Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
Managing user accounts
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Other Things Gentoo
View previous topic :: View next topic  
Author Message
ggaaron
Apprentice
Apprentice


Joined: 10 May 2007
Posts: 217

PostPosted: Wed Sep 05, 2007 2:38 pm    Post subject: Managing user accounts Reply with quote

I'd like to limit user's access to system files - hide from them this what they don't need to see. I cannot deny them access to everything because they will not be able to run programs. I'm afraid of destroying my system, so I ask for help here, for which folders I can deny read from users, and how to do this, so system users like portage or distcc would work as they should?

Thanks in advance
Aaron
Back to top
View user's profile Send private message
likewhoa
l33t
l33t


Joined: 04 Oct 2006
Posts: 778
Location: Brooklyn, New York

PostPosted: Wed Sep 05, 2007 2:59 pm    Post subject: Reply with quote

consider a hardened kernel using any of the following pax,grp,selinux or more.
Back to top
View user's profile Send private message
ggaaron
Apprentice
Apprentice


Joined: 10 May 2007
Posts: 217

PostPosted: Wed Sep 05, 2007 3:50 pm    Post subject: Reply with quote

Actually I don't think I need hardened gentoo, the control system which is already there should be sufficient if I knew how to use it not destroying my system=)
Back to top
View user's profile Send private message
Rob1n
l33t
l33t


Joined: 29 Nov 2003
Posts: 714
Location: Cambridge, UK

PostPosted: Wed Sep 05, 2007 3:58 pm    Post subject: Reply with quote

What are you trying to hide from them? Things are usually set up by default to restrict access for regular users to directories/files they shouldn't see. Beyond that it gets tricky - you can't disable acces to most of the config files as applications often run under user accounts. You can probably change /etc/init.d, /etc/runlevels, /etc/conf.d to disable world read access (since these should only be accessed by root).
Back to top
View user's profile Send private message
ggaaron
Apprentice
Apprentice


Joined: 10 May 2007
Posts: 217

PostPosted: Wed Sep 05, 2007 4:06 pm    Post subject: Reply with quote

I know about config files=/
I'd like to be safe, and even when I make a mistake by a command like chmod 0755 file to make it executable, so users won't feast on such a mistake. I know that I shouldn't make such mistakes, but it happens. And after it is hard to find such file.

And that is why I posted it there, I don't know if it is even possible to make such a thing, and not make user's accounts useless.
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Other Things Gentoo All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum