Re: ACL read attribute

Amon Ott <[email protected]> Mon, 30 Jul 2012 12:46:08 +0200
Newsgroups gmane.linux.rsbac
Message-ID <[email protected]>
On Saturday 14 July 2012 wrote Jens Kasten:
> I like to use an special user for update packages but how can I solve
> this?
>
> updater@jaschtschik-pc ~ $ attr_back_fd  -M AUTH /bin/su
>
> Sat Jul 14 12:16:51 2012 :<6>0000001897|rsbac_adf_request(): request
> READ_ATTRIBUTE, pid 16531, ppid 24076, prog_name attr_back_fd,
> prog_file /usr/bin/attr_back_fd, uid 410, audit uid 1000, target_type
> FILE,
>                       tid Device 254:01 Inode 307132 Path /bin/su, attr
> auth_learn, value 4294967295, result NOT_GRANTED by ACL

Either grant READ_ATTRIBUTE to that user or use an RC role and grant the right 
to that role.

Amon.
-- 
http://www.rsbac.org - GnuPG: 2048g/5DEAAA30 2002-10-22