Re: IMPORTANT CORRECTION!!! IFS effective user
Patrick Botz <botz-r/[email protected]>
| Newsgroups | gmane.comp.systems.as400.security |
|---|---|
| Message-ID | <OFFD939404.97FF172A-ON86256FC1.006B4527-86256FC2.0007F7E9@us.ibm.com> |
> These should not remain in effect after the program that adds them > completes (i.e. removed from the stack). If you are convinced that they > really do, you should probably report it as a bug.... I was flat-out wrong about this. Thanks to Ed Fishel for reminding me how this stuff works...(in a shameless attempt to provide a lousy reason for being wrong, we designed and implemented If the program does not reset the original contents, these changes DO remain in affect!!!!! Adopted authority is done by adding information to each stack-frame in a process. Therefore, when the stack-frame is removed, the adopted authority goes away. A swap (and setuid) changes the users and groups for a job. Like a swap, the setuid stuff is NOT removed when the program in a stack-frame that caused the change is removed. I apologize for providing incorrect information!!!! Patrick Botz Senior Technical Staff Member eServer Security Architect (507) 253-0917, T/L 553-0917 email: botz-r/[email protected] _______________________________________________ This is the Security Administration on the AS400 / iSeries (Security400) mailing list To post a message email: Security400-Zwy7GipZuJhWk0Htik3J/[email protected] To subscribe, unsubscribe, or change list options, visit: http://lists.midrange.com/mailman/listinfo/security400 or email: Security400-request-Zwy7GipZuJhWk0Htik3J/[email protected] Before posting, please take a moment to review the archives at http://archive.midrange.com/security400.