LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-13-2018, 11:04 AM   #1
bali
LQ Newbie
 
Registered: Oct 2007
Posts: 11

Rep: Reputation: 0
sudo/pkexec versus sandboxes


What are the pros and cons of sudo/pkexec to a system user versus sandboxing such as with Firejail from a security standpoint?

Thank you
 
Old 09-14-2018, 08:32 AM   #2
pan64
LQ Addict
 
Registered: Mar 2012
Location: Hungary
Distribution: debian/ubuntu/suse ...
Posts: 21,801

Rep: Reputation: 7306Reputation: 7306Reputation: 7306Reputation: 7306Reputation: 7306Reputation: 7306Reputation: 7306Reputation: 7306Reputation: 7306Reputation: 7306Reputation: 7306
Is this your homework?
 
Old 09-15-2018, 06:59 PM   #3
bali
LQ Newbie
 
Registered: Oct 2007
Posts: 11

Original Poster
Rep: Reputation: 0
Why would this be relevant ?!?!
But no it is not homework.

For example, I am trying to isolate Jitsi.
In my view there is too much risk in letting it run without isolation.
I've been able to run Jitsi as a system user (using pkexec) but I've not been able to firejail Jitsi.
It just doesn't launch under different configurations.
Worse, there is nothing in the logs pointing to what the error would be.
I've already spent many hours trying to get this to work.
I don't like to end up on a failure, but at the same time I have better use of my time.

What will I lose if I don't pursue the Firejail route?
 
Old 09-16-2018, 01:05 AM   #4
ondoho
LQ Addict
 
Registered: Dec 2013
Posts: 19,872
Blog Entries: 12

Rep: Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053
Quote:
Originally Posted by bali View Post
I've been able to run Jitsi as a system user
what?
you mean as root/sudo?
that can't be right.
 
Old 09-16-2018, 01:11 AM   #5
Turbocapitalist
LQ Guru
 
Registered: Apr 2005
Distribution: Linux Mint, Devuan, OpenBSD
Posts: 7,294
Blog Entries: 3

Rep: Reputation: 3719Reputation: 3719Reputation: 3719Reputation: 3719Reputation: 3719Reputation: 3719Reputation: 3719Reputation: 3719Reputation: 3719Reputation: 3719Reputation: 3719
Quote:
Originally Posted by bali View Post
For example, I am trying to isolate Jitsi.
You could use apparmor for that. However it lacks the ability to isloate network traffic so if you used sudo to run it under a different unprivileged user and group then you could supplement it with iptables.

Last edited by Turbocapitalist; 09-16-2018 at 02:55 AM. Reason: closed tag
 
Old 09-16-2018, 04:02 AM   #6
pan64
LQ Addict
 
Registered: Mar 2012
Location: Hungary
Distribution: debian/ubuntu/suse ...
Posts: 21,801

Rep: Reputation: 7306Reputation: 7306Reputation: 7306Reputation: 7306Reputation: 7306Reputation: 7306Reputation: 7306Reputation: 7306Reputation: 7306Reputation: 7306Reputation: 7306
probably you can try this: https://github.com/robertoandrade/docker-jitsi-meet - if I understand well.
 
Old 09-17-2018, 10:45 AM   #7
bali
LQ Newbie
 
Registered: Oct 2007
Posts: 11

Original Poster
Rep: Reputation: 0
Thank you turbocapitalist

That's what I've done:

useradd --system -s /usr/sbin/nologin -d /home/jitsi jitsi

pkexec -u jitsi env DISPLAY=$DISPLAY XAUTHORITY=$XAUTHORITY /usr/bin/jitsi %u

I've adjusted iptables for the user jitsi

This works except for the warning:
"could not determine how to handle %u"

But my original question remains unanswered:
How "firejail jitsi" (if this worked) differ from what I have above?
Also why would running apparmor+sudo be better than what I have above?
Would this produce better security? If yes, why?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Mutliple wheel users and pkexec authentication upnort Linux - Security 2 12-22-2014 01:12 PM
LXer: Linux-based Qubes OS sandboxes VMs for added security LXer Syndicated Linux News 0 09-11-2012 05:00 PM
How to limit a compile-run-respond cycle? (pretty much like ideone/web sandboxes) alfa64 Programming 1 02-18-2012 04:54 AM
Crontab for pkexec as root spyzer.abhishek0 Linux - Newbie 3 07-25-2011 05:53 PM
Jails/Sandboxes/Operating system-level virtualization Mellar Slackware 4 04-03-2008 11:27 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 02:11 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration