Re: Needed: suid library calls (was Re: cvs commit: src/crypto/openssh sshd_config)

2000-05-25 Thread Kris Kennaway
On Wed, 24 May 2000, Nick Sayer wrote: > What we _really_ need is some mechanism to recognize the difference > between a user program and a system library, with an eye towards > granting privileges to trusted libraries without letting those privileges > leak past the library in question. Let's t

Re: Needed: suid library calls (was Re: cvs commit: src/crypto/openssh sshd_config)

2000-05-25 Thread Ville-Pertti Keinonen
[EMAIL PROTECTED] (Nick Sayer) writes: > What we _really_ need is some mechanism to recognize the difference > between a user program and a system library, with an eye towards > granting privileges to trusted libraries without letting those privileges > leak past the library in question. > > I d

Re: Needed: suid library calls (was Re: cvs commit: src/crypto/openssh sshd_config)

2000-05-24 Thread Jeroen C. van Gelderen
Matthew Dillon wrote: > > :"Jeroen C. van Gelderen" wrote: > : > :> [...] > :> > :> Since user authentication is needed by more than one program it > :> should live in it's own process. Right now there is code > :> duplication and it is impossible to change the authentication > :> policy without

Re: Needed: suid library calls (was Re: cvs commit: src/crypto/openssh sshd_config)

2000-05-24 Thread Nick Sayer
Matthew Dillon wrote: [lost attribution. Nick wrote this] > : > :What we _really_ need is some mechanism to recognize the difference > :between a user program and a system library, with an eye towards > :granting privileges to trusted libraries without letting those privileges > :leak past the l

Re: Needed: suid library calls (was Re: cvs commit: src/crypto/openssh sshd_config)

2000-05-24 Thread Matthew Dillon
:"Jeroen C. van Gelderen" wrote: : :> [...] :> :> Since user authentication is needed by more than one program it :> should live in it's own process. Right now there is code :> duplication and it is impossible to change the authentication :> policy without messing with sshd. :> : :What we _really_

Needed: suid library calls (was Re: cvs commit: src/crypto/openssh sshd_config)

2000-05-24 Thread Nick Sayer
"Jeroen C. van Gelderen" wrote: > [...] > > Since user authentication is needed by more than one program it > should live in it's own process. Right now there is code > duplication and it is impossible to change the authentication > policy without messing with sshd. > What we _really_ need is so