<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="FeedCreator 1.8" -->
<?xml-stylesheet href="https://www.rsbac.org/lib/exe/css.php?s=feed" type="text/css"?>
<rdf:RDF
    xmlns="http://purl.org/rss/1.0/"
    xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
    xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
    xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel rdf:about="https://www.rsbac.org/feed.php">
        <title>RSBAC: Extending Linux Security Beyond the Limits wiki:experiences:igraltist</title>
        <description></description>
        <link>https://www.rsbac.org/</link>
        <image rdf:resource="https://www.rsbac.org/lib/tpl/rsbac/images/favicon.ico" />
       <dc:date>2026-04-30T15:24:35+00:00</dc:date>
        <items>
            <rdf:Seq>
                <rdf:li rdf:resource="https://www.rsbac.org/wiki/experiences/igraltist/acl-su?rev=1342900723&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.rsbac.org/wiki/experiences/igraltist/acl?rev=1342900513&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.rsbac.org/wiki/experiences/igraltist/admins?rev=1380782586&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.rsbac.org/wiki/experiences/igraltist/booting?rev=1345299240&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.rsbac.org/wiki/experiences/igraltist/examples?rev=1342900975&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.rsbac.org/wiki/experiences/igraltist/installation?rev=1345288458&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.rsbac.org/wiki/experiences/igraltist/introduction?rev=1345286530&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.rsbac.org/wiki/experiences/igraltist/jail_apache2?rev=1216003146&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.rsbac.org/wiki/experiences/igraltist/jail_apcupsd?rev=1309407204&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.rsbac.org/wiki/experiences/igraltist/jail_cron?rev=1215837316&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.rsbac.org/wiki/experiences/igraltist/jail_cups?rev=1215995319&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.rsbac.org/wiki/experiences/igraltist/jail_dbus?rev=1231730740&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.rsbac.org/wiki/experiences/igraltist/jail_ddclient?rev=1309410089&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.rsbac.org/wiki/experiences/igraltist/jail_dhcpd?rev=1309409914&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.rsbac.org/wiki/experiences/igraltist/jail_dmeventd?rev=1216004172&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.rsbac.org/wiki/experiences/igraltist/jail_flags?rev=1215810070&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.rsbac.org/wiki/experiences/igraltist/jail_ntpd?rev=1309408123&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.rsbac.org/wiki/experiences/igraltist/jail_pdnsd?rev=1309408300&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.rsbac.org/wiki/experiences/igraltist/jail_ping?rev=1216017270&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.rsbac.org/wiki/experiences/igraltist/jail_portmap?rev=1231730356&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.rsbac.org/wiki/experiences/igraltist/jail_postfix?rev=1309409718&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.rsbac.org/wiki/experiences/igraltist/jail_powernowd?rev=1216003949&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.rsbac.org/wiki/experiences/igraltist/jail_rklogd?rev=1309410181&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.rsbac.org/wiki/experiences/igraltist/jail_rsync?rev=1216017569&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.rsbac.org/wiki/experiences/igraltist/jail_samba?rev=1215995068&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.rsbac.org/wiki/experiences/igraltist/jail_shorewall?rev=1216002962&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.rsbac.org/wiki/experiences/igraltist/jail_squid?rev=1216005185&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.rsbac.org/wiki/experiences/igraltist/jail_syslog-ng?rev=1309416617&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.rsbac.org/wiki/experiences/igraltist/jail_syslogd?rev=1215997853&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.rsbac.org/wiki/experiences/igraltist/jail_vixie-cron?rev=1216002816&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.rsbac.org/wiki/experiences/igraltist/jail_wget?rev=1216017356&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.rsbac.org/wiki/experiences/igraltist/kernel_boot_parameters?rev=1294378050&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.rsbac.org/wiki/experiences/igraltist/kvm_guest_jail?rev=1294407568&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.rsbac.org/wiki/experiences/igraltist/kvm-network?rev=1297685845&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.rsbac.org/wiki/experiences/igraltist/kvm?rev=1336888424&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.rsbac.org/wiki/experiences/igraltist/manpages?rev=1294410157&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.rsbac.org/wiki/experiences/igraltist/manual?rev=1274798035&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.rsbac.org/wiki/experiences/igraltist/patch_fix_pax?rev=1256771520&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.rsbac.org/wiki/experiences/igraltist/patches?rev=1279236259&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.rsbac.org/wiki/experiences/igraltist/rc_old?rev=1315763868&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.rsbac.org/wiki/experiences/igraltist/rc?rev=1343470854&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.rsbac.org/wiki/experiences/igraltist/run-jail?rev=1342900894&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.rsbac.org/wiki/experiences/igraltist/scd_flags?rev=1215816905&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.rsbac.org/wiki/experiences/igraltist/setup?rev=1376049475&amp;do=diff"/>
                <rdf:li rdf:resource="https://www.rsbac.org/wiki/experiences/igraltist/um-gentoo?rev=1342901443&amp;do=diff"/>
            </rdf:Seq>
        </items>
    </channel>
    <image rdf:about="https://www.rsbac.org/lib/tpl/rsbac/images/favicon.ico">
        <title>RSBAC: Extending Linux Security Beyond the Limits</title>
        <link>https://www.rsbac.org/</link>
        <url>https://www.rsbac.org/lib/tpl/rsbac/images/favicon.ico</url>
    </image>
    <item rdf:about="https://www.rsbac.org/wiki/experiences/igraltist/acl-su?rev=1342900723&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2012-07-21T19:58:43+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>wiki:experiences:igraltist:acl-su</title>
        <link>https://www.rsbac.org/wiki/experiences/igraltist/acl-su?rev=1342900723&amp;do=diff</link>
        <description></description>
    </item>
    <item rdf:about="https://www.rsbac.org/wiki/experiences/igraltist/acl?rev=1342900513&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2012-07-21T19:55:13+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>wiki:experiences:igraltist:acl</title>
        <link>https://www.rsbac.org/wiki/experiences/igraltist/acl?rev=1342900513&amp;do=diff</link>
        <description>Back to igraltist&#039;s experiences/ACL


RSBAC ACL Example

Problem description

On standard linux system nothing prevented the root user switch to any other user.

Solution with ACL Groups

This is only example for ACL. 
The AUTH and or the RC module is much comfortable.
All have to do as  security user (uid 400).</description>
    </item>
    <item rdf:about="https://www.rsbac.org/wiki/experiences/igraltist/admins?rev=1380782586&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2013-10-03T06:43:06+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>wiki:experiences:igraltist:admins</title>
        <link>https://www.rsbac.org/wiki/experiences/igraltist/admins?rev=1380782586&amp;do=diff</link>
        <description>back to igraltist experiences

Split of the the admin duties

RSBAC gives the opportunity to split the all mighty root user into different admin users.
With this setup the root user is still present but the first task from an admin is transfer to specialized user.
Need the RSBAC RC module.</description>
    </item>
    <item rdf:about="https://www.rsbac.org/wiki/experiences/igraltist/booting?rev=1345299240&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2012-08-18T14:14:00+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>wiki:experiences:igraltist:booting</title>
        <link>https://www.rsbac.org/wiki/experiences/igraltist/booting?rev=1345299240&amp;do=diff</link>
        <description>Back to igraltist&#039;s experiences /RSBAC RC

The first part

When you hit this site I guess you have successfully boot your RSBAC system and RC is waiting to setup. All is depend on the proper setup of the RC module.

Most linux distribution using the  Filesystem Hierarchy Standard.
The first two colums in the table below refer to the RC type number and RC type name. I use my system so some directories maybe differ on your system.</description>
    </item>
    <item rdf:about="https://www.rsbac.org/wiki/experiences/igraltist/examples?rev=1342900975&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2012-07-21T20:02:55+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>wiki:experiences:igraltist:examples</title>
        <link>https://www.rsbac.org/wiki/experiences/igraltist/examples?rev=1342900975&amp;do=diff</link>
        <description>Back to igraltist experiences

Examples

On this site I give some example for using different RSBAC modules.
This is mostly from daily using but also gives me a place for look up my self.

If you need help to get the right paramaters for rsbac_jail then see explain jail messages.</description>
    </item>
    <item rdf:about="https://www.rsbac.org/wiki/experiences/igraltist/installation?rev=1345288458&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2012-08-18T11:14:18+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>wiki:experiences:igraltist:installation</title>
        <link>https://www.rsbac.org/wiki/experiences/igraltist/installation?rev=1345288458&amp;do=diff</link>
        <description>Back to igraltist experiences

Requirements

RSBAC can use on every modern computer on which the linux kernel 2.4 or 2.6 runs &gt;3.0. The kernel support for 2.4 and 2.6 is droped. 

You can choose your favorite linux distribution.

My favorites are gentoo and debian.

I have tested it on an old cpu with 133Mhz and 64MB.</description>
    </item>
    <item rdf:about="https://www.rsbac.org/wiki/experiences/igraltist/introduction?rev=1345286530&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2012-08-18T10:42:10+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>wiki:experiences:igraltist:introduction</title>
        <link>https://www.rsbac.org/wiki/experiences/igraltist/introduction?rev=1345286530&amp;do=diff</link>
        <description>Back to igraltist experiences

Why I chose RSBAC?

I read an article in linux magazin.
I bought a linux-magazin this contained a cd with adamantix.

Through this I have learned a lot and still be learning. Thanks to all people which   have helped me a lot. Mainly on the irc chanel rsbac on freenode.</description>
    </item>
    <item rdf:about="https://www.rsbac.org/wiki/experiences/igraltist/jail_apache2?rev=1216003146&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2008-07-14T02:39:06+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>wiki:experiences:igraltist:jail_apache2</title>
        <link>https://www.rsbac.org/wiki/experiences/igraltist/jail_apache2?rev=1216003146&amp;do=diff</link>
        <description>This is the modified apache2 init-script


--- apache2_orginal	2008-07-01 14:33:17.000000000 +0200
+++ apache2	2008-07-02 18:11:08.000000000 +0200
@@ -115,6 +115,8 @@
         	      fi
 		 done
 	fi
+	echo &quot;sleeping a bit, otherwise the port is blocking from dieing apache&quot;
+	sleep 2
 }
 
 # Stupid hack to keep lintian happy. (Warrk! Stupidhack!).
@@ -126,7 +128,9 @@
 		#ssl_scache shouldn&#039;t be here if we&#039;re just starting up.
 		[ -f /var/run/apache2/ssl_scache ] &amp;&amp; rm -f /var/run/apache2/*ssl_s…</description>
    </item>
    <item rdf:about="https://www.rsbac.org/wiki/experiences/igraltist/jail_apcupsd?rev=1309407204&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2011-06-30T04:13:24+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>wiki:experiences:igraltist:jail_apcupsd</title>
        <link>https://www.rsbac.org/wiki/experiences/igraltist/jail_apcupsd?rev=1309407204&amp;do=diff</link>
        <description>;
; RSBAC JAIL definition for apcupsd
; 20110112
;
; Tested by Jens Kasten
;
; on Gentoo(hardened)
;

&quot;&quot;
&quot;lo&quot;
(allow-netlink
 allow-inet-raw
 allow-external-ipc
 allow-dev-write
 allow-dev-read
 auto-adjust-ip-address)
(setgid
 setuid)
()
(rlimit)</description>
    </item>
    <item rdf:about="https://www.rsbac.org/wiki/experiences/igraltist/jail_cron?rev=1215837316&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2008-07-12T04:35:16+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>wiki:experiences:igraltist:jail_cron</title>
        <link>https://www.rsbac.org/wiki/experiences/igraltist/jail_cron?rev=1215837316&amp;do=diff</link>
        <description>This is the modified cron init-script
 diff -u cron_org cron
 --- cron_org	2008-07-03 04:10:46.000000000 +0200
 +++ cron	2008-07-03 04:12:02.000000000 +0200
 @@ -23,7 +23,7 @@
 case &quot;$1&quot; in
 start)	log_daemon_msg &quot;Starting periodic command scheduler&quot; &quot;crond&quot;
 -        start-stop-daemon --start --quiet --pidfile /var/run/crond.pid --name cron --startas /usr/sbin/cron --    $LSBNAMES
 +        run-jail cron start-stop-daemon --start --quiet --pidfile /var/run/crond.pid --name cron --startas   /usr…</description>
    </item>
    <item rdf:about="https://www.rsbac.org/wiki/experiences/igraltist/jail_cups?rev=1215995319&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2008-07-14T00:28:39+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>wiki:experiences:igraltist:jail_cups</title>
        <link>https://www.rsbac.org/wiki/experiences/igraltist/jail_cups?rev=1215995319&amp;do=diff</link>
        <description>--- cupsd_org	2008-07-14 02:28:06.000000000 +0200
+++ cupsd	2008-07-05 02:22:26.000000000 +0200
@@ -9,7 +9,7 @@
 
 start() {
 	ebegin &quot;Starting cupsd&quot;
-	start-stop-daemon --start --quiet --exec /usr/sbin/cupsd
+	run-jail cupsd start-stop-daemon --start --quiet --exec /usr/sbin/cupsd
 	eend $?
 }</description>
    </item>
    <item rdf:about="https://www.rsbac.org/wiki/experiences/igraltist/jail_dbus?rev=1231730740&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2009-01-12T03:25:40+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>wiki:experiences:igraltist:jail_dbus</title>
        <link>https://www.rsbac.org/wiki/experiences/igraltist/jail_dbus?rev=1231730740&amp;do=diff</link>
        <description>; jail definition for dbus
; 29.08.2008
; tested on gentoo by igraltist

&quot;&quot;
&quot;lo&quot;

(allow-external-ipc
 allow-dev-get-status
 allow-dev-read
 allow-dev-write
 auto-adjust-ip-address
 private-namespace)
(setgid
 setuid
 dac-override)
(priority)
()</description>
    </item>
    <item rdf:about="https://www.rsbac.org/wiki/experiences/igraltist/jail_ddclient?rev=1309410089&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2011-06-30T05:01:29+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>wiki:experiences:igraltist:jail_ddclient</title>
        <link>https://www.rsbac.org/wiki/experiences/igraltist/jail_ddclient?rev=1309410089&amp;do=diff</link>
        <description>;
; RSBAC JAIL definition for ddclient
; 11.02.2009 20110113
;
; Installed versions:  3.7.3-r1(12:58:00 10.11.2010)(ssl)
;
; tested by: Jens Kasten (igraltist)
;
; tested on: Gentoo (Hardened)
;

&quot;&quot;
&quot;&quot;
(allow-dev-read
 allow-dev-write
 allow-external-ipc
 allow-inet-raw
 allow-netlink)
()
()
(rlimit)</description>
    </item>
    <item rdf:about="https://www.rsbac.org/wiki/experiences/igraltist/jail_dhcpd?rev=1309409914&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2011-06-30T04:58:34+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>wiki:experiences:igraltist:jail_dhcpd</title>
        <link>https://www.rsbac.org/wiki/experiences/igraltist/jail_dhcpd?rev=1309409914&amp;do=diff</link>
        <description>;
; RSBAC JAIL definition for dhcpd
;
; In the configuration file from dhcpd is set chroot
; and is changing to user and group dhcp.
;
; 20110111
;
; Installed versions:  3.1.3_p1(12:09:38 06.05.2011)(kernel_linux -doc -minimal -selinux -static)
;
; Tested by Jens Kasten(igraltist)
; on Gentoo(hardened)
;
&quot;&quot;
&quot;&quot;
(allow-dev-write
 allow-external-ipc
 allow-inet-raw
 allow-all-net-family)
(net-raw
 sys-chroot
 dac-override
 chown
 net-bind-service
 setgid
 setuid)
()
()</description>
    </item>
    <item rdf:about="https://www.rsbac.org/wiki/experiences/igraltist/jail_dmeventd?rev=1216004172&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2008-07-14T02:56:12+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>wiki:experiences:igraltist:jail_dmeventd</title>
        <link>https://www.rsbac.org/wiki/experiences/igraltist/jail_dmeventd?rev=1216004172&amp;do=diff</link>
        <description>--- dmeventd_org	2008-07-14 04:53:34.000000000 +0200
+++ dmeventd	2008-07-05 03:27:51.000000000 +0200
@@ -9,7 +9,7 @@
 
 start() {
 	ebegin &quot;Starting dmeventd&quot;
-	start-stop-daemon --start --exec /sbin/dmeventd --pidfile /var/run/dmeventd.pid
+	run-jail dmeventd start-stop-daemon --start --exec /sbin/dmeventd --pidfile /var/run/dmeventd.pid
 	eend $?
 }</description>
    </item>
    <item rdf:about="https://www.rsbac.org/wiki/experiences/igraltist/jail_flags?rev=1215810070&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2008-07-11T21:01:10+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>wiki:experiences:igraltist:jail_flags</title>
        <link>https://www.rsbac.org/wiki/experiences/igraltist/jail_flags?rev=1215810070&amp;do=diff</link>
        <description>run-jail.py with the dictionary jail_flags
       self.jail_flags = {
              &quot;allow-dev-read&quot;: &quot;-d&quot;,
              &quot;allow-dev-write&quot;: &quot;-D&quot;,
              &quot;allow-external-ipc&quot;: &quot;-i&quot;,
              &quot;allow-all-net-family&quot;: &quot;-n&quot;,
              &quot;allow-inet-raw&quot;: &quot;-r&quot;,
              &quot;allow-tty-open&quot;: &quot;-t&quot;,
              &quot;allow-inet-localhost&quot;: &quot;-o&quot;,
              &quot;allow-dev-get-status&quot;: &quot;-e&quot;,
              &quot;allow-dev-mod-system&quot;: &quot;-E&quot;,
              &quot;allow-mount&quot;: &quot;-u&quot;,
              &quot;allow-sui…</description>
    </item>
    <item rdf:about="https://www.rsbac.org/wiki/experiences/igraltist/jail_ntpd?rev=1309408123&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2011-06-30T04:28:43+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>wiki:experiences:igraltist:jail_ntpd</title>
        <link>https://www.rsbac.org/wiki/experiences/igraltist/jail_ntpd?rev=1309408123&amp;do=diff</link>
        <description>--- ntpd_org	2008-07-14 02:29:40.000000000 +0200
+++ ntpd	2008-07-05 01:52:18.000000000 +0200
@@ -22,7 +22,7 @@
 	checkconfig || return $?
 
 	ebegin &quot;Starting ntpd&quot;
-	start-stop-daemon --start --exec /usr/sbin/ntpd \
+	run-jail ntpd start-stop-daemon --start --exec /usr/sbin/ntpd \
 	    --pidfile /var/run/ntpd.pid \
 	    -- -p /var/run/ntpd.pid ${NTPD_OPTS}
 	eend $? &quot;Failed to start ntpd&quot;</description>
    </item>
    <item rdf:about="https://www.rsbac.org/wiki/experiences/igraltist/jail_pdnsd?rev=1309408300&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2011-06-30T04:31:40+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>wiki:experiences:igraltist:jail_pdnsd</title>
        <link>https://www.rsbac.org/wiki/experiences/igraltist/jail_pdnsd?rev=1309408300&amp;do=diff</link>
        <description>;
; RSBAC JAIL definition for pdnsd
; 20081407,20110113
;
; Installed versions:  1.2.8(10:37:18 10.11.2010)(urandom -debug -ipv6 -isdn -test)
;
; test by: Jens Kasten (igraltist)
; run on: Gentoo (hardened)
;
; daemon change user and group to pdnsd
;

&quot;&quot;
&quot;0.0.0.0&quot;
(allow-external-ipc
 allow-dev-read
 allow-dev-write)
(net-raw
 sys-ptrace
 net-bind-service
 setgid
 setuid)
()
()</description>
    </item>
    <item rdf:about="https://www.rsbac.org/wiki/experiences/igraltist/jail_ping?rev=1216017270&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2008-07-14T06:34:30+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>wiki:experiences:igraltist:jail_ping</title>
        <link>https://www.rsbac.org/wiki/experiences/igraltist/jail_ping?rev=1216017270&amp;do=diff</link>
        <description>;
; RSBAC JAIL definition ping
; 2.10.06
;

&quot;&quot;
&quot;0.0.0.0&quot;
;&quot;192.168.1.1&quot;
(allow-dev-write
 allow-dev-read
 allow-inet-raw)
()
()
()



ping rsbac.org
	
This is execute now:
rsbac_jail  -D -d -r ping  rsbac.org
PING rsbac.org (81.169.183.215) 56(84) bytes of data.</description>
    </item>
    <item rdf:about="https://www.rsbac.org/wiki/experiences/igraltist/jail_portmap?rev=1231730356&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2009-01-12T03:19:16+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>wiki:experiences:igraltist:jail_portmap</title>
        <link>https://www.rsbac.org/wiki/experiences/igraltist/jail_portmap?rev=1231730356&amp;do=diff</link>
        <description>--- portmap_org	2008-07-14 04:58:03.000000000 +0200
+++ portmap	2008-07-05 03:36:52.000000000 +0200
@@ -11,7 +11,7 @@
 
 start() {
 	ebegin &quot;Starting portmap&quot;
-	start-stop-daemon --start --quiet --exec /sbin/portmap -- ${PORTMAP_OPTS}
+	run-jail portmap start-stop-daemon --start --quiet --exec /sbin/portmap -- ${PORTMAP_OPTS}
 	local ret=$?
 	eend ${ret}
 	# without, if a service depending on portmap is started too fast,</description>
    </item>
    <item rdf:about="https://www.rsbac.org/wiki/experiences/igraltist/jail_postfix?rev=1309409718&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2011-06-30T04:55:18+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>wiki:experiences:igraltist:jail_postfix</title>
        <link>https://www.rsbac.org/wiki/experiences/igraltist/jail_postfix?rev=1309409718&amp;do=diff</link>
        <description>--- postfix_org	2008-07-14 04:43:40.000000000 +0200
+++ postfix	2008-07-14 02:05:07.000000000 +0200
@@ -12,7 +12,8 @@
 
 start() {
 	ebegin &quot;Starting postfix&quot;
-	postfix /usr/sbin/postfix start &gt;/dev/null 2&gt;&amp;1
+	run-jail postfix /usr/sbin/postfix start 
+        #&gt;/dev/null 2&gt;&amp;1
 	eend $?
 }
 
@@ -24,6 +25,7 @@
 
 reload() {
 	ebegin &quot;Reloading postfix&quot;
-	postfix /usr/sbin/postfix reload &gt;/dev/null 2&gt;&amp;1
+	run-jail postfix /usr/sbin/postfix reload 
+        #&gt;/dev/null 2&gt;&amp;1
 	eend $?
 }</description>
    </item>
    <item rdf:about="https://www.rsbac.org/wiki/experiences/igraltist/jail_powernowd?rev=1216003949&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2008-07-14T02:52:29+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>wiki:experiences:igraltist:jail_powernowd</title>
        <link>https://www.rsbac.org/wiki/experiences/igraltist/jail_powernowd?rev=1216003949&amp;do=diff</link>
        <description>--- powernowd_org	2008-07-14 04:49:20.000000000 +0200
+++ powernowd	2008-07-05 03:38:09.000000000 +0200
@@ -7,7 +7,7 @@
 
 start() {
 	ebegin &quot;Starting powernowd&quot;
-	/usr/sbin/powernowd -q ${POWERNOWD_OPTS}
+	run-jail powernowd /usr/sbin/powernowd -q ${POWERNOWD_OPTS}
 	eend $?
 }</description>
    </item>
    <item rdf:about="https://www.rsbac.org/wiki/experiences/igraltist/jail_rklogd?rev=1309410181&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2011-06-30T05:03:01+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>wiki:experiences:igraltist:jail_rklogd</title>
        <link>https://www.rsbac.org/wiki/experiences/igraltist/jail_rklogd?rev=1309410181&amp;do=diff</link>
        <description>;
; RSBAC JAIL definition for rklogd
; 20110112
;
; Tested by Jens Kasten (igraltist))
;

&quot;&quot;
&quot;lo&quot;
(allow-external-ipc
 allow-dev-write
 allow-dev-read
 private-namespace)
()
(rsbac-log)
()</description>
    </item>
    <item rdf:about="https://www.rsbac.org/wiki/experiences/igraltist/jail_rsync?rev=1216017569&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2008-07-14T06:39:29+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>wiki:experiences:igraltist:jail_rsync</title>
        <link>https://www.rsbac.org/wiki/experiences/igraltist/jail_rsync?rev=1216017569&amp;do=diff</link>
        <description>;
; RSBAC JAIL definition for rsync
; 20080507
;
; Tested by igraltist

&quot;&quot;
&quot;0.0.0.0&quot;
(allow-external-ipc
 allow-dev-read
 allow-dev-write
 allow-ipc-parent)
()
()
(rlimit)



rsync
	
This is execute now:
rsbac_jail  -i -d -D -P -M  rlimit rsync
rsync  version 3.0.2  protocol version 30</description>
    </item>
    <item rdf:about="https://www.rsbac.org/wiki/experiences/igraltist/jail_samba?rev=1215995068&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2008-07-14T00:24:28+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>wiki:experiences:igraltist:jail_samba</title>
        <link>https://www.rsbac.org/wiki/experiences/igraltist/jail_samba?rev=1215995068&amp;do=diff</link>
        <description>--- samba_org	2008-07-14 02:21:38.000000000 +0200
+++ samba	2008-07-13 17:34:30.000000000 +0200
@@ -23,7 +23,13 @@
 		eval cmd_exec=\$${daemon}_${signal}
 		if [ -n &quot;${cmd_exec}&quot; ]; then
 			ebegin &quot;${my_service_name} -&gt; ${signal}: ${daemon}&quot;
-			samba ${cmd_exec} &gt; /dev/null
+			if [ &quot;${signal}&quot; = &quot;start&quot; ];then
+				#echo ${cmd} &#039;-&gt;&#039; ${!cmd}
+				run-jail samba ${cmd_exec}
+				# &gt; /dev/null
+			else
+				${cmd_exec}
+			fi
 			last_result=$?
 			eend ${last_result}
 		fi</description>
    </item>
    <item rdf:about="https://www.rsbac.org/wiki/experiences/igraltist/jail_shorewall?rev=1216002962&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2008-07-14T02:36:02+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>wiki:experiences:igraltist:jail_shorewall</title>
        <link>https://www.rsbac.org/wiki/experiences/igraltist/jail_shorewall?rev=1216002962&amp;do=diff</link>
        <description>;
; RSBAC JAIL definition for shorewall         
; 20080707
;
; Tested by:
; igraltist on gentoo
;
&quot;&quot;
&quot;0.0.0.0&quot;
(allow-dev-read
 allow-dev-write
 allow-dev-get-status
 allow-all-net-family
 allow-inet-raw
 allow-ipc-syslog
 allow-ipc-parent)
(net-admin
 sys-resource
 setuid
 setgid
 net-raw)
(firewall)
(firewall
 net-id
 sysctl
 rlimit)</description>
    </item>
    <item rdf:about="https://www.rsbac.org/wiki/experiences/igraltist/jail_squid?rev=1216005185&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2008-07-14T03:13:05+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>wiki:experiences:igraltist:jail_squid</title>
        <link>https://www.rsbac.org/wiki/experiences/igraltist/jail_squid?rev=1216005185&amp;do=diff</link>
        <description>--- squid_org	2008-07-14 05:09:33.000000000 +0200
+++ squid	2008-07-05 16:35:50.000000000 +0200
@@ -98,7 +98,7 @@
 	maxfds
 	umask 027
 	cd $cdr
-	start-stop-daemon --quiet --start \
+	run-jail squid start-stop-daemon --quiet --start \
 		--pidfile $PIDFILE \
 		--chuid $CHUID \
 		--exec $DAEMON -- $SQUID_ARGS &lt; /dev/null</description>
    </item>
    <item rdf:about="https://www.rsbac.org/wiki/experiences/igraltist/jail_syslog-ng?rev=1309416617&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2011-06-30T06:50:17+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>wiki:experiences:igraltist:jail_syslog-ng</title>
        <link>https://www.rsbac.org/wiki/experiences/igraltist/jail_syslog-ng?rev=1309416617&amp;do=diff</link>
        <description>--- syslog-ng_org	2008-07-14 02:42:13.000000000 +0200
+++ syslog-ng	2008-07-14 02:42:33.000000000 +0200
@@ -36,7 +36,7 @@
 	checkconfig || return 1
 	ebegin &quot;Starting syslog-ng&quot;
 	[ -n &quot;${SYSLOG_NG_OPTS}&quot; ] &amp;&amp; SYSLOG_NG_OPTS=&quot;-- ${SYSLOG_NG_OPTS}&quot;
-	start-stop-daemon --start --quiet --exec /usr/sbin/syslog-ng ${SYSLOG_NG_OPTS}
+	run-jail syslog-ng start-stop-daemon --start --quiet --exec /usr/sbin/syslog-ng ${SYSLOG_NG_OPTS}
 	eend $? &quot;Failed to start syslog-ng&quot;
 }</description>
    </item>
    <item rdf:about="https://www.rsbac.org/wiki/experiences/igraltist/jail_syslogd?rev=1215997853&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2008-07-14T01:10:53+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>wiki:experiences:igraltist:jail_syslogd</title>
        <link>https://www.rsbac.org/wiki/experiences/igraltist/jail_syslogd?rev=1215997853&amp;do=diff</link>
        <description>This is the modified syslogd init-script.


--- sysklogd_org	2008-07-03 05:22:39.000000000 +0200
+++ sysklogd	2008-07-11 16:23:35.000000000 +0200
@@ -59,7 +59,7 @@
   start)
     echo -n &quot;Starting system log daemon: syslogd&quot;
     create_xconsole
-    start-stop-daemon --start --quiet --exec $binpath -- $SYSLOGD
+    rsbac_jail -Y -i-N start-stop-daemon --start --quiet --exec $binpath -- $SYSLOGD
     echo &quot;.&quot;
     ;;
   stop)
@@ -76,7 +76,7 @@
     echo -n &quot;Restarting system log daemon: syslogd&quot;…</description>
    </item>
    <item rdf:about="https://www.rsbac.org/wiki/experiences/igraltist/jail_vixie-cron?rev=1216002816&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2008-07-14T02:33:36+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>wiki:experiences:igraltist:jail_vixie-cron</title>
        <link>https://www.rsbac.org/wiki/experiences/igraltist/jail_vixie-cron?rev=1216002816&amp;do=diff</link>
        <description>--- vixie-cron_org	2008-07-14 02:36:08.000000000 +0200
+++ vixie-cron	2008-07-07 04:44:02.000000000 +0200
@@ -11,7 +11,7 @@
 
 start() {
 	ebegin &quot;Starting vixie-cron&quot;
-	start-stop-daemon --start --quiet --exec /usr/sbin/cron
+	run-jail vixie-cron start-stop-daemon --start --quiet --exec /usr/sbin/cron
 	eend $?
 }</description>
    </item>
    <item rdf:about="https://www.rsbac.org/wiki/experiences/igraltist/jail_wget?rev=1216017356&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2008-07-14T06:35:56+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>wiki:experiences:igraltist:jail_wget</title>
        <link>https://www.rsbac.org/wiki/experiences/igraltist/jail_wget?rev=1216017356&amp;do=diff</link>
        <description>;
; RSBAC JAIL definition wget
; 
;

&quot;&quot;
&quot;0.0.0.0&quot;
(allow-dev-write
 allow-dev-read)
()
()
()



 wget rsbac.org
	
This is execute now:
rsbac_jail  -D -d wget  rsbac.org
--2008-07-14 08:35:32--  http://rsbac.org/</description>
    </item>
    <item rdf:about="https://www.rsbac.org/wiki/experiences/igraltist/kernel_boot_parameters?rev=1294378050&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2011-01-07T05:27:30+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>wiki:experiences:igraltist:kernel_boot_parameters</title>
        <link>https://www.rsbac.org/wiki/experiences/igraltist/kernel_boot_parameters?rev=1294378050&amp;do=diff</link>
        <description>Kernel boot parameters

All paramaters depends on, that the modules are include in the kernel.
See security models to get an overview.

In the table below only the most often used parameters are listed.
See kernel parameters to get all.
 Parameter  Explanation rsbac_softmode*If the kernel does have softmode available, its turn it on.</description>
    </item>
    <item rdf:about="https://www.rsbac.org/wiki/experiences/igraltist/kvm_guest_jail?rev=1294407568&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2011-01-07T13:39:28+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>wiki:experiences:igraltist:kvm_guest_jail</title>
        <link>https://www.rsbac.org/wiki/experiences/igraltist/kvm_guest_jail?rev=1294407568&amp;do=diff</link>
        <description>Back to igraltist&#039;s experiences/KVM on RSBAC

Start kvmguest with rsbac_jail

Based on the run-jail script and kvm-admin i do this.	 

kvm-jail-config

	 
;	 
; RSBAC JAIL definition for kvm	 
; 20080507	 
;	 
; Tested by igraltist	 
;	 
 
&quot;&quot;	 
&quot;0.0.0.0&quot;	 
(allow-dev-read	 
allow-dev-write	 
allow-ipc-syslog	 
allow-ipc-parent	 
allow-inet-raw	 
allow-all-net-family)	 
(net-raw	 
setgid	 
setuid	 
dac-override	 
net-admin	 
dac-read-search	 
sys-resource	 
sys-module)	 
()	 
(rlimit)</description>
    </item>
    <item rdf:about="https://www.rsbac.org/wiki/experiences/igraltist/kvm-network?rev=1297685845&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2011-02-14T12:17:25+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>wiki:experiences:igraltist:kvm-network</title>
        <link>https://www.rsbac.org/wiki/experiences/igraltist/kvm-network?rev=1297685845&amp;do=diff</link>
        <description>Back to igraltist&#039;s experiences / KVM

Network

What you need

Here are listed some points, which maybe helpfull to use the kvm-qemu network.

In most cases the user running a host machine thats already connected to internet or he wish to do that.

From this stage this points are appears:</description>
    </item>
    <item rdf:about="https://www.rsbac.org/wiki/experiences/igraltist/kvm?rev=1336888424&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2012-05-13T05:53:44+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>wiki:experiences:igraltist:kvm</title>
        <link>https://www.rsbac.org/wiki/experiences/igraltist/kvm?rev=1336888424&amp;do=diff</link>
        <description>Back to igraltist&#039;s experiences/KVM on RSBAC


Howto setup a kvm user on gentoo

Software packages

The listed software packages are required:

	* iproute2 (getnoo =&gt; sys-apps/iproute2,)
	* brctl (gentoo =&gt; net-misc/bridge-utils,)
	* tunctl (gentoo =&gt; sys-apps/usermode-utilities,)
	* tightvnc (gentoo</description>
    </item>
    <item rdf:about="https://www.rsbac.org/wiki/experiences/igraltist/manpages?rev=1294410157&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2011-01-07T14:22:37+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>wiki:experiences:igraltist:manpages</title>
        <link>https://www.rsbac.org/wiki/experiences/igraltist/manpages?rev=1294410157&amp;do=diff</link>
        <description>Back to igraltist&#039;s experiences/Manpages


Manpage

 The manpages  below are for rsbac version 1.4.4.
The new manpages are in process.

Manpages could be visited on external link  in the moment: manpages

	*  attr_get_net
	*  attr_back_net
	*  rc_get_eff_rights_fd
	*  rc_set_item
	*  attr_get_fd
	*  pm_create
	*  rc_get_current_role
	*  attr_get_ipc
	*  rc_copy_role
	*  switch_adf_log
	*  acl_mask
	*  attr_get_process
	*  attr_set_group
	*  auth_set_cap
	*  pm_ct_exec
	*  rc_create_file
	*  rc_r…</description>
    </item>
    <item rdf:about="https://www.rsbac.org/wiki/experiences/igraltist/manual?rev=1274798035&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2010-05-25T14:33:55+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>wiki:experiences:igraltist:manual</title>
        <link>https://www.rsbac.org/wiki/experiences/igraltist/manual?rev=1274798035&amp;do=diff</link>
        <description>Back to igraltist&#039;s experiences


Manpage

Manpages can visit in the moment on external link: manpages

	*  attr_get_net
	*  attr_back_net
	*  rc_get_eff_rights_fd
	*  rc_set_item
	*  attr_get_fd
	*  pm_create
	*  rc_get_current_role
	*  attr_get_ipc
	*  rc_copy_role
	*  switch_adf_log
	*  acl_mask
	*  attr_get_process
	*  attr_set_group
	*  auth_set_cap
	*  pm_ct_exec
	*  rc_create_file
	*  rc_role_wrap
	*  attr_get_file_dir
	*  rsbac_check
	*  attr_get_up
	*  attr_get_user
	*  attr_get_group
	…</description>
    </item>
    <item rdf:about="https://www.rsbac.org/wiki/experiences/igraltist/patch_fix_pax?rev=1256771520&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2009-10-28T23:12:00+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>wiki:experiences:igraltist:patch_fix_pax</title>
        <link>https://www.rsbac.org/wiki/experiences/igraltist/patch_fix_pax?rev=1256771520&amp;do=diff</link>
        <description>This site contain the patches wich are need if PAX was applied to the rsbac-kernel-source.

Patches

* svn_r_801
* svn_r_802</description>
    </item>
    <item rdf:about="https://www.rsbac.org/wiki/experiences/igraltist/patches?rev=1279236259&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2010-07-15T23:24:19+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>wiki:experiences:igraltist:patches</title>
        <link>https://www.rsbac.org/wiki/experiences/igraltist/patches?rev=1279236259&amp;do=diff</link>
        <description>This site contain the patches which are need if PAX was applied to the rsbac-kernel-source.
Get RSBAC source

If a rsbac patch for the current kernel version is not available, then you can use the git repository to obtain the linux source with already included rsbac-patches.</description>
    </item>
    <item rdf:about="https://www.rsbac.org/wiki/experiences/igraltist/rc_old?rev=1315763868&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2011-09-11T17:57:48+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>wiki:experiences:igraltist:rc_old</title>
        <link>https://www.rsbac.org/wiki/experiences/igraltist/rc_old?rev=1315763868&amp;do=diff</link>
        <description>RC Module

RC Testsetup

Prepare the System to get more verbose description what is missing on RC you should set this debug options.
Append in the ``/boot/grub/menu.lst`` for the used rsbac-kernel on line ``kernel``
rsbac_softmode rsbac_nosyslog rsbac_cap_process_hiding rsbac_debug_adf_auth rsbac_debug_adf_rc rsbac_debug_adf_jail rsbac_debug_adf_um rsbac_debug_jail_log_missing_rbsac_debug_cap_log_missing</description>
    </item>
    <item rdf:about="https://www.rsbac.org/wiki/experiences/igraltist/rc?rev=1343470854&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2012-07-28T10:20:54+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>wiki:experiences:igraltist:rc</title>
        <link>https://www.rsbac.org/wiki/experiences/igraltist/rc?rev=1343470854&amp;do=diff</link>
        <description>Back to igraltist&#039;s experiences /RSBAC RC

RC Module

Short explanation

Default RSBAC with RC module is using this roles:

	* Gerneral_User 0 
	* Role_Admin 1
	* System_Admin 2
	* Auditor 3

to run the system.

The permission for this roles are predefined. All this roles can be modify.
This page show only snippets or some ideas of using the RC module not a whole working setup for a server or desktop.</description>
    </item>
    <item rdf:about="https://www.rsbac.org/wiki/experiences/igraltist/run-jail?rev=1342900894&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2012-07-21T20:01:34+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>wiki:experiences:igraltist:run-jail</title>
        <link>https://www.rsbac.org/wiki/experiences/igraltist/run-jail?rev=1342900894&amp;do=diff</link>
        <description>Back to igraltist&#039;s experiences/JAIL


run-jail

Iam using my own tool to manage the RSBAC JAIL.

See the  mericurial repository.

Prepearation

Three important necessary preparations are have to be done.

	*  Enable jail support in the kernel.
	*  Enable RSBAC Debug support (RSBAC ---&gt; General Options ---&gt; [*]RSBAC-Debugging), needed for developing the jail polices.</description>
    </item>
    <item rdf:about="https://www.rsbac.org/wiki/experiences/igraltist/scd_flags?rev=1215816905&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2008-07-11T22:55:05+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>wiki:experiences:igraltist:scd_flags</title>
        <link>https://www.rsbac.org/wiki/experiences/igraltist/scd_flags?rev=1215816905&amp;do=diff</link>
        <description>the run-jail.py dictionary scd
        self.scd = {
              &quot;time-strucs&quot;: &quot;time_strucs&quot;,
              &quot;clock&quot;: &quot;clock&quot;,
              &quot;host-id&quot;: &quot;host_id&quot;,
              &quot;net-id&quot;: &quot;net_id&quot;,
              &quot;ioports&quot;: &quot;ioports&quot;,
              &quot;rlimit&quot;: &quot;rlimit&quot;,
              &quot;swap&quot;: &quot;swap&quot;,
              &quot;syslog&quot;: &quot;syslog&quot;,
              &quot;rsbac&quot;: &quot;rsbac&quot;,
              &quot;rsbac-log&quot;: &quot;rsbac_log&quot;,
              &quot;other&quot;: &quot;other&quot;,
              &quot;kmem&quot;: &quot;kmem&quot;,
              &quot;network&quot;: &quot;network&quot;…</description>
    </item>
    <item rdf:about="https://www.rsbac.org/wiki/experiences/igraltist/setup?rev=1376049475&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2013-08-09T11:57:55+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>wiki:experiences:igraltist:setup</title>
        <link>https://www.rsbac.org/wiki/experiences/igraltist/setup?rev=1376049475&amp;do=diff</link>
        <description>back to igraltist experiences

New home directory

To make the user management easier I create a subdirectories for admin users and normal users.
There are many reasons to do this. One of this is, I will protect the home directories with ACL RC module.

For convention I use this structure:</description>
    </item>
    <item rdf:about="https://www.rsbac.org/wiki/experiences/igraltist/um-gentoo?rev=1342901443&amp;do=diff">
        <dc:format>text/html</dc:format>
        <dc:date>2012-07-21T20:10:43+00:00</dc:date>
        <dc:creator>Anonymous (anonymous@undisclosed.example.com)</dc:creator>
        <title>wiki:experiences:igraltist:um-gentoo</title>
        <link>https://www.rsbac.org/wiki/experiences/igraltist/um-gentoo?rev=1342901443&amp;do=diff</link>
        <description>Back to igraltist&#039;s experiences


UM on Gentoo Linux

System preparation

The description below take the case to only use authenticate against rsbac.

Read this howto handbook user-managment
and migrating users and groups to rsbac management.

The point 9. is valid for a Debian system.
On a Gentoo is the main file to edit &#039;/etc/pam.d/system-auth&#039;.</description>
    </item>
</rdf:RDF>
