<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Linux security in Operating System - Linux</title>
    <link>https://community.hpe.com/t5/operating-system-linux/linux-security/m-p/4255127#M33508</link>
    <description>Hi All,&lt;BR /&gt;&lt;BR /&gt;How can we restrict a user when he access a linux machine can't go to any folder other than the one that he access to it upon login, also restrict him to use just specific commands and can't use anything else.&lt;BR /&gt;&lt;BR /&gt;Appreciate any help here.&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;</description>
    <pubDate>Wed, 20 Aug 2008 12:53:26 GMT</pubDate>
    <dc:creator>M.S</dc:creator>
    <dc:date>2008-08-20T12:53:26Z</dc:date>
    <item>
      <title>Linux security</title>
      <link>https://community.hpe.com/t5/operating-system-linux/linux-security/m-p/4255127#M33508</link>
      <description>Hi All,&lt;BR /&gt;&lt;BR /&gt;How can we restrict a user when he access a linux machine can't go to any folder other than the one that he access to it upon login, also restrict him to use just specific commands and can't use anything else.&lt;BR /&gt;&lt;BR /&gt;Appreciate any help here.&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;</description>
      <pubDate>Wed, 20 Aug 2008 12:53:26 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/linux-security/m-p/4255127#M33508</guid>
      <dc:creator>M.S</dc:creator>
      <dc:date>2008-08-20T12:53:26Z</dc:date>
    </item>
    <item>
      <title>Re: Linux security</title>
      <link>https://community.hpe.com/t5/operating-system-linux/linux-security/m-p/4255128#M33509</link>
      <description>Use restricted shell - &lt;A href="http://felipecruz.com/blog_restricte-linux-users-to-their-home.php" target="_blank"&gt;http://felipecruz.com/blog_restricte-linux-users-to-their-home.php&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;regards,&lt;BR /&gt;ivan</description>
      <pubDate>Wed, 20 Aug 2008 13:00:22 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/linux-security/m-p/4255128#M33509</guid>
      <dc:creator>Ivan Krastev</dc:creator>
      <dc:date>2008-08-20T13:00:22Z</dc:date>
    </item>
    <item>
      <title>Re: Linux security</title>
      <link>https://community.hpe.com/t5/operating-system-linux/linux-security/m-p/4255129#M33510</link>
      <description>Hi Ivan,&lt;BR /&gt;&lt;BR /&gt;I'm using rhel5, and i can't find bash2 package. Is it still in use.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;</description>
      <pubDate>Wed, 20 Aug 2008 13:32:42 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/linux-security/m-p/4255129#M33510</guid>
      <dc:creator>M.S</dc:creator>
      <dc:date>2008-08-20T13:32:42Z</dc:date>
    </item>
    <item>
      <title>Re: Linux security</title>
      <link>https://community.hpe.com/t5/operating-system-linux/linux-security/m-p/4255130#M33511</link>
      <description>See RH document - just copy bash to rbash - &lt;A href="http://kbase.redhat.com/faq/FAQ_35_3940.shtm" target="_blank"&gt;http://kbase.redhat.com/faq/FAQ_35_3940.shtm&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;regards,&lt;BR /&gt;ivan</description>
      <pubDate>Wed, 20 Aug 2008 13:35:32 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/linux-security/m-p/4255130#M33511</guid>
      <dc:creator>Ivan Krastev</dc:creator>
      <dc:date>2008-08-20T13:35:32Z</dc:date>
    </item>
    <item>
      <title>Re: Linux security</title>
      <link>https://community.hpe.com/t5/operating-system-linux/linux-security/m-p/4255131#M33512</link>
      <description>Hi Ivan,&lt;BR /&gt;&lt;BR /&gt;Thx for your help here, i still have an issue where i want to restrict this to use just specific command. Like just use ping and traceroute and nothing else at all (he can't create read write and do anything other than the predifined commands)&lt;BR /&gt;&lt;BR /&gt;Is there a way to do that &lt;BR /&gt;&lt;BR /&gt;Thx &lt;BR /&gt;</description>
      <pubDate>Wed, 20 Aug 2008 13:45:36 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/linux-security/m-p/4255131#M33512</guid>
      <dc:creator>M.S</dc:creator>
      <dc:date>2008-08-20T13:45:36Z</dc:date>
    </item>
    <item>
      <title>Re: Linux security</title>
      <link>https://community.hpe.com/t5/operating-system-linux/linux-security/m-p/4255132#M33513</link>
      <description>Shalom,&lt;BR /&gt;&lt;BR /&gt;Try chroot&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.howtoforge.com/chrooted_ssh_howto_debian" target="_blank"&gt;http://www.howtoforge.com/chrooted_ssh_howto_debian&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Number of good solutions.&lt;BR /&gt;&lt;BR /&gt;Not easy but air tight secure.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Wed, 20 Aug 2008 21:26:26 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/linux-security/m-p/4255132#M33513</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2008-08-20T21:26:26Z</dc:date>
    </item>
    <item>
      <title>Re: Linux security</title>
      <link>https://community.hpe.com/t5/operating-system-linux/linux-security/m-p/4255133#M33514</link>
      <description>What about modifying you system to serve the purpose.&lt;BR /&gt;&lt;BR /&gt;Create two new groups&lt;BR /&gt;1) restricted&lt;BR /&gt;2) free&lt;BR /&gt;&lt;BR /&gt;restricted:  to which all the user whom you want to restrict will belong.&lt;BR /&gt;&lt;BR /&gt;free: all the free and happy users will belong&lt;BR /&gt;&lt;BR /&gt;then create a directory say /rec_bin(or whatever u want to call it) and copy all the commands(to be used by restricted users) from /usr/bin /bin to this directory. make this directory readable and executable by restricted group.&lt;BR /&gt;&lt;BR /&gt;Change the permission of /bin /usr/bin /sbin etc etc. to disallow anybody except the owner and the free group.&lt;BR /&gt;&lt;BR /&gt;In this way the restricted users wont' be able to access all the commands on the system but they will be able to run the commands kept in /rec_bin&lt;BR /&gt;&lt;BR /&gt;Sri</description>
      <pubDate>Thu, 21 Aug 2008 05:27:02 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/linux-security/m-p/4255133#M33514</guid>
      <dc:creator>Srimalik</dc:creator>
      <dc:date>2008-08-21T05:27:02Z</dc:date>
    </item>
    <item>
      <title>Re: Linux security</title>
      <link>https://community.hpe.com/t5/operating-system-linux/linux-security/m-p/4255134#M33515</link>
      <description>Ivan, &lt;BR /&gt;Try to run bash from the "rbash" environment. On centos5, users that are logged into rbash are able to switch to bash (where "cd" is not restricted) simply by typing "bash".&lt;BR /&gt;I'm not sure whether it was designed that way on purpose...</description>
      <pubDate>Thu, 21 Aug 2008 06:47:46 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/linux-security/m-p/4255134#M33515</guid>
      <dc:creator>Alexander Chuzhoy</dc:creator>
      <dc:date>2008-08-21T06:47:46Z</dc:date>
    </item>
    <item>
      <title>Re: Linux security</title>
      <link>https://community.hpe.com/t5/operating-system-linux/linux-security/m-p/4255135#M33516</link>
      <description>Just changing the shell to rbash isn't sufficient because you need to control what's in $PATH. At a minimum, you need:&lt;BR /&gt;&lt;BR /&gt;1. restricted shell (like rbash)&lt;BR /&gt;2. directory with symlinks to permitted commands&lt;BR /&gt;3. read-only custom login script to set PATH to only contain that directory of symlinks&lt;BR /&gt;4. read-only home directory&lt;BR /&gt;</description>
      <pubDate>Thu, 21 Aug 2008 15:14:46 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/linux-security/m-p/4255135#M33516</guid>
      <dc:creator>Heironimus</dc:creator>
      <dc:date>2008-08-21T15:14:46Z</dc:date>
    </item>
  </channel>
</rss>

