Re: [X2go-dev] concept for X2go session lock-down to kiosk-mode (was Re: X2go is insecure)

2011-04-01 Thread Erik Auerswald
Hi Mike, On Fri, Apr 01, 2011 at 10:31:51AM +0200, Mike Gabriel wrote: > Sorry, I mixed both systems up. I want to refer to SELinux... I haven't > work with any of them, and only know them from reading. However, I think > the time being invested by someone in a wrapper script (->Dick...) it > c

Re: [X2go-dev] concept for X2go session lock-down to kiosk-mode (was Re: X2go is insecure)

2011-04-01 Thread Mike Gabriel
Hi Alex, hi Dick, On Fr 01 Apr 2011 10:07:15 CEST Alexander Wuerstlein wrote: > Maybe this can be achieved also by apparmor, but it looks to me that > apparmor is intended to secure the entire system which is really not > what I want. (Or maybe I am mistaken because of lack of knowledge of > ap

Re: [X2go-dev] concept for X2go session lock-down to kiosk-mode (was Re: X2go is insecure)

2011-04-01 Thread Dick Kniep
- Van: John A. Sullivan III Verzonden: vr 01-04-11 02:56:09 Aan: x2go-dev@lists.berlios.de; Onderwerp: Re: [X2go-dev] concept for X2go session lock-down to kiosk-mode (was Re: X2go is insecure) On Fri, 2011-04-01 at 02:44 +0200, Dick Kniep wrote: > Hi list, > >   > > Reading all com

Re: [X2go-dev] concept for X2go session lock-down to kiosk-mode (was Re: X2go is insecure)

2011-04-01 Thread Alexander Wuerstlein
On 11-04-01 04:58, Gerry Reno wrote: > On 03/31/2011 08:44 PM, Dick Kniep wrote: > > > > Hi list, > > > > > > > > Reading all comments on my stone in the pond I still think it is not > > really clear what the problem is (and my proposed solution) > > > > > > I do not want to secure the entire se

Re: [X2go-dev] concept for X2go session lock-down to kiosk-mode (was Re: X2go is insecure)

2011-03-31 Thread Erik Auerswald
Hi, On Thu, Mar 31, 2011 at 08:55:40PM -0400, John A. Sullivan III wrote: > On Fri, 2011-04-01 at 02:44 +0200, Dick Kniep wrote: > > > > I do not want to secure the entire server. I only want a door that can > > be locked. So I allow a user to use the terminal. Okay he is allowed > > to use the t

Re: [X2go-dev] concept for X2go session lock-down to kiosk-mode (was Re: X2go is insecure)

2011-03-31 Thread Gerry Reno
On 03/31/2011 08:44 PM, Dick Kniep wrote: > > Hi list, > > > > Reading all comments on my stone in the pond I still think it is not > really clear what the problem is (and my proposed solution) > > > I do not want to secure the entire server. I only want a door that can > be locked. So I allow a

Re: [X2go-dev] concept for X2go session lock-down to kiosk-mode (was Re: X2go is insecure)

2011-03-31 Thread John A. Sullivan III
On Fri, 2011-04-01 at 02:44 +0200, Dick Kniep wrote: > Hi list, > > > > Reading all comments on my stone in the pond I still think it is not > really clear what the problem is (and my proposed solution) > > > I do not want to secure the entire server. I only want a door that can > be locked.

Re: [X2go-dev] concept for X2go session lock-down to kiosk-mode (was Re: X2go is insecure)

2011-03-31 Thread Dick Kniep
erwerp: Re: [X2go-dev] concept for X2go session lock-down to kiosk-mode (was Re: X2go is insecure) Hi Dick, On Mi 30 Mär 2011 18:46:49 CEST Dick Kniep wrote: > We have developed the wrapper that does exactly what I describe   > here. Currently it is lacking a screen where an authorized use

Re: [X2go-dev] concept for X2go session lock-down to kiosk-mode (was Re: X2go is insecure)

2011-03-30 Thread Mike Gabriel
Hi Dick, On Mi 30 Mär 2011 18:46:49 CEST Dick Kniep wrote: We have developed the wrapper that does exactly what I describe here. Currently it is lacking a screen where an authorized user can change the authorization db, but that will come on short notice. I hope it is a little clearer now

Re: [X2go-dev] concept for X2go session lock-down to kiosk-mode (was Re: X2go is insecure)

2011-03-30 Thread Dick Kniep
-dev@lists.berlios.de; Onderwerp: Re: [X2go-dev] concept for X2go session lock-down to kiosk-mode (was Re: X2go is insecure) On Wed, 2011-03-30 at 10:58 +0200, Erik Auerswald wrote: > Hi, > > On Tue, Mar 29, 2011 at 06:31:07PM +0200, Mike Gabriel wrote: > > On Di 29 Mär 201

Re: [X2go-dev] concept for X2go session lock-down to kiosk-mode (was Re: X2go is insecure)

2011-03-30 Thread John A. Sullivan III
On Wed, 2011-03-30 at 10:58 +0200, Erik Auerswald wrote: > Hi, > > On Tue, Mar 29, 2011 at 06:31:07PM +0200, Mike Gabriel wrote: > > On Di 29 Mär 2011 16:55:50 CEST Alexander Wuerstlein wrote: > >> On 11-03-29 15:36, Dick Kniep wrote: > > > >> An authorized user running commands over ssh is not a

Re: [X2go-dev] concept for X2go session lock-down to kiosk-mode (was Re: X2go is insecure)

2011-03-30 Thread Erik Auerswald
Hi, On Tue, Mar 29, 2011 at 06:31:07PM +0200, Mike Gabriel wrote: > On Di 29 Mär 2011 16:55:50 CEST Alexander Wuerstlein wrote: >> On 11-03-29 15:36, Dick Kniep wrote: > >> An authorized user running commands over ssh is not a security problem >> at all. It works as intended. ssh provides shells.

[X2go-dev] concept for X2go session lock-down to kiosk-mode (was Re: X2go is insecure)

2011-03-29 Thread Mike Gabriel
Hi all, On Di 29 Mär 2011 16:55:50 CEST Alexander Wuerstlein wrote: On 11-03-29 15:36, Dick Kniep wrote: An authorized user running commands over ssh is not a security problem at all. It works as intended. ssh provides shells. As Reinhard has mentioned in another post: Dicks setup requi