Re: ACL learn, AUTH learn
Javier Juan Martínez Cabezón <[email protected]>
| Newsgroups | gmane.linux.rsbac |
|---|---|
| Message-ID | <[email protected]> |
Everything Learnt go into 0 transaction if I'm not wrong, try this: rsbac_list_ta commit 0 On 27/03/12 14:56, Jens Kasten wrote: > Hi list, > > Info: > > rsbac_version > Tools: 1.4.6, Kernel: 1.4.6, Tools-String: 1.4.6 > > uname -a > Linux jaschtschik-pc 3.2.12-rsbac-soft-4+ #1 SMP Mon Mar 26 00:41:32 > CEST 2012 x86_64 Intel(R) Core(TM)2 Quad CPU Q9550 @ 2.83GHz > GenuineIntel GNU/Linux > > > I have ACL learn and AUTH learn enabled in the rsbac kernel > configuration. > Also it is enabled while runtime. > > First I do "su - security" and get this: > > <6>0000000712|rsbac_adf_request(): request AUTHENTICATE, pid 2747, ppid > 2209, prog_name su, prog_file /bin/su, uid 1000, target_type USER, tid > 400, attr none, value none, result NOT_GRANTED by ACL > > When I do as security user: > > acl_grant USER 1000 AUTHENTICATE USER 400 > > and try again I can change to the user. > The ACL learn should apply this I think. > > > The second is the AUTH learn. > I get this: > > <6>0000000724|rsbac_adf_request(): request CHANGE_GROUP, pid 2799, ppid > 2798, prog_name cron, prog_file /usr/sbin/cron, uid 0, target_type > PROCESS, tid 2799(cron,parent=2798(cron)), attr group, value 0, result > NOT_GRANTED by AUTH > > AUTH learn had apply a lots to /usr/sbin/cron but not the uid 0. > > For testing: > > I set auth_learn: > > <6>0000000725|debug_proc_write(): setting rsbac_auth_learn to 1 > > and restart cron service > > <6>0000000726|rsbac_auth_p_capset_member(): adding AUTH group capability > for gid 0 to process 3005 (cron) to transaction 0! > <6>0000000727|rsbac_auth_p_capset_member(): adding AUTH group capability > for gid 4294967293 to FILE Device 254:01 Inode 191265 > Path /usr/sbin/cron to transaction 0! > > but uid 0 is not assigned to /usr/sbin/cron. > > > Grüße > Jens > > > _______________________________________________ > rsbac mailing list > [email protected] > http://www.rsbac.org/mailman/listinfo/rsbac _______________________________________________ rsbac mailing list [email protected] http://www.rsbac.org/mailman/listinfo/rsbac