wiki:experiences:igraltist:rc
=>  Releases

Current version
Git/Latestdiff: 1.5.6

Latest Snapshots
Produced after each commit or rebase to new upstream version

GIT
RSBAC source code, can be unstable sometimes

=>  Events

No events planned

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revision Previous revision
Next revision Both sides next revision
wiki:experiences:igraltist:rc [2012/07/22 22:44]
127.0.0.1 (old revision restored)
wiki:experiences:igraltist:rc [2012/07/28 11:43]
127.0.0.1 (old revision restored)
Line 1: Line 1:
 [[wiki:​experiences/​igraltist#​rc|Back to igraltist'​s experiences /RSBAC RC]] [[wiki:​experiences/​igraltist#​rc|Back to igraltist'​s experiences /RSBAC RC]]
 +
  
  
Line 13: Line 14:
 to run the system. to run the system.
  
 +The permission for this roles are predefined. All this roles can be modify.
 +This page show only snippets or some ideas of using the RC module not a whole working setup for a server or desktop.
 +
 +For a daemon or any script there are always two roles specified.
 +  - an initial RC role
 +  - a force RC role.
 +
 +For example the Apache daemon(names can differ) ​ read configuration files as user with UID 0 (root user) and then switch to UID 33 (www-data).
 +This is a good example for using the RC module. We can use two RC roles. The first RC role for reading the configuration files etc. and the the second RC role for serving the content.
  
-The permission for this roles are hardcoded in RSBAC code itself. Otherwise the system wont work. 
-Bevor set any specific RC role for a service you can detach the default running ``Boot-Role``. 
-For this you can create a Role ``Init``. 
  
-On a binary are always two roles, an initial- and force-role.\\ 
-The initial-role is used to start a service, for this its need permission to read the necessary configurationfiles.\\ 
-The force-role is used to run this service, there is usally no reason for permission to read the configurationfiles as example. 
  
-However, if a service not chown to other user, the process is running alway with the initial-role. 
-This is surly the case for the init process. 
-So thatswhy this setup firstly. 
  
  
//
wiki/experiences/igraltist/rc.txt · Last modified: 2012/07/28 12:20 by 127.0.0.1

wiki/experiences/igraltist/rc.txt · Last modified: 2012/07/28 12:20 by 127.0.0.1
This website is kindly hosted by m-privacy