[Security-Discuss] umask, Config Tools & User Private Groups

Joe Baker <[email protected]> Wed, 26 Apr 2006 11:54:47 -0500
Newsgroups gmane.linux.mandrake.security.general
Organization NEL Frequency Controls, Inc.
Message-ID <[email protected]>
I've seen the need to implement User Private Groups on our company's 
Mandriva system.  As such I've been trying to set the default umask to 
007 for both root and users.

I've noticed that this really messes with rpm installations of software 
and the menuing system.

I'd suggest that the drake configuration tools should store the initial 
umask, then set it to something sane, perform their task and restore the 
default umask.

I couldn't deploy updates to system menus.

My biggest concern is that Mandriva doesn't come with User Private 
groups by default.

We run a very diverse system here where shared folders may be accessed 
via NFS, Samba or via multiple users running remote XDMCP sessions via 
VNCServer or LTSP.  Hence the need to have a umask which allows group 
writable permissions and the need to set the group suid bit in the 
shared folders.

I apologize that this isn't the best place for this message. 
Suggestions where to take these concerns would be appreciated.

-Joe Baker
____________________________________________________
Want to buy your Pack or Services from Mandriva? 
Go to http://store.mandriva.com
Join the Club : http://www.mandrivaclub.com
____________________________________________________