|
From: Jeff D. <jd...@ka...> - 2000-10-07 22:23:28
|
epa...@up... said: > Many sysadmins (myself included) get very nervous when users ask for a > suid helper. There's another possibility. The eth daemon can be made to communicate with its peers on other boxes (which is a good idea in its own right), and you could set up a virtual network that has non-privileged daemons, except for one running as root on a machine that no one cares about. That one would be the gateway to the outside world for all the others. I think that most sysadmins would have no trouble finding an old box that could be dedicated as the UML gateway. If it got rooted through the eth daemon, that doesn't pose any danger to anything else. Jeff |