Re: New rules for su root attempts
Steve Grubb <[email protected]>
| Newsgroups | gmane.comp.security.ids.prelude.devel |
|---|---|
| Message-ID | <[email protected]> |
On Wednesday 23 July 2008 10:46:10 Yoann Vandoorselaere wrote: > I agree through that the current classification is discussable, and > might not fit in specific PAM case. We ideally should open a wiki page > to create a set of generic classification.text that can be used by any > products (hint: contribution in this area are more than welcome): do you > have any idea that would better fit for this event? I would think change of uid (su/sudo), group (newgrp), or role (newrole, pam_selinux) are changes in credentials. Authentication may or may not be involved (rootok / wheel). -Steve _______________________________________________ Prelude-devel site list [email protected] http://lists.prelude-ids.org/mailman/listinfo/prelude-devel