The seosd daemon registers a few privileged programs. Such programs are allowed to setuid to any user without checking the SURROGATE class. Currently, you can only make /bin/sendmail a privileged program, due to its flow requirements. You must keep this list as small as possible; we recommended that seoswd monitor all privileged programs to make sure they remain trusted. In the message text, programname is the full path of the registered program.
| Copyright © 2012 CA. All rights reserved. |
|