linux-kernel.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* RE: Re: Re: [PATCH]: non-readable binaries - binfmt_misc 2.6.0-test4
@ 2003-09-04  6:53 Zach, Yoav
  2003-09-04 21:28 ` insecure
  0 siblings, 1 reply; 2+ messages in thread
From: Zach, Yoav @ 2003-09-04  6:53 UTC (permalink / raw)
  To: insecure; +Cc: akpm, torvalds, linux-kernel

> --- insecure <insecure@mail.od.ua> wrote:
>
> > If the binary resides on a NFS drive ( which 
> > is a very common practice )
> > then the suid-wrapper solution will not work 
> > because root permissions
> > are squashed on the remote drive.
> 
> 
> This is a NFS promlem. Do not work around it by
> adding crap elsewhere.
> NFS has to get a decent user auth/crypto features.
> I did not try it yet, but NFSv4 will address that.
> --

This is not a workaround - it's a solution for systems
that use the unix user identification mechanism.
Considering the conservative nature of system-administrators,
this mechanism will still be in use for quite a while.

Thanks,
Yoav.

^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: Re: Re: [PATCH]: non-readable binaries - binfmt_misc 2.6.0-test4
  2003-09-04  6:53 Re: Re: [PATCH]: non-readable binaries - binfmt_misc 2.6.0-test4 Zach, Yoav
@ 2003-09-04 21:28 ` insecure
  0 siblings, 0 replies; 2+ messages in thread
From: insecure @ 2003-09-04 21:28 UTC (permalink / raw)
  To: Zach, Yoav; +Cc: akpm, torvalds, linux-kernel

On Thursday 04 September 2003 09:53, Zach, Yoav wrote:
> > --- insecure <insecure@mail.od.ua> wrote:
> > > If the binary resides on a NFS drive ( which
> > > is a very common practice )
> > > then the suid-wrapper solution will not work
> > > because root permissions
> > > are squashed on the remote drive.
> >
> > This is a NFS promlem. Do not work around it by
> > adding crap elsewhere.
> > NFS has to get a decent user auth/crypto features.
> > I did not try it yet, but NFSv4 will address that.
>
> This is not a workaround - it's a solution for systems
> that use the unix user identification mechanism.

In NFSv3 there is _no_ user identification mechanism.
ipaddr based /etc/exports does not count.
-- 
vda

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2003-09-04 21:29 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2003-09-04  6:53 Re: Re: [PATCH]: non-readable binaries - binfmt_misc 2.6.0-test4 Zach, Yoav
2003-09-04 21:28 ` insecure

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).