set user id for service ?

Thiago Macieira thiago at kde.org
Thu Sep 14 13:40:57 PDT 2006


frederic heem wrote:
>Unfortunately, making the program setuid is considered insecure.
>Another solution is to use sudo to restrict who can start the service,
> i.e the messagebus

Put the setuid-user program or wrapper in an 0500 messagebus-owned 
directory.

But if anyone can start the program (via D-Bus), what's the harm in 
letting anyone start the program directly?

-- 
  Thiago Macieira  -  thiago (AT) macieira.info - thiago (AT) kde.org
    PGP/GPG: 0x6EF45358; fingerprint:
    E067 918B B660 DBD1 105C  966C 33F5 F005 6EF4 5358
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: not available
Url : http://lists.freedesktop.org/archives/dbus/attachments/20060914/115e6af4/attachment.pgp


More information about the dbus mailing list