RE: Read Only File System

From: Nathaniel Hall (halln_at_otc.edu)
Date: 06/08/04

  • Next message: Rodolfo J. Paiz: "Re: dns - to delegate or not"
    To: <redhat-list@redhat.com>
    Date: Tue, 8 Jun 2004 15:08:15 -0500
    
    

    Ok, building on that, is there anyway to make an append only file system and
    make it where root cannot change or delete anything in the logs?

    ~~~~~~~~~~~~~~~~~~~~~~~~~~
    Nathaniel Hall
    Intrusion Detection and Firewall Technician
    Ozarks Technical Community College -- Office of Computer Networking
    417-799-0552

    -----Original Message-----
    From: Henry Axelrod [mailto:AxelrodH@emigrant.com]
    Sent: Tuesday, June 08, 2004 3:03 PM
    To: halln@otc.edu; redhat-list@redhat.com
    Subject: Re: Read Only File System

    You can do this by creating a sepreate partition or drive to mount for
    that fs. When you add the entry to /etc/fstab you can place "ro" in the
    options column. For Example:

    LABEL=/home /home ext3 ro 1 1

    The preceding line will mount the home directory as read only. You will
    of course have to remeber to label the partition as /home. You will also
    probably want to add more options then just read only. This is just an
    example.

    >>> halln@otc.edu 6/8/2004 3:44:25 PM >>>
    I am working a creating a remote log server using RedHat Advanced
    Server 3.
    I would like to be able to make an entire file system read only where
    root
    can't even change the contents. Does anybody know of a way to do
    this?

     

    ~~~~~~~~~~~~~~~~~~~~~~~~~~

    Nathaniel Hall

    Intrusion Detection and Firewall Technician

    Ozarks Technical Community College -- Office of Computer Networking

    417-799-0552

     

    -- 
    redhat-list mailing list
    unsubscribe mailto:redhat-list-request@redhat.com?subject=unsubscribe 
    https://www.redhat.com/mailman/listinfo/redhat-list 
    _____________
    LEGAL NOTICE
    Unless expressly stated otherwise, this message is confidential
    and may be privileged. It is intended for the addressee(s) only.
    Access to this E-mail by anyone else is unauthorized.
    If you are not an addressee, any disclosure or copying of the
    contents of this E-mail or any action taken (or not taken) in
    reliance on it is unauthorized and may be unlawful. If you are not an
    addressee, please inform the sender immediately, then delete this
    message and empty from your trash.
    -- 
    redhat-list mailing list
    unsubscribe mailto:redhat-list-request@redhat.com?subject=unsubscribe
    https://www.redhat.com/mailman/listinfo/redhat-list
    

  • Next message: Rodolfo J. Paiz: "Re: dns - to delegate or not"

    Relevant Pages

    • RE: Read Only File System
      ... not stop them being deleted by root as quite simply, ... On Tue, 8 Jun 2004, Nathaniel Hall wrote:> Ok, building on that, is there anyway to make an append only file system and> make it where root cannot change or delete anything in the logs? ... > Intrusion Detection and Firewall Technician> Ozarks Technical Community College -- Office of Computer Networking ...
      (RedHat)
    • Re: what to do about "cannot dump to dumpdev hd(1/41): space for
      ... smoke out anything that would point to root being there. ... whole disk division and maybe boot but nothing else. ... I've see that before when a client used Microlite Backup ... alter the file system and log its results to /tmp/logfsck. ...
      (comp.unix.sco.misc)
    • Isolated Base Installation?
      ... which will allow a FUSE File System to read through itself. ... FUSE file systems can be used to make snapshots. ... IBI is a method for preserving the install time ... The basic premise for IBI is that when the system is installed, the root ...
      (Ubuntu)
    • Re: Disabling "Edit with Vim " context menu entry in Windows?
      ... knew something about Usenet. ... One thing rumored for what became Longhorn was an entirely new file system based on SQL Server. ... Arguably root needs it more than other users, ... I'm trying to fill in the blanks in the wiki's info on early text editors and the evolution of editor design. ...
      (comp.editors)
    • Re: RFC: root mount enhancement (round 2)
      ... :>: Let me mention a problem with the currently implemented root mount ... I prefer mounting the root file system as soon as the device appears ... medium and software images are ISO images stored in it. ...
      (freebsd-arch)