Current version
Git/Latestdiff: 1.5.6
Latest Snapshots
Produced after each commit or rebase to new upstream version
GIT
RSBAC source code, can be unstable sometimes
No events planned
This shows you the differences between two versions of the page.
Both sides previous revision Previous revision | Next revision Both sides next revision | ||
wiki:experiences:igraltist:jail_apache2 [2008/07/12 07:00] 127.0.0.1 (old revision restored) |
wiki:experiences:igraltist:jail_apache2 [2008/07/12 07:07] 127.0.0.1 (old revision restored) |
||
---|---|---|---|
Line 48: | Line 48: | ||
; | ; | ||
; RSBAC JAIL definition for apache2 | ; RSBAC JAIL definition for apache2 | ||
+ | ; 20060502 | ||
+ | ; | ||
+ | ; Tested by: | ||
+ | ; Fuleki Miklos (RAk) | ||
+ | ; Peter Busser (peter) | ||
+ | ; Robert Penz (robert) | ||
; | ; | ||
"" | "" | ||
Line 53: | Line 59: | ||
(allow-dev-read | (allow-dev-read | ||
allow-dev-write | allow-dev-write | ||
- | allow-all-net-family | + | allow-all-net-family |
- | allow-inet-raw) | + | allow-inet-raw |
- | () | + | private-namespace) |
- | () | + | (setuid |
+ | setgid | ||
+ | net-bind-service | ||
+ | kill) | ||
+ | (sysctl) | ||
(rlimit) | (rlimit) | ||
+ | |||
+ | |||
/etc/init.d/apache2 start | /etc/init.d/apache2 start | ||
Starting web server (apache2)... | Starting web server (apache2)... | ||
This is execute now: | This is execute now: | ||
- | rsbac_jail -d -D -n -r -M rlimit /usr/sbin/apache2ctl start | + | rsbac_jail -d -D -n -r -N -C SETUID SETGID NET_BIND_SERVICE KILL -G sysctl -M rlimit /usr/sbin/apache2ctl start |