Re: ACL learn, AUTH learn
Jens Kasten <[email protected]>
| Newsgroups | gmane.linux.rsbac |
|---|---|
| Message-ID | <1332884449.17588.0.camel@jaschtschik-pc> |
no this does not work. <6>0000000843|rsbac_adf_request(): request AUTHENTICATE, pid 17532, ppid 5166, prog_name gnome-screensav, prog_file /usr/libexec/gnome-screensaver-dialog, uid 1000, target_type USER, tid 1000, attr none, value none, result NOT_GRANTED by ACL ACL learn is enabled and no message about learning. Am Dienstag, den 27.03.2012, 16:26 +0200 schrieb Javier Juan Martínez Cabezón: > > Everything Learnt go into 0 transaction if I'm not wrong, try this: > rsbac_list_ta commit 0 > > > > > On 27/03/12 14:56, Jens Kasten wrote: > > Hi list, > > > > Info: > > > > rsbac_version > > Tools: 1.4.6, Kernel: 1.4.6, Tools-String: 1.4.6 > > > > uname -a > > Linux jaschtschik-pc 3.2.12-rsbac-soft-4+ #1 SMP Mon Mar 26 00:41:32 > > CEST 2012 x86_64 Intel(R) Core(TM)2 Quad CPU Q9550 @ 2.83GHz > > GenuineIntel GNU/Linux > > > > > > I have ACL learn and AUTH learn enabled in the rsbac kernel > > configuration. > > Also it is enabled while runtime. > > > > First I do "su - security" and get this: > > > > <6>0000000712|rsbac_adf_request(): request AUTHENTICATE, pid 2747, ppid > > 2209, prog_name su, prog_file /bin/su, uid 1000, target_type USER, tid > > 400, attr none, value none, result NOT_GRANTED by ACL > > > > When I do as security user: > > > > acl_grant USER 1000 AUTHENTICATE USER 400 > > > > and try again I can change to the user. > > The ACL learn should apply this I think. > > > > > > The second is the AUTH learn. > > I get this: > > > > <6>0000000724|rsbac_adf_request(): request CHANGE_GROUP, pid 2799, ppid > > 2798, prog_name cron, prog_file /usr/sbin/cron, uid 0, target_type > > PROCESS, tid 2799(cron,parent=2798(cron)), attr group, value 0, result > > NOT_GRANTED by AUTH > > > > AUTH learn had apply a lots to /usr/sbin/cron but not the uid 0. > > > > For testing: > > > > I set auth_learn: > > > > <6>0000000725|debug_proc_write(): setting rsbac_auth_learn to 1 > > > > and restart cron service > > > > <6>0000000726|rsbac_auth_p_capset_member(): adding AUTH group capability > > for gid 0 to process 3005 (cron) to transaction 0! > > <6>0000000727|rsbac_auth_p_capset_member(): adding AUTH group capability > > for gid 4294967293 to FILE Device 254:01 Inode 191265 > > Path /usr/sbin/cron to transaction 0! > > > > but uid 0 is not assigned to /usr/sbin/cron. > > > > > > Grüße > > Jens > > > > > > _______________________________________________ > > rsbac mailing list > > [email protected] > > http://www.rsbac.org/mailman/listinfo/rsbac > > _______________________________________________ > rsbac mailing list > [email protected] > http://www.rsbac.org/mailman/listinfo/rsbac _______________________________________________ rsbac mailing list [email protected] http://www.rsbac.org/mailman/listinfo/rsbac