Ramesh

I'll look into it tonight and have a patch for you shortly.

Regards
-steve

On Wed, 2008-04-09 at 04:51 +0000, Hegde, Ramesh (OpenCall) wrote:
> Hello,
> 
>  
> 
> We have a strange problem with openais. We have overridden the default
> group in openais.conf as  below.
> 
>  
> 
> aisexec {
> 
>         group: ocadmin
> 
> }
> 
>  
> 
> Now if any user  who does not belongs to ocadmin group try to use
> event service using client API initialize, it will return with error
> SA_AIS_ERR_ACCESS
> 
>  
> 
> However at the same time , aisexecutive crashes and the service
> openais status says “aisexec dead but subsys locked”.
> 
>  
> 
> This is a serious concern as it is a security hole inside openais. Any
> one come across such problems already?  
> 
> 
> 
> I am using whitetank.
> 
>  
> 
> Regards
> 
> Ramesh
> 
>  
> 
>  
> 
> Ramesh Hegde 
> 
> Software Engineer, Hewlett Packard
> 
> 
> India Software Operations Pvt. Ltd 
> 
> 
> Sy No 192, Whitefield Road
> 
> 
> Mahadevapura Post
> 
> 
> Bangalore - 560 048. India. 
> 
> 
> +91 80 2516 6486- Direct 
> 
> 
> +91 80 2513 3522 - Fax 
> 
> 
> Jabber Id : [EMAIL PROTECTED] 
> 
> 
> +hp = everything is possible
> 
>  
> 
> 

_______________________________________________
Openais mailing list
[email protected]
https://lists.linux-foundation.org/mailman/listinfo/openais

Reply via email to