The following are compound privileges:
•BASIC
Basic privileges available to all processes.
•BASICROOT
Privileges that provide powers usually associated with UID=0. These privileges together replace the power of root.
•POLICY
Policy override privileges and policy configuration privileges. Policy override privileges override compartment rules. Policy configuration privileges control the configuration of
For a complete list of the privileges in each of the sets described above, refer to privileges(5).
Security Implications of Fine-Grained Privileges
Privilege Escalation
In certain situations, if you grant a process a certain privilege or set of privileges, that process can gain additional privileges that were not explicitly granted to it. This is called privilege escalation. For example, a process with the PRIV_DACWRITE privilege can overwrite critical operating system files and, in the process, can grant itself additional
Fine-Grained Privileges in HP Serviceguard Clusters
To maintain proper Serviceguard operations when deploying
•Ensure root (UID=0) has full privileges in the INIT compartment.
•Ensure
Troubleshooting Fine-Grained Privileges
If something is not working on your system and you suspect the problem is occurring because of
Problem 1: Even though
•Is the file in question a script?
Any
•Has the file changed since the
When a file is modified, its
# setfilexsec -d filename
Security Implications of | 55 |