[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: pon permissions



Quoting Thomas H. George (tomgeorge@spininternet.com):
> On a stand-alone system four users need access to the internet.  At
> present only root can run pon.  I have changed file permissions,
> commented auth in /etc/ppp/options, and executed adduser <userid> dip.
> Now, when a user tries to start pon, the user gets the message:
> 
>     must be root to run /usr/sbin/pppd, since it is not setuid-root
> 
> I have read the manpages for setuid and seteuid but it is not clear to
> me what I should change and the consequences of a file being setuid-root
> seem undesirable.  Can anyone help resolve this problem?

Having added the users concerned to group dip, I would reinstall
the ppp package to correct all the file permissions which are
probably now all screwed up. (If that doesn't do it, install it,
purge it and reinstall it.)

As pppd *is* setuid, you should get the permissions right.
Not to do so may leave security holes open, and may even cause
pppd to refuse to run (it checks permissions on some files).

Cheers,

-- 
Email:  d.wright@open.ac.uk   Tel: +44 1908 653 739  Fax: +44 1908 655 151
Snail:  David Wright, Earth Science Dept., Milton Keynes, England, MK7 6AA
Disclaimer:   These addresses are only for reaching me, and do not signify
official stationery. Views expressed here are either my own or plagiarised.



Reply to: