• Open Menu Close Menu
  • Apple
  • Shopping Bag
  • Apple
  • Mac
  • iPad
  • iPhone
  • Watch
  • TV
  • Music
  • Support
  • Search apple.com
  • Shopping Bag

Lists

Open Menu Close Menu
  • Terms and Conditions
  • Lists hosted on this site
  • Email the Postmaster
  • Tips for posting to public mailing lists
Re: setuid for priv sockets?
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: setuid for priv sockets?


  • Subject: Re: setuid for priv sockets?
  • From: "Jordan K. Hubbard" <email@hidden>
  • Date: Mon, 27 Oct 2008 20:22:31 -0700


On Oct 27, 2008, at 2:49 PM, Stephen Hoffman wrote:

Not passing out root or sudo access is a common practice in various production and security-conscious environments. Within those environments (and I deal with folks that are severely allergic to passing out root access), setuid can be an invaluable palliative.

I'm quite willing to move to another approach or environment or tool or interface here. But suggesting that they pass out root access as a solution for starting up certain command-line tools is just going to get me a heaping raft of static with these good folks.

I think Damien might have been a little too sweeping in his generalizations; I don't think anyone is suggesting that the user should be, or needs to be, involved in all such privilege decisions, it's just one additional approach. For the cases you're talking about, having Launchd start the helper tool and confer privileges to it, rather than making that tool setuid, is the answer.


- Jordan
_______________________________________________
Do not post admin requests to the list. They will be ignored.
Darwin-dev mailing list      (email@hidden)
Help/Unsubscribe/Update your Subscription:
This email sent to email@hidden


References: 
 >Re: setuid for priv sockets? (From: Stephen Hoffman <email@hidden>)

  • Prev by Date: Re: setuid for priv sockets?
  • Next by Date: Re: setuid for priv sockets?
  • Previous by thread: Re: setuid for priv sockets?
  • Next by thread: Re: setuid for priv sockets?
  • Index(es):
    • Date
    • Thread