LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Red Hat
User Name
Password
Red Hat This forum is for the discussion of Red Hat Linux.

Notices


Reply
  Search this Thread
Old 09-04-2009, 12:18 AM   #1
haariseshu
Member
 
Registered: Jan 2008
Location: Noida, India
Distribution: RHEL
Posts: 81

Rep: Reputation: 15
Question How to deny root access to specific user's files


Hi Guys,

I'm running postfix server under RHEL-5 and users information are stored in the LDAP database.(openldap). Postfix fetching these users information from ldap using virtual relay.

And now I just want to know about restricting root user access to other user's mailbox.

As lot of confidential mails will flow across users I dont want to give root user with privilege to view users mailboxes.

Is it possible? If so how i can achieve this..??

Please help me with this...

Thanks a lot...
 
Old 09-04-2009, 12:54 AM   #2
lazlow
Senior Member
 
Registered: Jan 2006
Posts: 4,363

Rep: Reputation: 172Reputation: 172
Root is king. If the emails are that confidential you should probably be encrypting them.
 
Old 09-04-2009, 01:25 AM   #3
haariseshu
Member
 
Registered: Jan 2008
Location: Noida, India
Distribution: RHEL
Posts: 81

Original Poster
Rep: Reputation: 15
Hello,

Thank you for your response...

But is there any encryption supported in RedHat by default and will it prevent the root user from viewing user's mailbox??

I like to have file and directory level encryption since it is not possible to have device level at this stage (as its required to format with that encryption prog. i hope).
 
Old 09-04-2009, 01:34 AM   #4
lazlow
Senior Member
 
Registered: Jan 2006
Posts: 4,363

Rep: Reputation: 172Reputation: 172
The sender of the email would encrypt it before he sent the email.

Assuming you are using thunderbird there are addons for it to do just this. Enigmail seems to be fairly popular.
 
Old 09-04-2009, 01:42 AM   #5
JulianTosh
Member
 
Registered: Sep 2007
Location: Las Vegas, NV
Distribution: Fedora / CentOS
Posts: 674
Blog Entries: 3

Rep: Reputation: 90
I'm not aware of any filesystem properties that can keep root from poking around once something is decrypted/mounted. The only thing that comes to mind is possibly an SELinux rule that blocks root from accessing files of a certain context.
 
Old 09-04-2009, 01:46 AM   #6
JulianTosh
Member
 
Registered: Sep 2007
Location: Las Vegas, NV
Distribution: Fedora / CentOS
Posts: 674
Blog Entries: 3

Rep: Reputation: 90
Quote:
Originally Posted by lazlow View Post
Root is king. If the emails are that confidential you should probably be encrypting them.
No No.. Root supersedes kings. Root is god!

8^P
 
Old 09-04-2009, 02:39 AM   #7
fotoguy
Senior Member
 
Registered: Mar 2003
Location: Brisbane Queensland Australia
Distribution: Custom Debian Live ISO's
Posts: 1,291

Rep: Reputation: 62
I wouldn't just worry about root, anyone can intercept an email and read the contents. Also every mail server it travels through can make copies before forward it on. If the information is that confidential, you definitely need to use encryption of some type. If it's just attachments that need to be secured, you can use GnuPG to encrypt the attachment.
 
Old 09-04-2009, 05:53 AM   #8
haariseshu
Member
 
Registered: Jan 2008
Location: Noida, India
Distribution: RHEL
Posts: 81

Original Poster
Rep: Reputation: 15
Hello Guys,
Thank you for your responses...

Is their any way to do encryption from server side for all end user mails so that it sits in mailbox in encrypted format? So that it will not be human readable in the server location.
 
Old 09-04-2009, 07:36 AM   #9
lazlow
Senior Member
 
Registered: Jan 2006
Posts: 4,363

Rep: Reputation: 172Reputation: 172
No. Both ends of the email have to be involved with the encryption/decryption. If it were done just on the server then root(of that server) would have to be able to deal with it(root would be able to read it).
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
deny a user access to specific command krock923 Linux - Security 7 10-11-2012 03:04 PM
pure-ftpd - allow/deny specific ip addresses proNick Linux - Server 3 08-04-2009 12:32 PM
automount specific user's file on an NFS server cememet Linux - Networking 4 05-16-2007 08:45 PM
transferring user's files to root account newbiesforever Linux - General 7 08-19-2006 11:48 PM
Give root access to user's display + sudo problems Ephracis Linux - General 12 01-11-2006 11:25 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Red Hat

All times are GMT -5. The time now is 07:31 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration