summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorKevin Steves <stevesk@pobox.com>2002-06-24 16:49:22 +0000
committerKevin Steves <stevesk@pobox.com>2002-06-24 16:49:22 +0000
commitd48663602d55d324aa4c5964b9782a876de0ff5b (patch)
tree8c772f7ac5db03acada74e27ee1f8ff99f936941
parent34f0d8f4040c3fe55e3a69aa92d18482077dd202 (diff)
- (stevesk) [README.privsep] minor updates
-rw-r--r--ChangeLog3
-rw-r--r--README.privsep6
2 files changed, 5 insertions, 4 deletions
diff --git a/ChangeLog b/ChangeLog
index ec6e4726d..4efc11acd 100644
--- a/ChangeLog
+++ b/ChangeLog
@@ -1,5 +1,6 @@
120020625 120020625
2 - (stevesk) [INSTALL acconfig.h configure.ac defines.h] remove --with-rsh 2 - (stevesk) [INSTALL acconfig.h configure.ac defines.h] remove --with-rsh
3 - (stevesk) [README.privsep] minor updates
3 4
420020624 520020624
5 - OpenBSD CVS Sync 6 - OpenBSD CVS Sync
@@ -1085,4 +1086,4 @@
1085 - (stevesk) entropy.c: typo in debug message 1086 - (stevesk) entropy.c: typo in debug message
1086 - (djm) ssh-keygen -i needs seeded RNG; report from markus@ 1087 - (djm) ssh-keygen -i needs seeded RNG; report from markus@
1087 1088
1088$Id: ChangeLog,v 1.2265 2002/06/24 16:26:49 stevesk Exp $ 1089$Id: ChangeLog,v 1.2266 2002/06/24 16:49:22 stevesk Exp $
diff --git a/README.privsep b/README.privsep
index 6c798f3a4..12b9cb2fc 100644
--- a/README.privsep
+++ b/README.privsep
@@ -12,7 +12,7 @@ On systems which lack mmap or anonymous (MAP_ANON) memory mapping,
12compression must be disabled in order for privilege separation to 12compression must be disabled in order for privilege separation to
13function. 13function.
14 14
15When privsep is enabled, the pre-authentication sshd process will 15When privsep is enabled, during the pre-authentication phase sshd will
16chroot(2) to "/var/empty" and change its privileges to the "sshd" user 16chroot(2) to "/var/empty" and change its privileges to the "sshd" user
17and its primary group. You should do something like the following to 17and its primary group. You should do something like the following to
18prepare the privsep preauth environment: 18prepare the privsep preauth environment:
@@ -21,7 +21,7 @@ prepare the privsep preauth environment:
21 # chown root:sys /var/empty 21 # chown root:sys /var/empty
22 # chmod 755 /var/empty 22 # chmod 755 /var/empty
23 # groupadd sshd 23 # groupadd sshd
24 # useradd -g sshd sshd 24 # useradd -g sshd -c 'sshd privsep' -d /var/empty sshd
25 25
26If you are on UnixWare 7 or OpenUNIX 8 do this additional step. 26If you are on UnixWare 7 or OpenUNIX 8 do this additional step.
27 # ln /usr/lib/.ns.so /usr/lib/ns.so.1 27 # ln /usr/lib/.ns.so /usr/lib/ns.so.1
@@ -57,4 +57,4 @@ process 1005 is the sshd process listening for new connections.
57process 6917 is the privileged monitor process, 6919 is the user owned 57process 6917 is the privileged monitor process, 6919 is the user owned
58sshd process and 6921 is the shell process. 58sshd process and 6921 is the shell process.
59 59
60$Id: README.privsep,v 1.7 2002/06/21 14:48:02 djm Exp $ 60$Id: README.privsep,v 1.8 2002/06/24 16:49:22 stevesk Exp $