Morgan Lindqvist created QPID-7090:
--------------------------------------

             Summary: qpidd should not use root as user
                 Key: QPID-7090
                 URL: https://issues.apache.org/jira/browse/QPID-7090
             Project: Qpid
          Issue Type: Improvement
          Components: C++ Broker
    Affects Versions: qpid-cpp-0.34
         Environment: Debian/Ubuntu
            Reporter: Morgan Lindqvist
            Priority: Minor
             Fix For: qpid-cpp-next


When using the testing PPA on https://launchpad.net/~qpid to install qpidd the 
daemon is executed using the user id and group id "root".

The user id and group id that should be used is "qpidd".

This will significantly reduce the risk the the daemon can be used to get root 
access on the server.



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to