[grsec] Two minor issues

John Logsdon j.logsdon at quantex-research.com
Fri Aug 19 07:25:49 EDT 2005


Two small requests:

1 When sysctl is invoked would it be possible not only to initialise those
where config=y and set /proc/sys/kernel/grsecurity/whatever to 1 but also
those not set to 0? 

Echoing 0 into a non-existent 'file' doesn't work.  Otherwise you need to
set all sysctl configs and switch what you don't want off.

2 In gradm, it appears when using domains that you can only have the user
or group role flag.  If you add, for example, the G flag to a domain to
authenticate the kernel, the message says it cannot find user G. 

ie

domain alladmins uG admin1 admin2 

will return that it can't find user G.

Usually of course you add the G to root or default but it may be that
there are a few admin users that are identical and we may want to be able
to authenticate directly.

John

John Logsdon                               "Try to make things as simple
Quantex Research Ltd, Manchester UK         as possible but not simpler"
j.logsdon at quantex-research.com              a.einstein at relativity.org
+44(0)161 445 4951/G:+44(0)7717758675       www.quantex-research.com




More information about the grsecurity mailing list