|
Bugzilla – Full Text Bug Listing |
| Summary: | Referencing a netgroup with multiple triplets from sudoHost and sudoUser | ||
|---|---|---|---|
| Product: | Sudo | Reporter: | Daniel Kopeček <dkopecek> |
| Component: | Sudoers | Assignee: | Todd C. Miller <Todd.Miller> |
| Status: | RESOLVED FIXED | ||
| Severity: | normal | CC: | daniele |
| Priority: | normal | ||
| Version: | 1.8.14 | ||
| Hardware: | PC | ||
| OS: | Linux | ||
| Attachments: | experimental patch | ||
|
Description
Daniel Kopeček
2015-09-04 02:48:29 MDT
Just found a similar question in the mailing list archive but without an answer: http://www.sudo.ws/pipermail/sudo-users/2010-March/004343.html The documentation references to the netgroups in sudoHost and sudoUser as "host netgroup" and "user netgroup". So, that should be read as a hint how sudo processes the netgroups, right? Yes, sudo has always only used either the host or user part of the netgroup but not both together. This is because historically sudo keyed everything on the user name. Hi, According to http://linux.die.net/man/5/netgroup, ( ,user, ) means all hosts and all domains. This is in contradiction to how sudo parse for netgroup. I personally think that this can be configured as a security bug, since netgroup with hosts and/or domain can be parsed anyway in sudoUser, and netgroups with users can be parsed anyway as sudoHost. Am i correct? Do you also think that this is a security bug? What do you think about it? Thanks, Daniele Sorry, I don't agree. The netgroup API allows the caller to specify which parts of the tuple are to be matched. This is something that could be documented better for sure. Hi Todd, do you see this issue as worth resolving as an RFE? i.e. introducing a new option to change the netgroup matching behavior? Yes, I think that makes the most sense. Perhaps something like a netgroup_tuple option. Just to give an update on this: I'm working on a patch for this issue, i.e. implementing the netgroup_tuple option. We are testing it currently and once I have a confirmation that it's working properly, I'll attach it here. Regards, Dan K. Created attachment 465 [details]
experimental patch
I've adapted this diff to sudo trunk: https://www.sudo.ws/repos/sudo/rev/9f694ba7c86d (In reply to Todd C Miller from comment #9) > I've adapted this diff to sudo trunk: > https://www.sudo.ws/repos/sudo/rev/9f694ba7c86d Great, thanks! Fixed in 1.8.16, available now. |