From: Jan Harkes <jaharkes@cs.cmu.edu>
To: linux-kernel@vger.kernel.org, linux-fsdevel@vger.kernel.org
Subject: Re: [OpenAFS-devel] Re: [PATCH] in-core AFS multiplexor and PAG support
Date: Tue, 13 May 2003 14:44:12 -0400 [thread overview]
Message-ID: <20030513184411.GC30766@delft.aura.cs.cmu.edu> (raw)
In-Reply-To: <B578DAA4FD40684793C953B491D4879174D3B9@umr-mail7.umr.edu>
On Tue, May 13, 2003 at 01:25:17PM -0500, Neulinger, Nathan wrote:
> > > If someone obtains my user id on in any way (i.e. weak password/
> > > bufferoverflow/ root exploit), he should not be allowed to use or access
> > > my tokens as he hasn't proven his identity. In this case he would either
> > > still be in his original process authentication group, or a new and
> > > empty PAG. But definitely not in any of my authentication groups.
> > >
> > > Which is also why joining a PAG should never be allowed.
> >
> > Someone asked for it, but I suspect if allowed at all it may
> > be best that this
> > ability is governed by its own capability bit and also that
> > the security
> > interface should be consulted.
>
> Definately. This is only allowed for root in any case. (Or the cap as
> you describe.)
I don't care if the local user id is 'root', or 'nobody'. As long as
this session hasn't gone through the steps to prove its identity, it
should not be allowed to hijack an existing session.
What should be allowed is for someone to obtain credentials (tokens) and
explicitly pass them to another PAG. Which is probably the reason you
want to be able to join a PAG in the first place.
situation:
"Hmm, my AFS tokens on my desktop are about to expire"
solution 1 (which I believe is bad):
"log in remotely, join the existing PAG and refresh the tokens"
solution 2:
"log in remotely, obtain new tokens and explicitly pass them to
another PAG"
A really bad reason for joining a PAG would be that you want to log in
remotely, but don't want to pay for the cost of proving your identity in
the new session.
Jan
next prev parent reply other threads:[~2003-05-13 18:31 UTC|newest]
Thread overview: 19+ messages / expand[flat|nested] mbox.gz Atom feed top
2003-05-13 18:25 Neulinger, Nathan
2003-05-13 18:44 ` Jan Harkes [this message]
-- strict thread matches above, loose matches on Subject: below --
2003-05-13 19:00 Neulinger, Nathan
2003-05-13 19:19 ` Douglas E. Engert
2003-05-13 18:53 David Howells
2003-05-13 20:19 ` [OpenAFS-devel] " Derrick J Brashear
2003-05-13 22:51 ` Booker Bense
2003-05-13 18:23 Neulinger, Nathan
2003-05-13 17:48 Neulinger, Nathan
2003-05-13 16:05 David Howells
2003-05-13 16:24 ` [OpenAFS-devel] " Douglas E. Engert
2003-05-13 16:47 ` Linus Torvalds
2003-05-13 17:20 ` Jan Harkes
2003-05-13 18:51 ` [OpenAFS-devel] " Douglas E. Engert
2003-05-13 20:33 ` Jan Harkes
2003-05-13 21:26 ` Douglas E. Engert
2003-05-13 21:40 ` Jan Harkes
2003-05-13 22:14 ` Douglas E. Engert
2003-05-14 2:02 ` Jan Harkes
2003-05-17 12:30 ` Pavel Machek
2003-05-18 14:22 ` [OpenAFS-devel] " Nathan Neulinger
2003-05-18 18:06 ` Pavel Machek
2003-05-13 15:52 Linus Torvalds
2003-05-13 15:44 ` Alan Cox
2003-05-13 21:46 ` [OpenAFS-devel] " Russ Allbery
2003-05-16 15:38 ` Derek Atkins
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20030513184411.GC30766@delft.aura.cs.cmu.edu \
--to=jaharkes@cs.cmu.edu \
--cc=linux-fsdevel@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®