mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* Securing a system with limits.conf
@ 2009-07-26  4:10 Lasse Kärkkäinen
  2009-07-27 22:46 ` Valdis.Kletnieks
  0 siblings, 1 reply; 2+ messages in thread
From: Lasse Kärkkäinen @ 2009-07-26  4:10 UTC (permalink / raw)
  To: linux-kernel

I'm not sure if this is off-topic for linux-kernel but here it goes...

After doing some research (Googling, checking Hardening Linux, Essential 
System Administration and a number of other books) I was quite shocked 
that configuring the limits doesn't seem to be documented anywhere. 
Sure, they all list the information that can be acquired by ulimit -a or 
man limits.conf but those oneliner descriptions of options fail to describe:

- What does the setting actually limit (one can find what the data 
segment or a core file is by Googling but it would be nicer if the 
documentation listed the security implications of each setting).

- What is the scope of the limit: per-user, per-process, all descendants 
of the current process, ...?

- How should things be configured to reliably prevent non-priveleged 
users from DoS'ing a machine.

Is there possibly some documentation that I have not found or is there 
actually a huge gap in the essential security documentation here?

Thanks.

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2009-07-27 22:46 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2009-07-26  4:10 Securing a system with limits.conf Lasse Kärkkäinen
2009-07-27 22:46 ` Valdis.Kletnieks

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®