Missing October 2003 mbox archive (Was Re: setreuid)

2003-11-28 Thread Igor Pechtchanski
On Fri, 28 Nov 2003, Baurjan Ismagulov wrote: > [snip] > BTW, I couldn't find the cygwin-2003-10.bz2 mbox archive under > ftp://sources.redhat.com/pub/cygwin/mail-archives. There are some > problems/delays, or these archives will not be available any more? The file seems to have been misplaced.

Re: setreuid

2003-11-28 Thread Baurjan Ismagulov
Hello, Corinna. On Fri, Nov 28, 2003 at 04:08:00PM +0100, Corinna Vinschen wrote: > > 3. Install the server as a service to be run as nobody or as a special > >user just for this service (say, "tftp"). > Best solution. If there's a chance to run stuff under a non-priv'd > account, just do it.

Re: setreuid

2003-11-28 Thread Corinna Vinschen
On Fri, Nov 28, 2003 at 02:06:29PM +0200, Baurjan Ismagulov wrote: > After some thinking I decided to keep the setup as simple as possible, > and not to use inetd. So, I have the following options: > > 1. Patch the server not to use setreuid, install it as a service and run >it as SYSTEM. Tha

Re: setreuid

2003-11-28 Thread Baurjan Ismagulov
Hello, hope you still remember this thread :) (http://cygwin.com/ml/cygwin/2003-10/msg00914.html). On Fri, Oct 17, 2003 at 03:52:03PM +0200, Corinna Vinschen wrote: > > > Start a > > > service under system account as inetd and let it handle the user context > > > switch. > > Thanks for the tip, I

Re: setreuid

2003-10-17 Thread Corinna Vinschen
On Fri, Oct 17, 2003 at 04:52:34PM +0300, Baurjan Ismagulov wrote: > > Btw., if you're planning to use that account as logon account, don't > > give these rights to that account. That's very dangerous. > > Because of possible privilege escalation, or are there any other > implications? Yes, no.

Re: setreuid

2003-10-17 Thread Baurjan Ismagulov
Hello, Corinna. On Thu, Oct 16, 2003 at 15:50:59, Corinna Vinschen wrote: > > This works if I grant "Erstellen eines Tokenobjekts" to ZAISAN\ibr. What > > is going on? > That's correct. Did you read http://cygwin.com/cygwin-ug-net/ntsec.html? The problem is not to read, the problem is to underst

Re: setreuid

2003-10-16 Thread Corinna Vinschen
On Thu, Oct 16, 2003 at 05:23:39PM +0300, Baurjan Ismagulov wrote: > On Thu, Oct 16, 2003 at 13:19:29, Corinna Vinschen wrote: > > No, that's not right. The German term for "increase quotas" is > > "Anpassen von Speicherkontingenten fuer einen Prozess" (at least on > > 2003 Server). "Erstellen ei

Re: setreuid

2003-10-16 Thread Baurjan Ismagulov
On Thu, Oct 16, 2003 at 13:19:29, Corinna Vinschen wrote: > No, that's not right. The German term for "increase quotas" is > "Anpassen von Speicherkontingenten fuer einen Prozess" (at least on > 2003 Server). "Erstellen eines Tokenobjekts" is German for "Create > a token object". Hmmm, the docum

Re: setreuid

2003-10-16 Thread Corinna Vinschen
On Thu, Oct 16, 2003 at 03:53:19PM +0300, Baurjan Ismagulov wrote: > Hello, Corinna. > > On Thu, Oct 16, 2003 at 11:47:15, Corinna Vinschen wrote: > > The problem with Windows permissions needed to switch user context has > > been discussed very often on this mailing list. And we have a bit of >

Re: setreuid

2003-10-16 Thread Baurjan Ismagulov
Hello, Corinna. On Thu, Oct 16, 2003 at 11:47:15, Corinna Vinschen wrote: > The problem with Windows permissions needed to switch user context has > been discussed very often on this mailing list. And we have a bit of > documentation under http://cygwin.com/cygwin-ug-net/ntsec.html. Ah! I had se

Re: setreuid

2003-10-16 Thread Corinna Vinschen
On Thu, Oct 16, 2003 at 01:37:25PM +0300, Baurjan Ismagulov wrote: > Hello, Corinna. > > Thank you for the prompt answer. > > On Wed, Oct 15, 2003 at 15:45:51, Corinna Vinschen wrote: > > > I'm trying to use tftp-hpa. Why does setreuid(1012, 1012) fail with > > > EPERM? Should I have any special

Re: setreuid

2003-10-16 Thread Baurjan Ismagulov
Hello, Corinna. Thank you for the prompt answer. On Wed, Oct 15, 2003 at 15:45:51, Corinna Vinschen wrote: > > I'm trying to use tftp-hpa. Why does setreuid(1012, 1012) fail with > > EPERM? Should I have any special privileges? > Yes. I was unable to find this information, could you please menti

Re: setreuid

2003-10-15 Thread Corinna Vinschen
On Wed, Oct 15, 2003 at 01:52:12PM +0300, Baurjan Ismagulov wrote: > Hello, > > I'm trying to use tftp-hpa. Why does setreuid(1012, 1012) fail with > EPERM? Should I have any special privileges? Yes. Corinna -- Corinna Vinschen Please, send mails regarding Cygwin to Cygwin Dev