LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 03-12-2014, 03:19 PM   #1
ZAMO
Member
 
Registered: Mar 2007
Distribution: Redhat &CentOS
Posts: 598

Rep: Reputation: 30
User settings or sudo


The user zamo is a member of the secondary group admin .
The files and directories under /var/dir1/* are owned by admin:admin .

Since user zamo is a member of the admin , he can allow to rwx to the files and directories beneath /var/dir1/* .

I cannot turn on acl here . .What will be the best way to give zamo with read-only access to /var/dir1/* ? Is there a way to do that in sudo ?
 
Old 03-12-2014, 04:26 PM   #2
notKlaatu
Senior Member
 
Registered: Sep 2010
Location: Lawrence, New Zealand
Distribution: Slackware
Posts: 1,077

Rep: Reputation: 732Reputation: 732Reputation: 732Reputation: 732Reputation: 732Reputation: 732Reputation: 732
I believe your options are:

1. remove zamo from admin group
2. create a new group that owns /var/dir1 and exclude zamo from that group


I cannot think of any way to use `sudo` to restrict zamo from writing to a directory. The purpose of `sudo` is to, as its man page says "execute a command as another user" so I don't think that will help you.


I've had to do some file permission things like this, and what I ended up doing was using a LOT of groups. Like 15 groups, sometimes one group just for one directory. It worked out pretty well, actually.
 
Old 03-12-2014, 04:41 PM   #3
pingu
Senior Member
 
Registered: Jul 2004
Location: Skuttunge SWEDEN
Distribution: Debian preferably
Posts: 1,350

Rep: Reputation: 127Reputation: 127
No, sudo can't withdraw file permissions. Sudo only grants permission to do things.
But you can change the permissions for group admin, so zamo only has read access.
If you can't do that you'll either have to remove zamo from group admin, or change group on /var/dir1/*
 
Old 03-13-2014, 06:59 AM   #4
ZAMO
Member
 
Registered: Mar 2007
Distribution: Redhat &CentOS
Posts: 598

Original Poster
Rep: Reputation: 30
Thanks , I want to make sure am on the right page .
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Question about the sudo command, specifically how to have sudo act as if user is root slacker_ Linux - Newbie 17 09-22-2013 03:48 PM
startx from root user is working while from sudo user not unkn(0)wn Linux - Newbie 2 08-17-2012 09:31 PM
[SOLVED] "sudo: Can't mkdir /var/run/sudo/%user%: File exists" CNBarnes Linux - Server 7 01-10-2011 04:11 PM
unchecked link between pc user and sudo user on Mint5 how do I get it back,stop laugh Fred Caro Linux - Newbie 2 04-22-2009 08:36 PM
Gconf-editor settings not sticking for root, sudo user, or user when run sandaili Fedora 1 07-19-2008 08:31 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:07 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration