Re: [Vserver] Issues of Security

2006-04-25 Thread Oliver Welter
Hi Manish, Has anybody done any work or study on security of vserver. What are the possible security downsides and possible areas of attack on vserver both from other vservers on the same host and from external agent. Any pointers on this would be very helpful. Thanks, I havent done a study, b

Re: [Vserver] secure a guest against the host's root-account

2006-04-25 Thread Serge E. Hallyn
Quoting Oliver Welter ([EMAIL PROTECTED]): > Hi Mike, Serge, > > >>>So, is there any way to do this ? I guess that SELinux/GR will offer > >>>some pointers to forbid root these actions, but are there any "easier" > >>>ways ?? > >>> > >>Sounds like SELinux is the tool of choice for that. > > > >A

[Vserver] Issues of Security

2006-04-25 Thread Manish Nair
Has anybody done any work or study on security of vserver. What are the possible security downsides and possible areas of attack on vserver both from other vservers on the same host and from external agent. Any pointers on this would be very helpful. Thanks, Manish. __

[Vserver] /vservers as an nfs mount?

2006-04-25 Thread Chuck
we are completely restructuring our entire physical network around the vserver concept. it has proven itself in stability and performance in production to the point we no longer see the need for dedicated servers except in the most demanding instances (mostly our email server which cannot be

[Vserver] Which capabilities I must set to run mDNSresponder ?

2006-04-25 Thread Sébastien CRAMATTE
Hello I try to run mt-daapd daemon + mDNSResponder into a vserver. mt-daapd runs perfectly but mDNSreponder can't bind the IP itunes:/usr/local/bin# mDNSResponder -d -a 192.168.1.11 [assert] error: 99 (Cannot assign requested address) [assert] where: "Posix/posix_interface.c", "sw_posix_networ

[Vserver] [x86_64] (AMD) 2.6.16.9(=8)-vs2.0.2-rc17 works with FC4/5

2006-04-25 Thread Guenther Fuchs
Hi there, just changed subversion of "8" to "9" and rc17 works fine with FC4 and also FC5. Both AMD Athlon 64 (single processor) and AMD Opteron dual- core work fine with 2.6.16.9 kernel an 2.6.16.8-vs2.0.2-rc17 patch. # ./testme.sh -Lv 4 records (Opteron SMP kernel): snip Linux-VServe

[Vserver] search debian sid iso file to use with vserver. My deboot can't get operational sid version

2006-04-25 Thread Sébastien CRAMATTE
Hello I' search for iso file for debian sid, ubuntu, ... to use with my vserver Because my debootstrap can't get a valid sid install. It. Can't found base-config and some libs #REMOVE_PACKAGES="sparc-utils,dhcp-client,lilo,makedev,pcmcia-cs,ppp, pppconfig,pppoe,pppoeconf,setserial,syslinux,

Re: [Vserver] secure a guest against the host's root-account

2006-04-25 Thread Sebastian Harl
> "open-up-vservers-like-cracked-eggs.ko"? That sounds interesting - where do I get that one from ;-) -- Sebastian "tokkee" Harl GnuPG-ID: 0x8501C7FC http://tokkee.org/ signature.asc Description: Digital signature ___ Vserver mailing list Vserver@li

Re: [Vserver] secure a guest against the host's root-account

2006-04-25 Thread Serge E. Hallyn
Quoting Eugen Leitl ([EMAIL PROTECTED]): > On Tue, Apr 25, 2006 at 08:25:37PM +1000, Tony Lewis wrote: > > > I think this would be a valuable addition to vservers. One of the risks > > of "renting" a virtual server (pick your flavour) is that you're not > > safe from the hosting sysadmin. If v

[Vserver] [x86] 2.6.16.8(9)-vs2.0.2-rc17 works with FC5

2006-04-25 Thread Guenther Fuchs
Hi there, just changed subversion of "8" to "9" and rc17 works fine with FC5. Don't know if vs has much changed, but kernel 2.6.16 to 2.6.16.9 has some important changes for my runtime, so will also change AMD env now as well. output 4 records: --- snip --- # ./testme.sh -Lv Linux-VServer Test

Re: [Vserver] secure a guest against the host's root-account

2006-04-25 Thread Eugen Leitl
On Tue, Apr 25, 2006 at 08:25:37PM +1000, Tony Lewis wrote: > I think this would be a valuable addition to vservers. One of the risks > of "renting" a virtual server (pick your flavour) is that you're not > safe from the hosting sysadmin. If vservers could offer something like You are never

Re: [Vserver] secure a guest against the host's root-account

2006-04-25 Thread Tony Lewis
Herbert Poetzl wrote: On Mon, Apr 24, 2006 at 08:02:43AM +0200, Oliver Welter wrote: So, is there any way to do this? definitely, if you plan to pursue this direction, please contact me and I will see what I can do. I think this would be a valuable addition to vservers. One of t

Re: [Vserver] forcedeth module for 2.6.14-amd64-smp-vs

2006-04-25 Thread Eugen Leitl
On Tue, Apr 25, 2006 at 10:07:58AM +0200, Markus Neubauer wrote: > Maybe you want to give my personal latest a try > http://helpdesk.std-service.de/kernel-image-2.6.15-amd64-smp-vs_0.94_amd64.deb > (still very reduced modules, but most network drivers). That one brought the eth1 interface up. Tha

[Vserver] fam inside vserver (kernel 2.6)

2006-04-25 Thread Wolfgang Hennerbichler
Hi! Kernel: 2.6.16-vs2.0.2-rc14 I'd like to use fam within a vserver, but unfortunately this doesn't seem to work. DNOTIFY is set in the kernel but still fam can't monitor files. Do I need a special 'capability' inside this vserver? thanks; wogri -- [EMAIL PROTECTED] http://www.wogri.com

Re: [Vserver] forcedeth module for 2.6.14-amd64-smp-vs

2006-04-25 Thread Markus Neubauer
Eugen Leitl schrieb: > I'm running 2.6.14-amd64-smp-vs on a Sun Fire X2100. Unfortunately, > 2.6.14-amd64-smp-vs lacks the forcedeth module, so only the Broadcom > NIC is usable. > > I didn't catch this in time to try building my own 2.6.14-amd64-smp-vs > Does anyone here have a new Debian package