Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
grsecurity + chroot
View unanswered posts
View posts from last 24 hours
View posts from last 7 days

 
Reply to topic    Gentoo Forums Forum Index Deutsches Forum (German)
View previous topic :: View next topic  
Author Message
LL0rd
l33t
l33t


Joined: 24 May 2004
Posts: 652
Location: Schlundcity

PostPosted: Thu Dec 30, 2004 9:32 pm    Post subject: grsecurity + chroot Reply with quote

Hallo,

irgendwie macht grsecurity mit gradm stress. Ich hab gradm installiert und ein Passowrt für den user admin gesetzt. Wenn ich dann gradm -E ausführe funktioniert es zwar, aber sshd verweigert irgendwie immer den SSH login.

Client:

Code:
14373: Read from socket failed: Connection reset by peer


Server:

Code:
Dec 30 23:30:58 dbserver sshd[32590]: fatal: chroot("/var/empty"): No such file or directory


/var/empty gibts aber. Kann mir jemand helfen?
Back to top
View user's profile Send private message
stkn
Retired Dev
Retired Dev


Joined: 09 Jun 2003
Posts: 65
Location: Germany, 6.8° 47' 60" E / 51° 0' N

PostPosted: Thu Dec 30, 2004 11:25 pm    Post subject: Reply with quote

scheinbar darf laut den grsec acls dein sshd /var/empty aber nicht benutzen /
sehen, deswegen die meldung

evlt. stehen noch ein paar details im output von dmesg
_________________
Welcome to reality
Back to top
View user's profile Send private message
LL0rd
l33t
l33t


Joined: 24 May 2004
Posts: 652
Location: Schlundcity

PostPosted: Thu Dec 30, 2004 11:33 pm    Post subject: Reply with quote

in dmesg steht noch folgendes:

Code:
grsec: From 80.134.132.50: (default:D:/usr/sbin/sshd) denied access to hidden file /var/empty by /usr/sbin/sshd[sshd:7137] uid/euid:0/0 gid/egid:0/0, parent /usr/sbin/sshd[sshd:23743] uid/euid:0/0 gid/egid:0/0


was muss ich den tun, damit der ssh login geht?
Back to top
View user's profile Send private message
Deever
Veteran
Veteran


Joined: 06 Jul 2002
Posts: 1354
Location: Zürich / Switzerland

PostPosted: Fri Dec 31, 2004 12:02 am    Post subject: Reply with quote

Die grsecurity-ACLs für den sshd anpassen.
Steht aber alles in der grsecurity-Doku!

Gruß,
/dev
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Deutsches Forum (German) All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum