RE: ACL



Yes. It is wise. If you have an application that writes sensitive
data, you may not want your admins to have access to it as root, either
for accounting reasons or otherwise.

Maarten Broekman
Email: maarten.broekman@xxxxxxx

-----Original Message-----
From: redhat-list-bounces@xxxxxxxxxx
[mailto:redhat-list-bounces@xxxxxxxxxx] On Behalf Of Laszlo BERES
Sent: Monday, July 28, 2008 10:13 AM
To: General Red Hat Linux discussion list
Subject: Re: ACL

Mark Haney wrote:

Are you saying you can deny root access to a file with SELinux? Is
that
ever wise?

Yes, it's possible. Wise or not, there are many scenarios when root
shouldn't see stored data, but have to administer basic system services.

--
Laszlo BERES RHCE, RHCX
senior IT engineer, trainer

--
redhat-list mailing list
unsubscribe mailto:redhat-list-request@xxxxxxxxxx?subject=unsubscribe
https://www.redhat.com/mailman/listinfo/redhat-list


--
redhat-list mailing list
unsubscribe mailto:redhat-list-request@xxxxxxxxxx?subject=unsubscribe
https://www.redhat.com/mailman/listinfo/redhat-list



Relevant Pages

  • Re: Not Enough Memory Error?
    ... >>I have root as default with a passwordless automatic login. ... >>seem as if that might be not wise. ... > No more unwise than sky diving without a chute. ...
    (alt.os.linux.suse)
  • Re: LEDs
    ... a wise man stops as soon as possible. ... You must examine the root of the word. ... Wilbur Hubbard ...
    (rec.boats.cruising)
  • Re: ACL
    ... Wise or not, there are many scenarios when root shouldn't see stored data, but have to administer basic system services. ...
    (RedHat)
  • Re: LEDs
    ... Wilbur Hubbard ... a wise man stops as soon as possible. ... You must examine the root of the word. ...
    (rec.boats.cruising)
  • Re: "Bugbear" virus in Linux?
    ... >> I am one of several Unix admins in a relatively large corporation. ... > root login shell running if it is legitimate or not. ... Given your description of sudo, I'd like to hear what additional risk there ...
    (comp.os.linux.misc)