|
From: Zsiros Z. <zs...@ma...> - 2005-02-02 15:18:46
|
Hi, I'm trying to create an NTPD jail config, but the included ntpd in DL 1.2.2 doesn't support chrooting. Does anybody know where can I find a more-or-less (preferably more :-) official chroot patch for ntpd-4.2.0? I tried to search it on google, but it was unsuccessfull... What patch source can accept the main development team? Zsolt |
|
From: Heiko Z. <he...@zu...> - 2005-02-02 18:07:07
|
Hey, > I'm trying to create an NTPD jail config, but the included ntpd in DL > 1.2.2 doesn't support chrooting. > Does anybody know where can I find a more-or-less (preferably more :-) > official chroot patch for ntpd-4.2.0? > > I tried to search it on google, but it was unsuccessfull... > What patch source can accept the main development team? For cases like this we have the 'compartment' tool included, which takes care of chroot, setting capabilities and stuff like that. Take a look at what I did for Lotus Notes. Take a look at those files: /etc/sysconfig/jail/DOMINO /etc/init.d/domino The jail script itself will take care of all the needed shared libraries (as long as the binaries tells us which ones it needs). Otherwise you can always add the missing ones to the jail config. -- Regards Heiko Zuerker http://www.devil-linux.org |
|
From: Zsiros Z. <zs...@ma...> - 2005-02-03 09:10:39
|
2005-02-02, sze keltezéssel 19:06-kor Heiko Zuerker ezt írta:
> Hey,
>
> > I'm trying to create an NTPD jail config, but the included ntpd in DL
> > 1.2.2 doesn't support chrooting.
> > Does anybody know where can I find a more-or-less (preferably more :-)
> > official chroot patch for ntpd-4.2.0?
> >
> > I tried to search it on google, but it was unsuccessfull...
> > What patch source can accept the main development team?
>
> For cases like this we have the 'compartment' tool included, which takes
> care of chroot, setting capabilities and stuff like that.
> Take a look at what I did for Lotus Notes. Take a look at those files:
> /etc/sysconfig/jail/DOMINO
> /etc/init.d/domino
I found this utility and I'm using it for Postfix but the compiled ntpd
binary in DL does not support chrooting. The ntpd in DL produces the
following "help":
root@devil:~ # ntpd -h
ntpd: unknown option -h
usage: ntpd [ -abdgmnqx ] [ -c config_file ] [ -e e_delay ]
[ -f freq_file ] [ -k key_file ] [ -l log_file ]
[ -p pid_file ] [ -r broad_delay ] [ -s statdir ]
[ -t trust_key ] [ -v sys_var ] [ -V default_sysvar ]
[ -P fixed_process_priority ]
But in my old RH9:
[root@ubul ~]# ntpd -h
ntpd: unknown option -h
usage: ntpd [ -abdgmnqx ] [ -c config_file ] [ -e e_delay ]
[ -f freq_file ] [ -k key_file ] [ -l log_file ]
[ -p pid_file ] [ -r broad_delay ] [ -s statdir ]
[ -t trust_key ] [ -v sys_var ] [ -V default_sysvar ]
[ -T chroot_dir ] [ -U server_user ]
[ -P fixed_process_priority ]
There is the -T to chroot ntpd and -U option to drop root privileges
after starting.
On next link I found that the 4.2.0 version does not support chrooting:
http://lists.ntp.isc.org/pipermail/questions/2004-February/003323.html
I'm a bit confused because I'm not sure about this chroot patch, is it
required to use ntp with compartment?
Zsolt
|
|
From: Heiko Z. <he...@zu...> - 2005-02-04 00:49:32
|
Zsiros Zsolt wrote: >2005-02-02, sze keltezéssel 19:06-kor Heiko Zuerker ezt írta: > > >>Hey, >> >> >> >>>I'm trying to create an NTPD jail config, but the included ntpd in DL >>>1.2.2 doesn't support chrooting. >>>Does anybody know where can I find a more-or-less (preferably more :-) >>>official chroot patch for ntpd-4.2.0? >>> >>>I tried to search it on google, but it was unsuccessfull... >>>What patch source can accept the main development team? >>> >>> >>For cases like this we have the 'compartment' tool included, which takes >>care of chroot, setting capabilities and stuff like that. >>Take a look at what I did for Lotus Notes. Take a look at those files: >>/etc/sysconfig/jail/DOMINO >>/etc/init.d/domino >> >> > >I found this utility and I'm using it for Postfix but the compiled ntpd >binary in DL does not support chrooting. The ntpd in DL produces the >following "help": > >root@devil:~ # ntpd -h >ntpd: unknown option -h >usage: ntpd [ -abdgmnqx ] [ -c config_file ] [ -e e_delay ] > [ -f freq_file ] [ -k key_file ] [ -l log_file ] > [ -p pid_file ] [ -r broad_delay ] [ -s statdir ] > [ -t trust_key ] [ -v sys_var ] [ -V default_sysvar ] > [ -P fixed_process_priority ] > >But in my old RH9: > >[root@ubul ~]# ntpd -h >ntpd: unknown option -h >usage: ntpd [ -abdgmnqx ] [ -c config_file ] [ -e e_delay ] > [ -f freq_file ] [ -k key_file ] [ -l log_file ] > [ -p pid_file ] [ -r broad_delay ] [ -s statdir ] > [ -t trust_key ] [ -v sys_var ] [ -V default_sysvar ] > [ -T chroot_dir ] [ -U server_user ] > [ -P fixed_process_priority ] > >There is the -T to chroot ntpd and -U option to drop root privileges >after starting. > >On next link I found that the 4.2.0 version does not support chrooting: >http://lists.ntp.isc.org/pipermail/questions/2004-February/003323.html > >I'm a bit confused because I'm not sure about this chroot patch, is it >required to use ntp with compartment? > > Compartment is for daemons which do not support chrooting per default. It basically takes care of chrooting and dropping the priviliges. In addition you need to use the jail script and a config file with it (see my domino example), so all the necessary libraries, files and config files are available within the chroot jail. -- Regards Heiko Zuerker http://www.devil-linux.org |