archive | https://lists.debian.org/msgid-search/Ynv/zLJp6jlmNoZL@tuxteam.de |
| Approved | robomod@news.nic.it |
| Lines | 51 |
| Organization | linux.* mail to news gateway |
| Sender | robomod@news.nic.it |
| X-Original-Date | Wed, 11 May 2022 20:26:20 +0200 |
| X-Original-Message-ID | <Ynv/zLJp6jlmNoZL@tuxteam.de> |
| X-Original-References | <202205100750.18645.rhkramer@gmail.com> <20220510082100.1aebbee2@jhegaala.localdomain> <YnqN99ZJChEXctnt@axis.corp> <20220510171225.5d3dd5d6@ideapc> <YnsopAchZEjJ+9HD@axis.corp> <YntEK2cKyIvKR9V1@tuxteam.de> <YnvfLV95rehOxrYV@axis.corp> |
| Xref | csiph.com linux.debian.user:248104 |
Show key headers only | View raw
[Multipart message — attachments visible in raw view] - view raw
On Wed, May 11, 2022 at 11:07:09AM -0500, David Wright wrote: [...] > But after two posts about background information on setuid shell > scripts, you now write "the worst antipattern is to misuse tech > to force people to follow some nonsensical rituals". Strong words. Sorry if I was unclear. The point I was trying to make is that OpenSSH allows you to change the behaviour we are discussing if you wish so. So it /doesn't/ follow that antipattern. As to the other points? Well: 0. if you want to be able to login directly as root, /and/ with a password, change the server's /etc/sshd_config 1. if you can be bothered to set up a key for root, use that (generally preferrable to 0.) 1a. you can even limit what a private key owner is able to do: e.g. "only backup". So even if someone manages to steal your remote backup's private key, (s)he'll only able to trigger a backup 2. if you don't like 0..1a, there's still sudo. You can fine-tune what commands (and what parameters go with those) each (local or remote) user is allowed to invoke, and even whether they're supposed to issue a password for that or they get it "password-less". What's not to like? What's missing? Cheers -- t
Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Help with suid (bash) rhkramer@gmail.com - 2022-05-10 14:00 +0200
Re: Help with suid (bash) <tomas@tuxteam.de> - 2022-05-10 14:20 +0200
Re: Help with suid (bash) Charles Curley <charlescurley@charlescurley.com> - 2022-05-10 16:30 +0200
Unlocking (remote/local), was Re: Help with suid (bash) David Wright <deblis@lionunicorn.co.uk> - 2022-05-10 18:10 +0200
Re: Unlocking (remote/local), was Re: Help with suid (bash) Greg Wooledge <greg@wooledge.org> - 2022-05-10 21:10 +0200
Re: Unlocking (remote/local), was Re: Help with suid (bash) David Wright <deblis@lionunicorn.co.uk> - 2022-05-10 21:30 +0200
Re: Unlocking (remote/local), was Re: Help with suid (bash) Charles Curley <charlescurley@charlescurley.com> - 2022-05-11 01:20 +0200
Re: Unlocking (remote/local), was Re: Help with suid (bash) Greg Wooledge <greg@wooledge.org> - 2022-05-11 03:10 +0200
Re: Unlocking (remote/local), was Re: Help with suid (bash) David Wright <deblis@lionunicorn.co.uk> - 2022-05-11 05:10 +0200
Re: Unlocking (remote/local), was Re: Help with suid (bash) <tomas@tuxteam.de> - 2022-05-11 07:10 +0200
Re: Unlocking (remote/local), was Re: Help with suid (bash) David Wright <deblis@lionunicorn.co.uk> - 2022-05-11 18:10 +0200
Re: Unlocking (remote/local), was Re: Help with suid (bash) <tomas@tuxteam.de> - 2022-05-11 20:30 +0200
Re: Unlocking (remote/local), was Re: Help with suid (bash) David Wright <deblis@lionunicorn.co.uk> - 2022-05-12 01:00 +0200
Re: Unlocking (remote/local), was Re: Help with suid (bash) Dan Ritter <dsr@randomstring.org> - 2022-05-11 14:10 +0200
Re: Help with suid (bash) rhkramer@gmail.com - 2022-05-10 18:50 +0200
csiph-web