|
From: Roland P. <pa...@ta...> - 2004-04-27 20:19:54
|
On Tuesday 27 April 2004 21:39, Heiko Zuerker wrote: > > On Tuesday 27 April 2004 06:14, Tim Tait wrote: > > [...] > > [...] > > > > if you have several users on a system, the most dangerous part is > > rebooting. > > it's the only time a false config could be injected, but even worse: just > > pass init=/bin/bash and you have a root shell. So either: don't reboot, > > or: > > always attend your reboots and make sure the right config is loaded. > > If you want to disable command line passing, you have to change > > isolinux.cfg. > > When doing that, you can also add a "config=/dev/whatever" and if you > > protect > > that device properly, everything should be fine. > > You can NEVER protect a system when somebody has access to the hardware. > There are endless possibilities on how to gain access.... That's true, that "everything" was an overstatement... > > of course, make sure no one swaps CD's and boots a rescue system... > > so, IMHO, root ownership may be an additional security check, but it's > > inferior to gpg signing (but maybe we should make that part easier...) > > Suggestions on how we can make it easier? > At the moment you only put the public key on the CD and it's working. That's nothing we can change, unless you bring the public to the system every time you boot. Improvement's could be: - automatic key pair generation on custom build - use keys the user supplies (both via menuconfig) > I think the signing of the config is the most complicated part, since you > have to get the etc.tar.bz2, sign it and copy the signature to the config > media. the private key must be supplied by root somehow. If he (the admin) is personally present at the system, we could search for the gpg key on another medium (for example usb-stick...) If not, that's difficult...copying the archive around and signing without knowing how the admin wants to access it, no way... Roland -- ICQ UIN 49339118 Linux Counter #88774 GPG-Key 1024D/59C6AFA6 2003-02-07 Roland Pabel <ro...@pa...> |