Re: ACL learn, AUTH learn

Javier Juan Martínez Cabezón <[email protected]>
Newsgroups gmane.linux.rsbac
Message-ID <[email protected]>

Everything Learnt go into 0 transaction if I'm not wrong, try this:
rsbac_list_ta commit 0




On 27/03/12 14:56, Jens Kasten wrote:
> Hi list,
> 
> Info:
> 
> rsbac_version 
> Tools: 1.4.6, Kernel: 1.4.6, Tools-String: 1.4.6
> 
> uname -a
> Linux jaschtschik-pc 3.2.12-rsbac-soft-4+ #1 SMP Mon Mar 26 00:41:32
> CEST 2012 x86_64 Intel(R) Core(TM)2 Quad CPU Q9550 @ 2.83GHz
> GenuineIntel GNU/Linux
> 
>  
> I have ACL learn and AUTH learn enabled in the rsbac kernel
> configuration.
> Also it is enabled while runtime.
> 
> First I do "su - security" and get this:
> 
> <6>0000000712|rsbac_adf_request(): request AUTHENTICATE, pid 2747, ppid
> 2209, prog_name su, prog_file /bin/su, uid 1000, target_type USER, tid
> 400, attr none, value none, result NOT_GRANTED by ACL
> 
> When I do as security user:
> 
> 	acl_grant USER 1000 AUTHENTICATE USER 400
> 
> and try again I can change to the user.
> The ACL learn should apply this I think.
> 
> 
> The second is the AUTH learn.
> I get this:
> 
> <6>0000000724|rsbac_adf_request(): request CHANGE_GROUP, pid 2799, ppid
> 2798, prog_name cron, prog_file /usr/sbin/cron, uid 0, target_type
> PROCESS, tid 2799(cron,parent=2798(cron)), attr group, value 0, result
> NOT_GRANTED by AUTH
> 
> AUTH learn had apply a lots to /usr/sbin/cron but not the uid 0.
> 
> For testing:
> 
> I set auth_learn:
> 
> <6>0000000725|debug_proc_write(): setting rsbac_auth_learn to 1
> 
> and restart cron service
> 
> <6>0000000726|rsbac_auth_p_capset_member(): adding AUTH group capability
> for gid 0 to process 3005 (cron) to transaction 0!
> <6>0000000727|rsbac_auth_p_capset_member(): adding AUTH group capability
> for gid 4294967293 to FILE Device 254:01 Inode 191265
> Path /usr/sbin/cron to transaction 0!
> 
> but uid 0 is not assigned to /usr/sbin/cron.
> 
> 
> Grüße
> Jens
> 
> 
> _______________________________________________
> rsbac mailing list
> [email protected]
> http://www.rsbac.org/mailman/listinfo/rsbac

_______________________________________________
rsbac mailing list
[email protected]
http://www.rsbac.org/mailman/listinfo/rsbac
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.