OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: [suse-security] Deny access to file for all applications with apparmor?

From: Carlos E. R. (robin.listastelefonica.net)
Date: Sat Sep 30 2006 - 18:30:08 CDT


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

The Saturday 2006-09-30 at 11:44 +0300, Boyan Tabakov wrote:

> Or, what I really want to accomplish, how can I deny
> access to specific file for ALL processes, except, let's say one or two?
> If I understand the concept right, this can't be done, but let me know if I am
> wrong, please!

The file could belong to a certain user, and only he could open it. The
processes in question could be run by that user (or be suid to that user).
Perhaps a better alternative would be acl.M S6

- --
Cheers,
       Carlos E. R.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2 (GNU/Linux)
Comment: Made with pgp4pine 1.76

iD8DBQFFHv4HtTMYHG2NR9URAsD0AJ9gKO5nSOxbA4iEMBGaCrzlEw4vXwCfaFxT
TFpDa94R7T6Cv1FusJYXQYU=
=imXE
-----END PGP SIGNATURE-----

--
Check the headers for your unsubscription address
For additional commands, e-mail: suse-security-helpsuse.com
Security-related bug reports go to securitysuse.de, not here