[GE users] Details on rsh Security Bug Fixed in 6.0u7_1

Andy Schwierskott andy.schwierskott at sun.com
Tue Jan 24 09:49:18 GMT 2006


Hi,

this is a suitable workaround indeed, however only if in addition the rsh
binary is deleted or the SUID-root bit is removed.

Andy

>> The "workaround" is to remove the SUID root bit from the rsh binary or
>> delete the binary. Both however make the "qrsh" functionality unavailable
>> (including parallel support with tight integration).
>
> Perhaps using ssh as the transport protocol would also qualify as a good
> "workaround" that does not affect functionality quite so adversely.
>
> 	http://gridengine.sunsource.net/howto/qrsh_qlogin_ssh.html
>
> It also has the benefit letting the sge binaries reside on NFS shares with
> root_squash.
>
> /mark
>
> Dr. Mark Olesen
> Principal Engineer Thermofluids Analysis
> ArvinMeritor Light Vehicle Systems
> ArvinMeritor Emissions Technologies GmbH
> Biberbachstr. 9
> D-86154 Augsburg, GERMANY
>
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: users-unsubscribe at gridengine.sunsource.net
> For additional commands, e-mail: users-help at gridengine.sunsource.net
>
>

---------------------------------------------------------------------
To unsubscribe, e-mail: users-unsubscribe at gridengine.sunsource.net
For additional commands, e-mail: users-help at gridengine.sunsource.net




More information about the gridengine-users mailing list