Re: [Vserver] CAP_SYS_ADMIN, how unsecure it is within vserver

2005-05-29 Thread Herbert Poetzl
On Sat, May 28, 2005 at 09:25:51PM +0200, Bodo Eggert wrote: On Sat, 28 May 2005, gary ng wrote: I am testing out vserver(1.2.10 on 2.4, not ready for 2.6 yet because of stability issue unrelated to vserver) and I am wondering what is the impact of giving CAP_SYS_ADMIN to it.

[Vserver] CAP_SYS_ADMIN, how unsecure it is within vserver

2005-05-28 Thread gary ng
Hi, I am testing out vserver(1.2.10 on 2.4, not ready for 2.6 yet because of stability issue unrelated to vserver) and I am wondering what is the impact of giving CAP_SYS_ADMIN to it. Without it, I cannot mount within vserver but I see mount as a legitimate use like mounting CIFS/NFS or FUSE

Re: [Vserver] CAP_SYS_ADMIN, how unsecure it is within vserver

2005-05-28 Thread Bodo Eggert
On Sat, 28 May 2005, gary ng wrote: I am testing out vserver(1.2.10 on 2.4, not ready for 2.6 yet because of stability issue unrelated to vserver) and I am wondering what is the impact of giving CAP_SYS_ADMIN to it. Without it, I cannot mount within vserver but I see mount as a legitimate

Re: [Vserver] CAP_SYS_ADMIN, how unsecure it is within vserver

2005-05-28 Thread gary ng
Thanks. The reason I said it is legitimate use is that I saw people offer vserver based VDS solutions. After a closer examine, I think vserver is more suitable for host service only jail rather than a full featured VDS(I had one before which use uml), so mainly for internal server