login
Header Space

 
 

Re: Debian libssl security (OpenSSH safe?)

Score:
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: <misc@...>
Date: Thursday, May 15, 2008 - 9:52 am

On Thu, May 15, 2008 at 12:53:06AM +0000, Jussi Peltola wrote:
 

Remember that in linux/debian, files don't inheret the ownership of the
directory into which they are placed.  Therefore, e.g for copying backup
files from one box to another with rsync, if a normal user does it
(assuming that user has write permission to, e.g. on debian
/var/local/backup, then the files end up owned by that user.  The user
can't change the ownership to root.  This may not seem like a huge
problem for e.g. tarballs that protect the ownership and permissions of
files but for regular files, eg copies from /etc, then its an issue.
Also, during restore, if that uid is either not the same user or no user
at all, things can get interesting.

Better to have root have ssh access to the backup repository box for
rsyncing the backups.

Root has to do the backups since debian packages don't come set up for
"operator" to be able to read otherwise unreadable files.

Doug.
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Debian libssl security (OpenSSH safe?), Juan Miscaro, (Tue May 13, 11:37 am)
Re: Debian libssl security (OpenSSH safe?), Sean Malloy, (Tue May 13, 12:14 pm)
Re: Debian libssl security (OpenSSH safe?), Gabriel Linder, (Wed May 14, 3:41 am)
Re: Debian libssl security (OpenSSH safe?), Otto Moerbeek, (Wed May 14, 7:22 am)
Re: Debian libssl security (OpenSSH safe?), Ted Unangst, (Wed May 14, 7:24 am)
Re: Debian libssl security (OpenSSH safe?), raven, (Wed May 14, 7:45 pm)
Re: Debian libssl security (OpenSSH safe?), Darrin Chandler, (Wed May 14, 8:22 pm)
Re: Debian libssl security (OpenSSH safe?), Ben Calvert, (Wed May 14, 8:30 pm)
Re: Debian libssl security (OpenSSH safe?), Ted Unangst, (Wed May 14, 10:22 pm)
Re: Debian libssl security (OpenSSH safe?), Darrin Chandler, (Wed May 14, 10:43 pm)
Re: Debian libssl security (OpenSSH safe?), Otto Moerbeek, (Thu May 15, 1:11 am)
Re: Debian libssl security (OpenSSH safe?), Dave Ewart, (Thu May 15, 5:02 am)
Re: Debian libssl security (OpenSSH safe?), Tim Post, (Thu May 15, 5:44 am)
Re: Debian libssl security (OpenSSH safe?), Darrin Chandler, (Thu May 15, 9:31 am)
Re: Debian libssl security (OpenSSH safe?), Tim Post, (Fri May 16, 2:51 am)
Re: Debian libssl security (OpenSSH safe?), Ted Unangst, (Wed May 14, 11:10 pm)
Re: Debian libssl security (OpenSSH safe?), Jussi Peltola, (Wed May 14, 8:53 pm)
Re: Debian libssl security (OpenSSH safe?), Douglas A. Tutty, (Thu May 15, 9:52 am)
Re: Debian libssl security (OpenSSH safe?), Marc Espie, (Tue May 13, 1:00 pm)
speck-geostationary