OpenVZ Forum


Home » General » Support » Pureftpd and Linux capabilties
Re: Pureftpd and Linux capabilties [message #4209 is a reply to message #4203] Sun, 02 July 2006 20:50 Go to previous messageGo to previous message
christoph is currently offline  christoph
Messages: 19
Registered: July 2006
Junior Member
Hi!

Thanks for the fast (especially on Sunday Wink) and competent answer.

I found out with strace that pureftpd likes to set the following capabilities:

CHOWN DAC_READ_SEARCH SETGID SETUID NET_BIND_SERVICE NET_ADMIN SYS_CHROOT SYS_NICE CHOWN DAC_READ_SEARCH SETGID SETUID NET_BIND_SERVICE NET_ADMIN SYS_CHROOT SYS_NICE

I activated those via vzctl and it works perfectly now!

One thing I was thinking about. What about security when all those capabilities are set?

Christoph
 
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Read Message
Previous Topic: OpenVZ and Fedora 16
Next Topic: passwd for ssh (OpenVZ)
Goto Forum:
  


Current Time: Sun Aug 04 08:15:17 GMT 2024

Total time taken to generate the page: 0.02561 seconds