Re: Yet Another New systemd Feature

Liste des GroupesRevenir à ol misc 
Sujet : Re: Yet Another New systemd Feature
De : gtaylor (at) *nospam* tnetconsulting.net (Grant Taylor)
Groupes : comp.os.linux.misc
Date : 07. May 2024, 21:19:38
Autres entêtes
Organisation : TNet Consulting
Message-ID : <v1dusa$q8t$2@tncsrv09.home.tnetconsulting.net>
References : 1 2 3 4 5 6 7
User-Agent : Mozilla Thunderbird
On 5/7/24 10:29, Richard Kettlewell wrote:
I think this is optimistic at best.
I've used it that way for years.
The big outsourced IT company that I worked for converted hundreds of clients (each with hundreds of servers using sudo) to this model.
It was a PITA to do the conversion.  But once it was done, things worked better, there was more tracking, and everybody involved had a much better idea of what was going on.

One reason is the difficulty of writing correct setuid programs. sudo’s CVE record shows how hard this is (as if there were any doubt by now). Some of the historical CVEs stem from it being written in C but for others the implementation language doesn’t seem to be very relevant.
I didn't mean to imply that sudo was perfect.  If anything, it's imperfect.  But nothing is perfect.  It's also got decades of people poking at it with sticks of varying sharpness.

The other is that impracticality of ensuring the the commands you want to run don’t allow further escalation. Of course you may be auditing all the commands you permit in this way but realistically, most people doing this aren’t.
 Some of these issues translate to any other strategy for managing privilege escalation (there is no free lunch); others don’t.
I had typed out something to similar sentiment, then saw your comment.

Certainly getting the escalated process out of the calling user’s environment, as run0 does, is a real improvement. Being able to remove setuid/setgid programs from Linux would be a big step forward in security terms.
I don't agree that removing setuid / setgid binaries from systems is the panacea some make it out to be.
I also suspect that we may be looking at sudo, et al, slightly differently.
All of the use cases we had at my previous employer were business justifiable (as in the business benefited from people running the commands) and had multiple layers of management approval / blessing for the requestor to be able to run them.
So sudo really was a way to conveniently provide the approved commands without the requestor needing to go through the hassle of checking the shared password out of a database, logging in as the target user, running the necessary commands, logging out, and ensuring that the password was rotated.
Sudo was really a way to make it easier for people to access the privileges that they had already been granted.
The more people that need to access a shared account, the more benefit there is in them not utilizing the shared password for everything.
Size of team and managerial bye in makes a HUGE difference.
--
Grant. . . .

Date Sujet#  Auteur
6 May 24 * Yet Another New systemd Feature134Lawrence D'Oliveiro
6 May 24 `* Re: Yet Another New systemd Feature133The Natural Philosopher
6 May 24  +- Re: Yet Another New systemd Feature1Carlos E.R.
6 May 24  +* Re: Yet Another New systemd Feature18Lawrence D'Oliveiro
6 May 24  i+* Re: Yet Another New systemd Feature7Kyonshi
6 May 24  ii+* Re: Yet Another New systemd Feature5The Natural Philosopher
6 May 24  iii`* Re: Yet Another New systemd Feature4Kyonshi
6 May 24  iii +- Re: Yet Another New systemd Feature1Carlos E.R.
6 May 24  iii +- Re: Yet Another New systemd Feature1Grant Taylor
6 May 24  iii `- Re: Yet Another New systemd Feature1The Natural Philosopher
6 May 24  ii`- Re: Yet Another New systemd Feature1Lawrence D'Oliveiro
6 May 24  i`* Re: Yet Another New systemd Feature10The Natural Philosopher
6 May 24  i +* Re: Yet Another New systemd Feature6yeti
6 May 24  i i`* Re: Yet Another New systemd Feature5John McCue
7 May 24  i i `* Re: Yet Another New systemd Feature4Carlos E.R.
7 May 24  i i  +* Re: Yet Another New systemd Feature2The Natural Philosopher
7 May 24  i i  i`- Re: Yet Another New systemd Feature1Joe Beanfish
8 May 24  i i  `- Re: Yet Another New systemd Feature1The Natural Philosopher
6 May 24  i +- Re: Yet Another New systemd Feature1G
6 May 24  i `* Re: Yet Another New systemd Feature2Lawrence D'Oliveiro
7 May 24  i  `- Re: Yet Another New systemd Feature1The Natural Philosopher
6 May 24  `* Re: Yet Another New systemd Feature113Andy Burns
6 May 24   +* Re: Yet Another New systemd Feature106The Natural Philosopher
6 May 24   i+- Re: Yet Another New systemd Feature1Grant Taylor
6 May 24   i+* Re: Yet Another New systemd Feature67Andy Burns
7 May 24   ii`* Re: Yet Another New systemd Feature66Grant Taylor
7 May 24   ii `* Re: Yet Another New systemd Feature65Richard Kettlewell
7 May 24   ii  `* Re: Yet Another New systemd Feature64Grant Taylor
8 May 24   ii   `* Re: Yet Another New systemd Feature63Richard Kettlewell
8 May 24   ii    +- Re: Yet Another New systemd Feature1Lawrence D'Oliveiro
8 May 24   ii    `* Re: Yet Another New systemd Feature61The Natural Philosopher
8 May 24   ii     +* Re: Yet Another New systemd Feature4Richard Kettlewell
8 May 24   ii     i`* Re: Yet Another New systemd Feature3The Natural Philosopher
9 May 24   ii     i `* Re: Yet Another New systemd Feature2Richard Kettlewell
9 May 24   ii     i  `- Re: Yet Another New systemd Feature1vallor
8 May 24   ii     `* Re: Yet Another New systemd Feature56Lawrence D'Oliveiro
9 May 24   ii      `* Re: Yet Another New systemd Feature55The Natural Philosopher
10 May 24   ii       `* Re: Yet Another New systemd Feature54Lawrence D'Oliveiro
10 May 24   ii        `* Re: Yet Another New systemd Feature53The Natural Philosopher
10 May 24   ii         `* Re: Yet Another New systemd Feature52Lawrence D'Oliveiro
11 May 24   ii          +* Re: Yet Another New systemd Feature32The Natural Philosopher
11 May 24   ii          i`* Re: Yet Another New systemd Feature31Lawrence D'Oliveiro
11 May 24   ii          i `* Re: Yet Another New systemd Feature30The Natural Philosopher
11 May 24   ii          i  +- Re: Yet Another New systemd Feature1D
12 May 24   ii          i  `* Re: Yet Another New systemd Feature28Lawrence D'Oliveiro
12 May 24   ii          i   `* Re: Yet Another New systemd Feature27The Natural Philosopher
12 May 24   ii          i    +* Re: Yet Another New systemd Feature21Lawrence D'Oliveiro
12 May 24   ii          i    i+* Re: Yet Another New systemd Feature11D
12 May 24   ii          i    ii`* Re: Yet Another New systemd Feature10Lawrence D'Oliveiro
13 May 24   ii          i    ii `* Re: Yet Another New systemd Feature9D
14 May 24   ii          i    ii  `* Re: Yet Another New systemd Feature8Lawrence D'Oliveiro
14 May 24   ii          i    ii   `* Re: Yet Another New systemd Feature7D
27 May 24   ii          i    ii    `* Re: Yet Another New systemd Feature6Lawrence D'Oliveiro
27 May 24   ii          i    ii     `* Re: Yet Another New systemd Feature5The Natural Philosopher
28 May 24   ii          i    ii      `* Re: Yet Another New systemd Feature4Carlos E.R.
28 May 24   ii          i    ii       `* Re: Yet Another New systemd Feature3The Natural Philosopher
28 May 24   ii          i    ii        `* Re: Yet Another New systemd Feature2Marc Haber
29 May 24   ii          i    ii         `- Re: Yet Another New systemd Feature1Lawrence D'Oliveiro
12 May 24   ii          i    i`* Re: Yet Another New systemd Feature9The Natural Philosopher
12 May 24   ii          i    i `* Re: Yet Another New systemd Feature8Lawrence D'Oliveiro
13 May 24   ii          i    i  +* Re: Yet Another New systemd Feature6D
13 May 24   ii          i    i  i+- Re: Yet Another New systemd Feature1The Natural Philosopher
14 May 24   ii          i    i  i`* Re: Yet Another New systemd Feature4Lawrence D'Oliveiro
14 May 24   ii          i    i  i `* Re: Yet Another New systemd Feature3D
17 May 24   ii          i    i  i  `* Re: Yet Another New systemd Feature2Lawrence D'Oliveiro
18 May 24   ii          i    i  i   `- Re: Yet Another New systemd Feature1D
13 May 24   ii          i    i  `- Re: Yet Another New systemd Feature1The Natural Philosopher
12 May 24   ii          i    `* Re: Yet Another New systemd Feature5D
12 May 24   ii          i     `* Re: Yet Another New systemd Feature4The Natural Philosopher
12 May 24   ii          i      `* Re: Yet Another New systemd Feature3D
13 May 24   ii          i       `* Re: Yet Another New systemd Feature2The Natural Philosopher
14 May 24   ii          i        `- Re: Yet Another New systemd Feature1D
11 May 24   ii          `* Re: Yet Another New systemd Feature19D
11 May 24   ii           +* Re: Yet Another New systemd Feature5The Natural Philosopher
11 May 24   ii           i`* Re: Yet Another New systemd Feature4D
12 May 24   ii           i `* Re: Yet Another New systemd Feature3The Natural Philosopher
12 May 24   ii           i  `* Re: Yet Another New systemd Feature2D
12 May 24   ii           i   `- Re: Yet Another New systemd Feature1The Natural Philosopher
12 May 24   ii           `* Re: Yet Another New systemd Feature13Lawrence D'Oliveiro
12 May 24   ii            `* Re: Yet Another New systemd Feature12D
12 May 24   ii             +* Re: Yet Another New systemd Feature9Lawrence D'Oliveiro
12 May 24   ii             i`* Re: Yet Another New systemd Feature8D
12 May 24   ii             i `* Re: Yet Another New systemd Feature7Lawrence D'Oliveiro
13 May 24   ii             i  `* Re: Yet Another New systemd Feature6D
14 May 24   ii             i   `* Re: Yet Another New systemd Feature5Lawrence D'Oliveiro
14 May 24   ii             i    `* Re: Yet Another New systemd Feature4D
17 May 24   ii             i     `* Re: Yet Another New systemd Feature3Lawrence D'Oliveiro
18 May 24   ii             i      `* Re: Yet Another New systemd Feature2D
27 May 24   ii             i       `- Re: Yet Another New systemd Feature1Lawrence D'Oliveiro
12 May 24   ii             `* Re: Yet Another New systemd Feature2The Natural Philosopher
12 May 24   ii              `- Re: Yet Another New systemd Feature1D
7 May 24   i+* Re: Yet Another New systemd Feature31Lawrence D'Oliveiro
7 May 24   ii+* Re: Yet Another New systemd Feature14Marc Haber
7 May 24   iii`* Re: Yet Another New systemd Feature13Grant Taylor
8 May 24   iii `* Re: Yet Another New systemd Feature12D
8 May 24   iii  `* Re: Yet Another New systemd Feature11Grant Taylor
8 May 24   iii   +* Re: Yet Another New systemd Feature9Carlos E.R.
8 May 24   iii   i+* Re: Yet Another New systemd Feature3Marc Haber
9 May 24   iii   ii`* Re: Yet Another New systemd Feature2Grant Taylor
9 May 24   iii   ii `- Re: Yet Another New systemd Feature1Carlos E.R.
9 May 24   iii   i`* Re: Yet Another New systemd Feature5Grant Taylor
8 May 24   iii   `- Re: Yet Another New systemd Feature1D
7 May 24   ii+- Re: Yet Another New systemd Feature1Lawrence D'Oliveiro
7 May 24   ii`* Re: Yet Another New systemd Feature15candycanearter07
7 May 24   i`* Re: Yet Another New systemd Feature6Lars Poulsen
6 May 24   +* Re: Yet Another New systemd Feature4Grant Taylor
6 May 24   +- Re: Yet Another New systemd Feature1Farley Flud
7 May 24   `- Re: Yet Another New systemd Feature1Woozy Song

Haut de la page

Les messages affichés proviennent d'usenet.

NewsPortal