[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: limiting user access



(Back to just debian-user; no discussions of policy in my message.)

Anthony Towns <aj@azure.humbug.org.au> writes:

> But what about /var? /var/tmp should be world writable (albeit sticky)
> according to the FSSTND, but at least a couple of packages use /var
> for executable files, notably dpkg (/var/lib/dpkg/info/*), and the
> distributed-net client (/var/lib/distributed-net/distributed-net).

Put /var/tmp on a different partition than /var (and /tmp on a
different partition than /).  This also stops them from keeping huge
files in /var/tmp where the news spool, mail spool and logs are.  You
probably want to run something like tmpreaper to keep it clean too.
Look out for anyone usinh email to keep big files.

-- 
	 Carey Evans  http://home.clear.net.nz/pages/c.evans/

	  GNU GPL: "The Source will be with you... always."


--
TO UNSUBSCRIBE FROM THIS MAILING LIST: e-mail the word "unsubscribe" to
debian-user-request@lists.debian.org . 
Trouble?  e-mail to templin@bucknell.edu .


Reply to: