I have NRPE running on Solaris 10 SPARC under SMF, but the only way I could get 
it to run as user nagios is if I set SUID on the nrpe executable.

This is the output inetadm -l svc:/network/nrpe/tcp:default

SCOPE    NAME=VALUE
         name="nrpe"
         endpoint_type="stream"
         proto="tcp"
         isrpc=FALSE
         wait=FALSE
         exec="/usr/local/nagios/bin/nrpe -c /usr/local/nagios/etc/nrpe.cfg -i"
         arg0="/usr/local/nagios/bin/nrpe"
         user="nagios"
default  bind_addr=""
default  bind_fail_max=-1
default  bind_fail_interval=-1
default  max_con_rate=-1
default  max_copies=-1
default  con_rate_offline=-1
default  failrate_cnt=40
default  failrate_interval=60
default  inherit_env=TRUE
default  tcp_trace=FALSE
default  tcp_wrappers=FALSE

user="nagios" , but if I don't do the SUID I get in the system log:
nrpe[10222]: [ID 306117 auth.error] Error: NRPE daemon cannot be run as 
user/group root!

I've searched the web and the archives to no avail. Does anyone have experience 
running NRPE under SMF? Any concerns about running it SUID? Thanks so much.



Robert C. Cipriani
Senior Network Administrator
Tampa Bay Division IT
Bright House Networks
W: (727) 329-2000 x74264
M: (727) 365-1231






________________________________
CONFIDENTIALITY NOTICE: This e-mail may contain information that is privileged, 
confidential or otherwise protected from disclosure. If you are not the 
intended recipient of this e-mail, please notify the sender immediately by 
return e-mail, purge it and do not disseminate or copy it.
-------------------------------------------------------------------------
This SF.net email is sponsored by: Microsoft
Defy all challenges. Microsoft(R) Visual Studio 2008.
http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/
_______________________________________________
Nagios-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/nagios-users
::: Please include Nagios version, plugin version (-v) and OS when reporting 
any issue. 
::: Messages without supporting info will risk being sent to /dev/null

Reply via email to