Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #248080

Re: Unlocking (remote/local), was Re: Help with suid (bash)

From David Wright <deblis@lionunicorn.co.uk>
Newsgroups linux.debian.user
Subject Re: Unlocking (remote/local), was Re: Help with suid (bash)
Date 2022-05-10 21:30 +0200
Message-ID <ElDIt-eBwD-17@gated-at.bofh.it> (permalink)
References <ElwGZ-exjv-3@gated-at.bofh.it> <Elz29-eyP5-1@gated-at.bofh.it> <ElAAV-ezOV-3@gated-at.bofh.it> <ElDp8-eBpZ-21@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On Tue 10 May 2022 at 13:02:41 (-0400), Greg Wooledge wrote:
> On Tue, May 10, 2022 at 11:08:23AM -0500, David Wright wrote:

[> > On Tue 10 May 2022 at 08:21:00 (-0600), Charles Curley wrote:]

> > > Why the aversion to doing things as root? Why not just run your scripts
> > > as root? This is exactly the sort of thing that is reserved to root for
> > > reasons of security.
> > 
> > That complicates unlocking partitions remotely because, even if you
> > can log in as root, you normally can't log in remotely as root.
> 
> But you *can* typically sudo on the remote system, which is what is
> actually being suggested here.  I think.

It's certainly what's being suggested by /me/, as can be seen in my:

  sudo udisksctl unlock --block-device "$j"

but that's not how rhkramer (judging by the 12:40:25 response¹) and
I would take Charles' post as meaning, but rather:

  $ su -
  # cryptsetup luksOpen /dev/sd<ann> <luks_device_name> && /bin/mount \
/dev/mapper/<luks_device_name> <mount_point>

presumably with the command wrapped, as now, in a script.

> (Also, you'd be surprised how many systems *do* allow remote root logins,
> either from a quasi-trusted set of source IPs, or using key auth only,
> or both.)

I do myself, using keys, but only local-root to remote-root. Having an
ordinary user use sudo means that one script suffices to unlock /home
both from a remote machine or at the console. Of course, it's a separate
ordinary user because of their non-/home home directory.

Simplification and generalisation are quite important to me, so as you
can see, the script will work unchanged on any of my hosts, and though
I mentioned unlock-acer, that function is one of several that are
created on the fly, in this case from:

  function unlock-AAAAAAAA { # unlock /home before logging in or transfers
      ping -c 1 -W 1 AAAAAAAA | grep 'bytes from' # wake it up first
      date && ssh -X AAAAAAAA -l unlock
  }

(The ping seems to help those powerline devices that some hosts use.)

¹ "a general aversion to being in root"

Cheers,
David.

Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

Help with suid (bash) rhkramer@gmail.com - 2022-05-10 14:00 +0200
  Re: Help with suid (bash) <tomas@tuxteam.de> - 2022-05-10 14:20 +0200
  Re: Help with suid (bash) Charles Curley <charlescurley@charlescurley.com> - 2022-05-10 16:30 +0200
    Unlocking (remote/local), was Re: Help with suid (bash) David Wright <deblis@lionunicorn.co.uk> - 2022-05-10 18:10 +0200
      Re: Unlocking (remote/local), was Re: Help with suid (bash) Greg Wooledge <greg@wooledge.org> - 2022-05-10 21:10 +0200
        Re: Unlocking (remote/local), was Re: Help with suid (bash) David Wright <deblis@lionunicorn.co.uk> - 2022-05-10 21:30 +0200
      Re: Unlocking (remote/local), was Re: Help with suid (bash) Charles Curley <charlescurley@charlescurley.com> - 2022-05-11 01:20 +0200
        Re: Unlocking (remote/local), was Re: Help with suid (bash) Greg Wooledge <greg@wooledge.org> - 2022-05-11 03:10 +0200
        Re: Unlocking (remote/local), was Re: Help with suid (bash) David Wright <deblis@lionunicorn.co.uk> - 2022-05-11 05:10 +0200
          Re: Unlocking (remote/local), was Re: Help with suid (bash) <tomas@tuxteam.de> - 2022-05-11 07:10 +0200
            Re: Unlocking (remote/local), was Re: Help with suid (bash) David Wright <deblis@lionunicorn.co.uk> - 2022-05-11 18:10 +0200
              Re: Unlocking (remote/local), was Re: Help with suid (bash) <tomas@tuxteam.de> - 2022-05-11 20:30 +0200
                Re: Unlocking (remote/local), was Re: Help with suid (bash) David Wright <deblis@lionunicorn.co.uk> - 2022-05-12 01:00 +0200
        Re: Unlocking (remote/local), was Re: Help with suid (bash) Dan Ritter <dsr@randomstring.org> - 2022-05-11 14:10 +0200
    Re: Help with suid (bash) rhkramer@gmail.com - 2022-05-10 18:50 +0200

csiph-web