by gtatur » Wed Jun 04, 2008 3:34 am
Hi,
I get following problem, when I updated to latest stable grsecurity: grsecurity-2.1.11-2.6.24.5-200804211829.patch.gz
My previous sshd ACL was working fine:
subject /usr/sbin/sshd op {
user_transition_allow root
group_transition_allow root
...................
After update I get error:
(root:U:/usr/sbin/sshd) change to gid 65534 denied for /usr/sbin/sshd[sshd:4667] uid/euid:0/0 gid/egid:0/0, parent /usr/sbin/sshd[sshd:4666] uid/euid:0/0 gid/egid:0/0
65534 this is gid of group nogroup.
To get rid off these errors, ACL group_transition_allow and user_transition_allow should be changed. In my case this is:
subject /usr/sbin/sshd o {
user_transition_allow root sshd
group_transition_allow root nogroup
......
I guess, in your case, this should be:
subject /usr/sbin/sshd op {
user_transition_allow root sshd
group_transition_allow root sshd
Hope, this should help you.