Re: [Vserver] secure a guest against the host's root-account

2006-04-24 Thread Sebastian Harl
Hi there, > Q: Is there a way to prevent that a superuser on the host system can Well, usually one characteristic of a superuser is the right to do _everything_. Even if you use something like SELinux or whatever, most superusers have physical access to their machines in one way or another. IMHO

Re: [Vserver] vserver features

2006-04-24 Thread Herbert Poetzl
On Mon, Apr 24, 2006 at 06:40:22PM +0200, Jonathan Dray wrote: > 2006/4/24, Herbert Poetzl <[EMAIL PROTECTED]>: > > > networking in Linux-VServer happens on the host to > > provide highest possible performance, which atm > > means that the iptable entries have to be set on > > the host too, this m

Re: [Vserver] vserver features

2006-04-24 Thread Jonathan Dray
2006/4/24, Herbert Poetzl <[EMAIL PROTECTED]>: networking in Linux-VServer happens on the host toprovide highest possible performance, which atmmeans that the iptable entries have to be set onthe host too, this might change in the future, butusually it doesn't pose any problem ... I've read someth

[Vserver] Re: how can I remove this in a Vserver : perl: warning: Falling back to the standard locale ("C")...

2006-04-24 Thread Nicolas Costes
Le Vendredi 21 Avril 2006 02:27, Tony Lewis a écrit : > > It should be solved by a little "apt-get install locales" > 1. apt-get install language-pack-en > 2. add the following to /etc/environment: > LANG="en_AU.UTF-8" > LANGUAGE="en_AU:en_US:en_GB:en" Same thing in Mandriva : When creatin

Re: [Vserver] great flower page

2006-04-24 Thread Herbert Poetzl
On Mon, Apr 24, 2006 at 04:11:37PM +0200, Guenther Fuchs wrote: > Hi there, > > on Monday, April 24, 2006 at 3:57:43 PM there was posted: > > >> e> - way of keeping heavily-commented template config for vserver. > >> e> There is no easy way to comment current config. > >> Agreed. > > HP> what

Re: [Vserver] secure a guest against the host's root-account

2006-04-24 Thread Herbert Poetzl
On Mon, Apr 24, 2006 at 08:02:43AM +0200, Oliver Welter wrote: > Hi Folks, > > this might be a strange question for some of you as it is more an > academical interesst, but I hope you can help me out ;) > > Q: Is there a way to prevent that a superuser on the host system can > > * see process o

Re: [Vserver] great flower page

2006-04-24 Thread Guenther Fuchs
Hi there, on Monday, April 24, 2006 at 3:57:43 PM there was posted: >> e> - way of keeping heavily-commented template config for vserver. >> e> There is no easy way to comment current config. >> Agreed. HP> what about writing option.info files? The documentation lacks this optional info yet ;

Re: [Vserver] What is the best method to clone a vserver from one host to another ?

2006-04-24 Thread Herbert Poetzl
On Sun, Apr 23, 2006 at 06:42:53PM +0200, Sébastien CRAMATTE wrote: > Hello > > What is the best method to clone a vserver from one host to another ? > I've tried to use vcopy script (http://www.micropp.se/vserver/). This > method works localy. rsync or dump/restore (when you use ext2/3) best,

Re: [Vserver] vserver features

2006-04-24 Thread Herbert Poetzl
On Sun, Apr 23, 2006 at 06:17:22PM +0200, Jonathan Dray wrote: > I've successfully installed Vserver on a debian etch with a 2.6.15 > patched kernel and started my first guest a few days ago. > I'm now looking for help/information about two features I acually > didn't find : > > - iptables supp

Re: [Vserver] great flower page

2006-04-24 Thread Herbert Poetzl
On Sun, Apr 23, 2006 at 10:28:05AM +0200, Guenther Fuchs wrote: > Hi there, > > on Sunday, April 23, 2006 at 9:57:06 AM there was posted: > > e> - ability to hot-add/hot-remove IPs from running guest > This is lost? AFAIK it is still possible, using the proper context. this is a feature which w

Re: [Vserver] secure a guest against the host's root-account

2006-04-24 Thread Oliver Welter
Hi Mike, Serge, So, is there any way to do this ? I guess that SELinux/GR will offer some pointers to forbid root these actions, but are there any "easier" ways ?? Sounds like SELinux is the tool of choice for that. And if your concern is with the host's admins, not with exploited root app

Re: [Vserver] secure a guest against the host's root-account

2006-04-24 Thread Serge E. Hallyn
Quoting Michael S. Zick ([EMAIL PROTECTED]): > On Mon April 24 2006 01:02, Oliver Welter wrote: > > Hi Folks, > > > > this might be a strange question for some of you as it is more an > > academical interesst, but I hope you can help me out ;) > > > > Q: Is there a way to prevent that a superuse

Re: [Vserver] secure a guest against the host's root-account

2006-04-24 Thread Michael S. Zick
On Mon April 24 2006 01:02, Oliver Welter wrote: > Hi Folks, > > this might be a strange question for some of you as it is more an > academical interesst, but I hope you can help me out ;) > > Q: Is there a way to prevent that a superuser on the host system can > > * see process of a guest > *