T.R | Title | User | Personal Name | Date | Lines |
---|
2822.1 | Please have the kit put the right privs on the directory. | SLINK::HOOD | Just add water | Wed Apr 22 1992 12:11 | 8 |
| The problem is the protection on the /var/mcc directory itself. It needs
to be world-write. When we changed the protection to 777 (instead of 775)
it worked ok.
Perhaps the installation kit should do this?
Thanks,
Tom
|
2822.2 | Stop MMs before changing protection | TOOK::MINTZ | Erik Mintz, DECmcc Development, dtn 226-5033 | Wed Apr 22 1992 12:15 | 10 |
| (5) ran as hood. Watched errors happen.
(6) set protection to 666 for all files in /var/mcc where the mir's
and dns files are.
> Did you restart you MMs at this point (mcc_kill to stop them)?
> Otherwise, the old protection is still in effect.
(7) ran as hood. Watched errors happen.
|
2822.3 | Doc problem? | TOOK::MINTZ | Erik Mintz, DECmcc Development, dtn 226-5033 | Wed Apr 22 1992 12:20 | 12 |
| >The problem is the protection on the /var/mcc directory itself. It needs
>to be world-write. When we changed the protection to 777 (instead of 775)
>it worked ok.
>Perhaps the installation kit should do this?
We are not permitted to create world writable directories on the customer
systems. But if this is not clear in the documentation, then the documentation
should be fixed.
-- Erik
|
2822.4 | perhaps the domain_fm needs a change in protection?? | QUIVER::WILSON | | Wed Apr 22 1992 15:44 | 14 |
| re: -1
>The problem is the protection on the /var/mcc directory itself. It needs
>to be world-write. When we changed the protection to 777 (instead of 775)
>it worked ok.
>Perhaps the installation kit should do this?
Instead of having to go through all of this, perhaps the mcc_domain_fm
needs to have the setuid bit set when it is installed. Then when it is
owned by root, you don't have to modify the protections on the files,
since root has all the access you could ever want.
Karen
|
2822.5 | Security vs Convenience | TOOK::MINTZ | Erik Mintz, DECmcc Development, dtn 226-5033 | Wed Apr 22 1992 16:38 | 6 |
| I understand that security can be a pain. But we can't take security
away from the system managers (they may not WANT everyone to be able
to modify the DECmcc MIR...)
-- Erik
|