Subject: Re: operator shutdowns and su
To: Greg Troxel <gdt@ir.bbn.com>
From: Simon Burge <simonb@wasabisystems.com>
List: tech-userlevel
Date: 05/14/2006 01:12:11
Greg Troxel wrote:

>   Why does rc.subr try to change privileges to *_user during stop?
> 
> My immediate reaction is that when shutdown is invoked by
> user-in-group-operator the rc.d processing must run as root; they have
> to in order to do most things.  So perhaps su is getting confused
> between USER vs uid, or the framework isn't doing this quite right.

What sort of security concerns do we have here with users only in group
operator being able to run shell scripts as root?

Simon.
--
Simon Burge                            <simonb@wasabisystems.com>
NetBSD Support and Service:         http://www.wasabisystems.com/