The UNIX and Linux Forums  

Go Back   The UNIX and Linux Forums > Top Forums > UNIX for Dummies Questions & Answers
Google UNIX.COM


UNIX for Dummies Questions & Answers If you're not sure where to post a UNIX or Linux question, post it here. All UNIX and Linux newbies welcome !!

More UNIX and Linux Forum Topics You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
how to add permission of directory to a group ahjiefreak UNIX for Dummies Questions & Answers 2 02-29-2008 12:20 AM
permission, owner and group pascalbout Shell Programming and Scripting 2 01-14-2006 08:47 AM
group permission thumper UNIX for Dummies Questions & Answers 6 02-17-2005 01:03 PM
Group permission not working bbauerle AIX 13 05-10-2004 05:41 AM
how to define permission of unix group mncapara UNIX for Dummies Questions & Answers 3 10-16-2002 06:00 AM

Reply
 
Submit Tools LinkBack Thread Tools Search this Thread Display Modes
  #1  
Old 08-13-2008
Registered User
 

Join Date: Oct 2007
Posts: 93
Red face group & user permission question

Folks;
I'd like to create a group on my Linux box & add a few users to it.
Is there a way to do so and restrict this group/users to have access to only one or directory trees?
Let's say i need this group to only have a read write access to only these two directories /opt/Virtu & /fsn/comers

How can i do so?

Your help is very much appreciated
Reply With Quote
Forum Sponsor
  #2  
Old 08-13-2008
...@...
 

Join Date: Feb 2004
Location: NM
Posts: 4,298
One way is to chroot those users to some directory - /home/whatever - with links to those two directories plus /usr - or you can copy just the utilities you want them to have down into a local /usr directory.

This is what is done with FTP accounts for example, where they are only allowed to mess around in one directory tree.
Reply With Quote
  #3  
Old 08-13-2008
Registered User
 

Join Date: Oct 2007
Posts: 93
Thanks Jim
but i'm not sure if i fully understand your solution. any clarification?
Reply With Quote
  #4  
Old 08-13-2008
broli's Avatar
Registered User
 

Join Date: Dec 2007
Location: Argentina
Posts: 198
cerate a dir.
change the group to the group you created. make the proper mode changes (rwx)
is not hard. you just need to calm down, and , if it helps, lay down some concept schematics on a paper
Reply With Quote
  #5  
Old 08-13-2008
Registered User
 

Join Date: Oct 2007
Posts: 93
Thanks Broli;
I'm aware of the creating/changing directories process. I was asking about how to restrict this group/users to have access to only one or directory trees?
Let's say i need this group to only have a read write access to only these two directories /opt/Virtu & /fsn/comers

Katkota
Reply With Quote
  #6  
Old 08-13-2008
broli's Avatar
Registered User
 

Join Date: Dec 2007
Location: Argentina
Posts: 198
Quote:
Originally Posted by Katkota View Post
Thanks Broli;
I'm aware of the creating/changing directories process. I was asking about how to restrict this group/users to have access to only one or directory trees?
Let's say i need this group to only have a read write access to only these two directories /opt/Virtu & /fsn/comers

Katkota
suposing that /opt/Virtu has this permissions
-rwxrwxrwx root root
and you created the group virtu
chwon root:virtu /opt/Virtu
chmod 770
andmake the users youw ant, to be part of the virtu group

or maybe im not getting your question ...
Reply With Quote
  #7  
Old 08-13-2008
Registered User
 

Join Date: Aug 2008
Location: Portugal
Posts: 213
Be aware that the users will still be allowed on world writable directories (such as /tmp). Otherwise, you will got to stick with mcnamara's opinion on chroot(). Still, I must say chroot() is awfully easy to bypass without the proper kernel limitations (grsecurity).
Reply With Quote
Google The UNIX and Linux Forums
Reply

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes




All times are GMT -7. The time now is 09:16 PM.


Powered by: vBulletin, Copyright ©2000 - 2006, Jelsoft Enterprises Limited.
The UNIX and Linux Forums Content Copyright ©1993-2008. All Rights Reserved.Ad Management by RedTyger Visit The Complex Event Processing Blog

Content Relevant URLs by vBSEO 3.2.0