The UNIX and Linux Forums  
Hello and Welcome from United States to the UNIX and Linux Forums! Thank You for Visiting and Joining Our Global Community.

Go Back   The UNIX and Linux Forums > Operating Systems > Linux
.
google unix.com



Linux RedHat, Ubuntu, SUSE, Fedora, Debian, Mandriva, Slackware, Gentoo linux, PCLinuxOS. All Linux questions here!

More UNIX and Linux Forum Topics You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
Keeping old Private Messages era Post Here to Contact Site Administrators and Moderators 6 09-16-2008 02:24 AM
ssh public/private Keys richo king UNIX for Dummies Questions & Answers 2 03-13-2008 06:34 PM
Private network *Jess* IP Networking 10 11-23-2006 04:41 AM
Private Lessons john furman SUN Solaris 1 03-04-2005 09:55 AM
private network to private network gateway norsk hedensk IP Networking 2 12-05-2002 01:25 PM

Closed Thread
English Japanese Spanish French German Portuguese Italian Dutch Swedish Russian Norwegian Hungarian Hebrew Danish Bulgarian Greek Powered by Powered by Google
 
LinkBack Thread Tools Search this Thread Rating: Thread Rating: 1 votes, 4.00 average. Display Modes
  #1 (permalink)  
Old 10-27-2008
Giordano Bruno Giordano Bruno is offline
Registered User
  
 

Join Date: Oct 2008
Posts: 30
Angry Private directory

Hi there,

I'm working on a server with Fedora 6 and I can access root password. My problem is that even other people can ... and I'd like to have at least a private directory, but until now I couldn't find a clear answer...

So I'd like to know if it's possiple to restrict access to a directory even from the root or, if this is not allowed, which is the best way to know who access my file and when...

Thanks in advance for any suggestion!!!

GB
  #2 (permalink)  
Old 10-28-2008
otheus's Avatar
otheus otheus is offline Forum Staff  
Moderator ala Mode
  
 

Join Date: Feb 2007
Location: Innsbruck, Austria
Posts: 1,886
It's generally NOT possible to prevent root from seeing a local disk. You can, however, try to create a user-space filesystem which squashes root's access to it. I think cryptfs used to do this. The other possibility is using setfacl to achieve this effect. However, root can always call setfacl to remove whatever restrictions you add.

The long-term solution is to separate the root privilege into roles and have those roles separated through a judicious sudo configuration.
  #3 (permalink)  
Old 10-28-2008
Giordano Bruno Giordano Bruno is offline
Registered User
  
 

Join Date: Oct 2008
Posts: 30
Thank you very much!!! I'm going to look for setfacl and cryptfs on internet and try to solve the problem
  #4 (permalink)  
Old 10-31-2008
Giordano Bruno Giordano Bruno is offline
Registered User
  
 

Join Date: Oct 2008
Posts: 30
Hi,

I've just "discovered" that I have CRYPTSETUP installed on my server with FEDORA 6, but I couldn't find yet many information about it, while I'm getting many information about TRUECRYPT and its installation seems to be a little complicated on my linux version. Any opinion about that???Are these two tools reliable in the same way?

In particular I couldn't find any answer about this two questions (for both the toos):

1. If I'm logged on the linux box where the encrypted volume is and I've mounted it, then all logged users will see the volume as well???

2. Using remote access, will be possible to see my encrypted volume?

In any case I think I'm going to use CRYPTSETUP and trying to see how it works.
Thanks in advance for any suggestion!!!

Giordano Bruno
  #5 (permalink)  
Old 11-01-2008
otheus's Avatar
otheus otheus is offline Forum Staff  
Moderator ala Mode
  
 

Join Date: Feb 2007
Location: Innsbruck, Austria
Posts: 1,886
Giordano,

I looked at the CRYPTSETUP and LUKS for Linux and found it lacking your specific requirements. I was trying to find what I actually used a few years ago. I believe it was Matt Blaze's CFS, described here by Linux Journal (free subscription required) Using CFS, the Cryptographic Filesystem.

CFS does not guarantee that root cannot get access to the files. However, it can make it very difficult on hardenened systems where even root cannot access /proc/$$/mem. For more info, see the last paragraph on page 4 of Matt's paper.


Here are quite a few other possibilities:

http://www.usenix.org/events/usenix0...tml/index.html

I leave you with some other links that might be relevant:

Download TCFS 3.0b2 for Linux

I believe the risk here is that a root user, who exists on the host where your filesystem is mounted, can "su " to the user that has already entered

CryptFS, whose original authors describe their work here:

Cryptfs: A Stackable Vnode Level Encryption File System

And I think is downloadable here:

Download DM CryptFS 0.3.2 for Linux

Also note Download cryptmount 3.1 for Linux which contains the following description:
Quote:
After the initial configuration of the encrypted filesystem, an ordinary user can mount and unmount the filesystem on demand, solely by providing the decryption password.
  #6 (permalink)  
Old 11-23-2008
Giordano Bruno Giordano Bruno is offline
Registered User
  
 

Join Date: Oct 2008
Posts: 30
Thanks a lot for all your suggestion!!!

I couldn't find a "safe" solution to my problem and now I was wondering if using something like a virtual machine is a another way???

Giordano Bruno
Closed Thread

Bookmarks

Tags
linux download

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT -4. The time now is 12:10 PM.


Powered by: vBulletin, Copyright ©2000 - 2006, Jelsoft Enterprises Limited. Language Translations Powered by .
vBCredits v1.4 Copyright ©2007 - 2008, PixelFX Studios
The UNIX and Linux Forums Content Copyright ©1993-2009. All Rights Reserved.Ad Management by RedTyger

Content Relevant URLs by vBSEO 3.2.0