delorie.com/archives/browse.cgi   search  
Mail Archives: cygwin/2004/03/23/09:53:32

Mailing-List: contact cygwin-help AT cygwin DOT com; run by ezmlm
List-Subscribe: <mailto:cygwin-subscribe AT cygwin DOT com>
List-Archive: <http://sources.redhat.com/ml/cygwin/>
List-Post: <mailto:cygwin AT cygwin DOT com>
List-Help: <mailto:cygwin-help AT cygwin DOT com>, <http://sources.redhat.com/ml/#faqs>
Sender: cygwin-owner AT cygwin DOT com
Mail-Followup-To: cygwin AT cygwin DOT com
Delivered-To: mailing list cygwin AT cygwin DOT com
X-Authentication-Warning: denzel.sciencetools.com: rtroy owned process doing -bs
Date: Tue, 23 Mar 2004 07:04:05 -0800 (PST)
From: Richard Troy <rtroy AT ScienceTools DOT com>
To: <cygwin AT cygwin DOT com>
Subject: Re: suid bit on executables?
In-Reply-To: <20040323105820.GB13267@cygbert.vinschen.de>
Message-ID: <Pine.LNX.4.33.0403230654282.1808-100000@denzel.sciencetools.com>
MIME-Version: 1.0
X-IsSubscribed: yes

On Tue, 23 Mar 2004, Corinna Vinschen wrote:
> On Mar 22 19:49, Richard Troy wrote:
> > A little over a year ago, I poked my nose under the tent to inquire about
> > this once more and in the interrim there had been a new cygserver and a
> > new ssh daemon, and I was very happy with the advance, but still things
> > were short of the SUID bit being honored...
> >
> > Now, I read in the archives about something, apparently upcoming, called
> > cygdaemon... I read hints that cygdaemon helps address this problem.
>
> There's no such thing as a cygdaemon, only cygserver.  If the SUID stuff
> gets implemented, it will be based on cygserver.  But there's no code
> for doing this so far.  Security changes in 2K3 are making an implementation
> even more complex.
>
> Corinna

Thank you, Corinna.

...might you please propose a work-around for the following scenario?

If I wanted just one particular program to run as this other user, there's
that nifty tool in Cygwin that lets you define a service that _can_ run as
another user. This would work for me if I had a way for a Cygwin program,
launched from a command-line interface, from Bash, say, to attach to it
and let it do the dirty work. It would need a way to pass command-line
arguments, and redirect or share std-in, std-out, and std-error. ...I know
there's the SSHD code that could serve as an example, but it seems to me
that it's overkill for what I want since there's no need for it to
credential itself as anyone. ...The simpler, the better, so long as it's
sufficient!

Thank you for your suggestions/ideas,

Richard


-- 
Richard Troy, Chief Scientist
Science Tools Corporation
rtroy AT ScienceTools DOT com, 510-567-9957, http://ScienceTools.com/


--
Unsubscribe info:      http://cygwin.com/ml/#unsubscribe-simple
Problem reports:       http://cygwin.com/problems.html
Documentation:         http://cygwin.com/docs.html
FAQ:                   http://cygwin.com/faq/

- Raw text -


  webmaster     delorie software   privacy  
  Copyright © 2019   by DJ Delorie     Updated Jul 2019