Hi,
I get this error when i try to create a directory:
wooley grsec: From 192.168.1.30: (root:U:/usr/sbin/pure-ftpd) denied mkdir of /www/club/test2 by /usr/sbin/pure-ftpd[pure-ftpd:7845] uid/euid:0/1119 gid/egid:1119/1119, parent /usr/sbin/pure-ftpd[pure-ftpd:6524] uid/euid:0/0 gid/egid:0/0
the two acls:
under role root :
subject /usr/sbin/pure-ftpd o {
/
/dev h
/dev/log rw
/dev/null rw
/dev/urandom r
/etc r
/etc/ssh h
/etc/grsec h
/etc/shadow h
/lib rx
/proc h
/proc/loadavg r
/sbin h
/sbin/insmod x
/usr h
/usr/lib/libcrypto.so.0.9.6 rx
/usr/lib/libssl.so.0.9.6 rx
/usr/sbin/pure-ftpd x
/usr/share/zoneinfo/Europe/London r
/var h
/var/log/pure-ftpd
/var/log/pure-ftpd/transfer.log w
/var/run/pure-ftpd rwcd
-CAP_ALL
+CAP_NET_BIND_SERVICE
+CAP_SETGID
+CAP_SETUID
+CAP_SYS_CHROOT
bind 192.168.5.35/32:21 stream dgram ip tcp
bind 192.168.5.35/32:12523-13123 stream dgram ip tcp
connect 192.168.0.9/32:53 dgram udp
connect 192.168.0.10/32:53 dgram udp
}
under role club (user id 1119):
subject /usr/sbin/pure-ftpd o {
/
/dev h
/dev/log rw
/dev/null rw
/dev/urandom r
/etc r
/etc/ssh h
/etc/grsec h
/etc/shadow h
/lib rx
/proc h
/proc/loadavg r
/sbin h
/sbin/insmod x
/usr h
/usr/lib/libcrypto.so.0.9.6 rx
/usr/lib/libssl.so.0.9.6 rx
/usr/sbin/pure-ftpd x
/usr/share/zoneinfo/Europe/London r
/var h
/var/log/pure-ftpd
/var/log/pure-ftpd/transfer.log w
/var/run/pure-ftpd rwcd
/var/www h
/www/club rwcd
-CAP_ALL
+CAP_NET_BIND_SERVICE
+CAP_SETGID
+CAP_SETUID
+CAP_SYS_CHROOT
bind 192.168.5.35/32:21 stream dgram ip tcp
# bind 192.168.5.35/32:22523-23123 stream dgram ip tcp
connect 192.168.0.9/32:53 dgram udp
connect 192.168.0.10/32:53 dgram udp
}
ps faxu:
root 18768 0.0 0.3 3072 1824 ? Ss 16:30 0:00 pure-ftpd (SERVER)
root 13645 0.0 0.4 3224 2072 ? S 16:47 0:00 \_ pure-ftpd (PRIV)
club 12525 0.0 0.4 3228 2276 ? S 16:47 0:00 \_ pure-ftpd (IDLE)
Thanks,
Andras