Re: Are there good reasons for running radiusd as user 'root'?

Maurice Makaay <[email protected]> Sat, 15 Nov 2003 18:17:03 +0100
Newsgroups gmane.comp.gnu.radius.bugs
Organization InterNLnet BV
Message-ID <[email protected]>
Hi Sergey,

> > I created a patch which adds a new keyword "exec-user" to the configuration
> > file's vocabulary.
> 
> Thanks Maurice! I'll get back to this a bit later this week.

I just found a little problem with my patch. I can make the logs 
directory of the user I set as the run-user, but radiusd starts logging
before drop_privileges() is called. Resulting, affected logfiles 
(e.g. radius.debug) will be owned by "root" and after dropping privileges
radiusd can't add any more loglines to them. 

I haven't got a fix for this at this time. I'm too busy converting some
of our radiusservers to gnu-radius. I'll look into it a.s.a.p.

Regards,

-- Maurice Makaay