[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: New user for logcheck



On Wed, Nov 24, 1999 at 01:09:39PM +1100, Brian May wrote:
> Anyway, I believe my post was justified, because the original poster
> stated that he intended to run the daemon from cron.
> 
> As this involves running a separate process, then using a shared user
> id would open up security holes (eg with signals).

Could you be more specific about the security hole possibilities of
signalling? I'm not seeing anything critical in that. I maintain that
it's well worth examining any new userids very carefully, since we don't
currently have a decent method for managing them. If that changes there
won't be any problem with handing them out loosely, but until then
they're a headache.

-- 
Mike Stone

Attachment: pgpCg3llZAx69.pgp
Description: PGP signature


Reply to: