Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Focus on Sun
(mis)using RBAC... Apr 12 2005 07:19PM
Jonathan Katz (jonathan katz gmail com) (3 replies)
Re: (mis)using RBAC... Apr 15 2005 03:43PM
Glenn M. Brunette, Jr. (Glenn Brunette Sun COM)
Re: (mis)using RBAC... Apr 14 2005 09:12PM
Darren J Moffat (Darren Moffat Sun COM)
Re: (mis)using RBAC... Apr 14 2005 05:26PM
benjamin brumaire (benjamin brumaire biz) (1 replies)
Jonathan Katz schrieb:

>All,
>
>I was recently charged with setting up RBAC so that the group I work
>
...

> I then added the role to my account on the server in /etc/user_attr:
>jkatz::::type=normal;profiles=Web Administration,Basic Solaris User
>
>
>
you added a right profile. I missed the right profile "All" in this entry.

>4) Finally, I changed my shell to /bin/pfcsh. Now, with my regular
>user account I can start and restart our webservers.
>
>My questions are, is this a normal practice (are there other people
>doing it) and is it supported? What unintended consequences am I
>missing? I understand that if a user's account is compromised, the
>webserver services can be stopped and started at-will. I also
>understand that our sysadmin group will be restricted to using
>pfcsh/pfksh/pfsh and cannot use bash or tcsh (although we can still
>leave those set, type 'exec pfsh' and then do what we need to do as
>the Profile.)
>
>
>
It looks valid to me . To avoid error you should use usermod,
smprofile, etc ... to modify the RBAC databases.
Another way, less invasive perhaps, is to use pfsh as interpreter in
the start/stop script or use a "pf" wrapper to call them.

On Solaris10 you should try to give the http daemon the privilege to
open privileged port "PRIV_NET_PRIVADDR" so it doens't need to be start
as root :)

regards
benjamin

[ reply ]
Re: (mis)using RBAC... Apr 15 2005 03:51PM
Glenn M. Brunette, Jr. (Glenn Brunette Sun COM)







 

Privacy Statement
Copyright 2009, SecurityFocus