mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Florian Weimer <Florian.Weimer@RUS.Uni-Stuttgart.DE>
To: Andi Kleen <ak@suse.de>
Cc: linux-kernel@vger.kernel.org
Subject: Re: getpeereid() for Linux
Date: 05 Sep 2001 12:05:50 +0200	[thread overview]
Message-ID: <tgu1yi2br5.fsf@mercury.rus.uni-stuttgart.de> (raw)
In-Reply-To: <tgsne23sou.fsf@mercury.rus.uni-stuttgart.de.suse.lists.linux.kernel> <oupae0ax8vq.fsf@pigdrop.muc.suse.de>
In-Reply-To: <oupae0ax8vq.fsf@pigdrop.muc.suse.de> (Andi Kleen's message of "05 Sep 2001 11:52:09 +0200")

Andi Kleen <ak@suse.de> writes:

> Florian Weimer <Florian.Weimer@RUS.Uni-Stuttgart.DE> writes:
> 
> > Would anyone like to give me a helping hand in implementing the
> > getpeereid() syscall for Linux?  See the following page for the
> > documentation of the OpenBSD implementation:
> 
> It is implemented for unix sockets (see unix(7))

Hmm, it is not documented in my local copy (?).  getpeereid() is
different from the standard credential passing mechanism because it
does not require cooperation of the other end.

> For TCP it is rather useless because it would work only locally.

Obviously, we need it only locally. ;-) The interface is useful if you
are implementing poor man's VPN in user space.

> If you trust the localhost you're probably better off using the
> ident protocol for it.

This means running just another server, even with root privileges. :-(

-- 
Florian Weimer 	                  Florian.Weimer@RUS.Uni-Stuttgart.DE
University of Stuttgart           http://cert.uni-stuttgart.de/
RUS-CERT                          +49-711-685-5973/fax +49-711-685-5898

  reply	other threads:[~2001-09-05 10:10 UTC|newest]

Thread overview: 12+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <tgsne23sou.fsf@mercury.rus.uni-stuttgart.de.suse.lists.linux.kernel>
2001-09-05  9:52 ` Andi Kleen
2001-09-05 10:05   ` Florian Weimer [this message]
2001-09-05 10:48     ` Andi Kleen
2001-09-05 10:56       ` Florian Weimer
2001-09-05 16:19 Jesse Pollard
2001-09-05 16:36 ` Florian Weimer
  -- strict thread matches above, loose matches on Subject: below --
2001-09-05 15:51 Jesse Pollard
2001-09-05 15:53 ` Florian Weimer
2001-09-05 20:26   ` H. Peter Anvin
2001-09-05  9:14 Florian Weimer
2001-09-05 13:38 ` Michael Bacarella
2001-09-05 14:35   ` Florian Weimer

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=tgu1yi2br5.fsf@mercury.rus.uni-stuttgart.de \
    --to=florian.weimer@rus.uni-stuttgart.de \
    --cc=ak@suse.de \
    --cc=linux-kernel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®