summaryrefslogtreecommitdiff
path: root/README.privsep
diff options
context:
space:
mode:
authorKevin Steves <stevesk@pobox.com>2002-06-24 16:49:22 +0000
committerKevin Steves <stevesk@pobox.com>2002-06-24 16:49:22 +0000
commitd48663602d55d324aa4c5964b9782a876de0ff5b (patch)
tree8c772f7ac5db03acada74e27ee1f8ff99f936941 /README.privsep
parent34f0d8f4040c3fe55e3a69aa92d18482077dd202 (diff)
- (stevesk) [README.privsep] minor updates
Diffstat (limited to 'README.privsep')
-rw-r--r--README.privsep6
1 files changed, 3 insertions, 3 deletions
diff --git a/README.privsep b/README.privsep
index 6c798f3a4..12b9cb2fc 100644
--- a/README.privsep
+++ b/README.privsep
@@ -12,7 +12,7 @@ On systems which lack mmap or anonymous (MAP_ANON) memory mapping,
12compression must be disabled in order for privilege separation to 12compression must be disabled in order for privilege separation to
13function. 13function.
14 14
15When privsep is enabled, the pre-authentication sshd process will 15When privsep is enabled, during the pre-authentication phase sshd will
16chroot(2) to "/var/empty" and change its privileges to the "sshd" user 16chroot(2) to "/var/empty" and change its privileges to the "sshd" user
17and its primary group. You should do something like the following to 17and its primary group. You should do something like the following to
18prepare the privsep preauth environment: 18prepare the privsep preauth environment:
@@ -21,7 +21,7 @@ prepare the privsep preauth environment:
21 # chown root:sys /var/empty 21 # chown root:sys /var/empty
22 # chmod 755 /var/empty 22 # chmod 755 /var/empty
23 # groupadd sshd 23 # groupadd sshd
24 # useradd -g sshd sshd 24 # useradd -g sshd -c 'sshd privsep' -d /var/empty sshd
25 25
26If you are on UnixWare 7 or OpenUNIX 8 do this additional step. 26If you are on UnixWare 7 or OpenUNIX 8 do this additional step.
27 # ln /usr/lib/.ns.so /usr/lib/ns.so.1 27 # ln /usr/lib/.ns.so /usr/lib/ns.so.1
@@ -57,4 +57,4 @@ process 1005 is the sshd process listening for new connections.
57process 6917 is the privileged monitor process, 6919 is the user owned 57process 6917 is the privileged monitor process, 6919 is the user owned
58sshd process and 6921 is the shell process. 58sshd process and 6921 is the shell process.
59 59
60$Id: README.privsep,v 1.7 2002/06/21 14:48:02 djm Exp $ 60$Id: README.privsep,v 1.8 2002/06/24 16:49:22 stevesk Exp $