Subject: Re: su(1) asking for pw if euid==0
To: None <tech-userlevel@NetBSD.org>
From: Bill Stouder-Studenmund <wrstuden@netbsd.org>
List: tech-userlevel
Date: 07/13/2007 12:36:04
--V0207lvV8h4k8FAm
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Wed, Jul 11, 2007 at 09:11:35AM +0200, Peter Bex wrote:
> On Wed, Jul 11, 2007 at 02:07:34AM +0000, Christos Zoulas wrote:
> > >So, what should be fixed? su(1), rc(8) or my understanding of them?
> >=20
> > Make the setuid program set the real id to 0 before exec'ing su.
>=20
> Yes, please do this!  I've also had problems with database/postgresql from
> pkgsrc.  It also tries to use su to stop a daemon, which prompts for
> a password if you run shutdown as normal user.

database/postgresql is why I started a thread about this a while ago which=
=20
resulted in the fixed version of shutdown. :-)

Take care,

Bill

--V0207lvV8h4k8FAm
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.7 (NetBSD)

iD8DBQFGl9QkWz+3JHUci9cRAn8tAJ4yKyIHZM11I4HofLj2sKUNYLZOuwCfdAms
TXy4IbsDUtb3LEYUDXGio6o=
=4aXa
-----END PGP SIGNATURE-----

--V0207lvV8h4k8FAm--