[Bug 296] Priv separation does not work on OSF/1

bugzilla-daemon at mindrot.org bugzilla-daemon at mindrot.org
Thu Jun 27 04:50:32 EST 2002


http://bugzilla.mindrot.org/show_bug.cgi?id=296





------- Additional Comments From mouring at eviladmin.org  2002-06-27 04:50 -------
The platform was not tagged to set 'BROKEN_FD_PASSING'  after ./configure go 
into config.h and grep for it and set it.  It is a temporary work around.

Something that was regretfully missed.  A full solution needs to be forth 
coming from the OSF/1 user/developers.

Summary of issue:

The issue is by time do_child() is ran when PrivSep is enabled it has lost root 
access and therefor can not set the SIA security information.  For this to be 
correctly fixed one has to pre-allocate the TTY *BEFORE* root privs are 
dropped.  This is a massive hack.  And needs someone willing to look at the 
problem to solve.



------- You are receiving this mail because: -------
You are the assignee for the bug, or are watching the assignee.



More information about the openssh-unix-dev mailing list