Bug#298060: (forw) Bug#298060: Please don't install login as setuid root

2005-03-08 Thread Michael Banck
On Tue, Mar 08, 2005 at 05:03:11PM +0100, Wouter Verhelst wrote: > Op za, 05-03-2005 te 22:56 -0800, schreef Matt Zimmerman: > > On Sat, Mar 05, 2005 at 03:34:58PM +0100, Christian Perrier wrote: > > > > > Security and release teams, may I have your advice about this suggestion? > > > > > > As yo

Bug#298060: (forw) Bug#298060: Please don't install login as setuid root

2005-03-08 Thread Samuel Thibault
Wouter Verhelst, le mar 08 mar 2005 17:03:11 +0100, a dit : > Op za, 05-03-2005 te 22:56 -0800, schreef Matt Zimmerman: > > On Sat, Mar 05, 2005 at 03:34:58PM +0100, Christian Perrier wrote: > > > > > Security and release teams, may I have your advice about this suggestion? > > > > > > As you may

Bug#298060: (forw) Bug#298060: Please don't install login as setuid root

2005-03-08 Thread Wouter Verhelst
Op za, 05-03-2005 te 22:56 -0800, schreef Matt Zimmerman: > On Sat, Mar 05, 2005 at 03:34:58PM +0100, Christian Perrier wrote: > > > Security and release teams, may I have your advice about this suggestion? > > > > As you may know, I currently act as maintainer for the shadow package, > > but I'm

Bug#298060: (forw) Bug#298060: Please don't install login as setuid root

2005-03-07 Thread Steve Langasek
On Sun, Mar 06, 2005 at 05:24:06PM -0800, Matt Zimmerman wrote: > On Sun, Mar 06, 2005 at 04:34:32PM -0800, Joey Hess wrote: > > Has anyone looked at shadow's existing changelog? > > * /bin/login is suid root for several good reasons. For one, it allows > > daemons that use it to run as non

Bug#298060: (forw) Bug#298060: Please don't install login as setuid root

2005-03-07 Thread Martin Schulze
Christian Perrier wrote: > Security and release teams, may I have your advice about this suggestion? > > As you may know, I currently act as maintainer for the shadow package, > but I'm also aware of my own weaknesses when it comes at security (and > security-related) issues so I prefer getting th

Bug#298060: (forw) Bug#298060: Please don't install login as setuid root

2005-03-07 Thread Matt Zimmerman
On Sun, Mar 06, 2005 at 10:19:08PM -0800, Joey Hess wrote: > Matt Zimmerman wrote: > > I'm more than willing to consider telnetd a legacy, insecure-by-design > > component for which it is justified to require a non-default configuration. > > , my multiple uses of telnetd are all secure. :-P I ju

Bug#298060: (forw) Bug#298060: Please don't install login as setuid root

2005-03-06 Thread Christian Perrier
Quoting Joey Hess ([EMAIL PROTECTED]): > Has anyone looked at shadow's existing changelog? Honestly, no..:-) > see shy jo (hurrah for changelog abuse!) Yep. Sometimes this helps especially for packages where Debian specific changes are noticeable. Well, about this issue, I think I'll delay this

Bug#298060: (forw) Bug#298060: Please don't install login as setuid root

2005-03-06 Thread Joey Hess
Matt Zimmerman wrote: > I'm more than willing to consider telnetd a legacy, insecure-by-design > component for which it is justified to require a non-default configuration. , my multiple uses of telnetd are all secure. :-P -- see shy jo signature.asc Description: Digital signature

Bug#298060: (forw) Bug#298060: Please don't install login as setuid root

2005-03-06 Thread Matt Zimmerman
On Sun, Mar 06, 2005 at 04:34:32PM -0800, Joey Hess wrote: > Has anyone looked at shadow's existing changelog? > > * /bin/login is suid root for several good reasons. For one, it allows > daemons that use it to run as non-root. This is a good thing since it > means only one program is r

Bug#298060: (forw) Bug#298060: Please don't install login as setuid root

2005-03-06 Thread Joey Hess
Has anyone looked at shadow's existing changelog? * /bin/login is suid root for several good reasons. For one, it allows daemons that use it to run as non-root. This is a good thing since it means only one program is running as root, and not several. closes: #17911 -- Ben Collins <[EMA

Bug#298060: (forw) Bug#298060: Please don't install login as setuid root

2005-03-06 Thread Steve Langasek
explain why this is actually useful (since no one else can think of a reason). -- Steve Langasek postmodern programmer > - Forwarded message from Martin Pitt <[EMAIL PROTECTED]> - > > Subject: Bug#298060: Please don't install login as setuid root > Reply-To: Martin

Bug#298060: (forw) Bug#298060: Please don't install login as setuid root

2005-03-06 Thread Christian Perrier
> (what does this have to do with debian-release?) Because I was wondering whether such change would be appropriate to have in sarge and I wanted to get the wise advice of our release managers...:) -- -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? C

Bug#298060: (forw) Bug#298060: Please don't install login as setuid root

2005-03-06 Thread Matt Zimmerman
On Sun, Mar 06, 2005 at 05:10:59AM -0600, Bill Allombert wrote: > On Sat, Mar 05, 2005 at 10:56:45PM -0800, Matt Zimmerman wrote: > > FWIW, We've been doing this for some time in Ubuntu, and no one has > > missed it. In this age of pseudoterminals and single-user systems... > > Because that is t

Bug#298060: (forw) Bug#298060: Please don't install login as setuid root

2005-03-06 Thread Bill Allombert
On Sat, Mar 05, 2005 at 10:56:45PM -0800, Matt Zimmerman wrote: > On Sat, Mar 05, 2005 at 03:34:58PM +0100, Christian Perrier wrote: > > > Security and release teams, may I have your advice about this suggestion? > > > > As you may know, I currently act as maintainer for the shadow package, > > b

Bug#298060: (forw) Bug#298060: Please don't install login as setuid root

2005-03-05 Thread Matt Zimmerman
On Sat, Mar 05, 2005 at 03:34:58PM +0100, Christian Perrier wrote: > Security and release teams, may I have your advice about this suggestion? > > As you may know, I currently act as maintainer for the shadow package, > but I'm also aware of my own weaknesses when it comes at security (and > secu

Bug#298060: (forw) Bug#298060: Please don't install login as setuid root

2005-03-05 Thread Steve Kemp
On Sat, Mar 05, 2005 at 03:34:58PM +0100, Christian Perrier wrote: > Security and release teams, may I have your advice about this suggestion? > > As you may know, I currently act as maintainer for the shadow package, > but I'm also aware of my own weaknesses when it comes at security (and > secur

Bug#298060: (forw) Bug#298060: Please don't install login as setuid root

2005-03-05 Thread Christian Perrier
#298060: Please don't install login as setuid root Reply-To: Martin Pitt <[EMAIL PROTECTED]>, [EMAIL PROTECTED] Date: Fri, 4 Mar 2005 12:39:11 +0100 From: Martin Pitt <[EMAIL PROTECTED]> To: Debian Bug Tracking System <[EMAIL PROTECTED]> Package: login Version: 1:4.0.3-30

Bug#298060: Please don't install login as setuid root

2005-03-04 Thread Martin Pitt
Package: login Version: 1:4.0.3-30.9 Severity: wishlist Tags: patch Hi! /bin/login is currently installed setuid root, which is absolutely not necessary and only a potential security threat. In Ubuntu we install it as 0755 for ages now without any problems. Trivial patch, but for the record: