summary: root-done file has o:w permission

From: anthony.miller@vf.vodafone.co.uk
Date: Thu Nov 09 2000 - 06:27:32 CST


All...

Re my earlier mail, I also logged this with SUN support. I should have said
that we were running VxVm V3.0.4. Apparently this is a known issue and is
fixed in VxVm V3.1. The SUN bug ID is 4244390. The advice is to do the
following:

Set /etc/vx/reconfig.d/state.d/root-done to rw/r/r
permission.
Set /etc/vx/reconfig.d/saveconf.d to rw/r/r
permission.
Set /etc/vx/reconfig.d/saveconf.d/etc to rw/r/r permission.

Many thanks to:
Merrell, Vince [IT] [vince.merrell@ssmb.com]

Who replied in the affirmative to change the original permission as I
indicated.

Thanks - Tony

=======================Original Posting=====================================
All...

I am checking through the audit report from a security analysis tool our
security team use. This has suggested removing write permission from group
'other' on the file /etc/vx/reconfig.d/saveconf.d/root-done

Is anybody aware of the implications of doing this? The only reference to
this file I can find is in:
http://www.dataman.nl/showsunman.lp?i=520995&s=ec86dc88859ebaf0faee0e7d7849a
3fe

A summary from From: nospam@warp.dats.ml.com (Vahid Moghaddasi) on 4/may/99
which suggests this needs to be removed as part of the deconfiguration of
VxVm.

Anybody any ideas please? I'm running Solaris 2.6 but a similarly
configured Solaris 2.7 node has this file with the same protection mask.

Thanks - Tony

Quotation: "Is the glass half full or half empty?? ...
               Well, drink it anyhow, that's what I say".
  Pete Goss.

Quotation: "God gave men two ears but only one tongue. Think
               about something and chew it to death before you
               spit it out as abuse, for the greatest remedy to
               anger is delay.".
  Charlie Burton.

+-----------------------------------------------------------------+
| TONY MILLER - Systems Projects - VODAFONE LTD, Derby House, |
| Newbury Business Park, Newbury, Berkshire. |
+-------------+---------------------------------------------------+
| Phone | 01635-677687(local) |
| Work email | ANTHONY.MILLER@VF.VODAFONE.CO.UK |
| FAX | 01635-233517 |
+-------------+---------------------------------------------------+

Disclaimer: Opinions expressed in this mail are my own and do not
reflect the company view unless explicitly stated. The information
is provided on an 'as is' basis and no responsibility is accepted for
any system damage howsoever caused.

S
U BEFORE POSTING please READ the FAQ located at
N ftp://ftp.cs.toronto.edu/pub/jdd/sun-managers/faq
. and the list POLICY statement located at
M ftp://ftp.cs.toronto.edu/pub/jdd/sun-managers/policy
A To submit questions/summaries to this list send your email message to:
N sun-managers@sunmanagers.ececs.uc.edu
A To unsubscribe from this list please send an email message to:
G majordomo@sunmanagers.ececs.uc.edu
E and in the BODY type:
R unsubscribe sun-managers
S Or
. unsubscribe sun-managers original@subscription.address
L To view an archive of this list please visit:
I http://www.latech.edu/sunman.html
S
T



This archive was generated by hypermail 2.1.2 : Fri Sep 28 2001 - 23:14:21 CDT