aboutsummaryrefslogtreecommitdiff
path: root/configure.ac
diff options
context:
space:
mode:
authorTopi Miettinen <toiwoton@gmail.com>2019-05-10 22:11:40 +0300
committerTomáš Mráz <t8m@users.noreply.github.com>2020-02-18 13:18:16 +0100
commit59812d1cf1127a1af65b530addff76be767092b1 (patch)
treec05252f35d58f485d13af5988cd340a80b3e1121 /configure.ac
parentc7a66c8ca510e12f43355ac7cc893834964235b7 (diff)
downloadpam-59812d1cf1127a1af65b530addff76be767092b1.tar.gz
pam-59812d1cf1127a1af65b530addff76be767092b1.tar.bz2
pam-59812d1cf1127a1af65b530addff76be767092b1.zip
pam_namespace: secure tmp-inst directories
When using polyinstantiation for /tmp and/or /var/tmp, pam_namespace creates subdirectories with fixed name tmp-inst. These paths should be secured as early as possible to avoid that somehow these directories could created and controlled by for example a malicious user or service. Ship a systemd service, which creates the directories early in boot sequence with correct permissions and ownership. Closes #111. Signed-off-by: Topi Miettinen <toiwoton@gmail.com>
Diffstat (limited to 'configure.ac')
-rw-r--r--configure.ac1
1 files changed, 1 insertions, 0 deletions
diff --git a/configure.ac b/configure.ac
index 2e7f131f..6a7ba0e0 100644
--- a/configure.ac
+++ b/configure.ac
@@ -687,6 +687,7 @@ AC_CONFIG_FILES([Makefile libpam/Makefile libpamc/Makefile libpamc/test/Makefile
modules/pam_loginuid/Makefile modules/pam_mail/Makefile \
modules/pam_mkhomedir/Makefile modules/pam_motd/Makefile \
modules/pam_namespace/Makefile \
+ modules/pam_namespace/pam_namespace_helper modules/pam_namespace/pam_namespace.service \
modules/pam_nologin/Makefile modules/pam_permit/Makefile \
modules/pam_pwhistory/Makefile modules/pam_rhosts/Makefile \
modules/pam_rootok/Makefile modules/pam_exec/Makefile \