<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<title type="html"><![CDATA[HyperForum — postfix sendmail and FHS permissions]]></title>
	<link rel="self" href="https://forums.hyperbola.info/extern.php?action=feed&amp;tid=240&amp;type=atom" />
	<updated>2019-09-22T13:42:29Z</updated>
	<generator>PunBB</generator>
	<id>https://forums.hyperbola.info/viewtopic.php?id=240</id>
		<entry>
			<title type="html"><![CDATA[Re: postfix sendmail and FHS permissions]]></title>
			<link rel="alternate" href="https://forums.hyperbola.info/viewtopic.php?pid=1121#p1121" />
			<content type="html"><![CDATA[<div class="quotebox"><cite>Emulatorman wrote:</cite><blockquote><p>It is intended because the utilities used for system administration (and other root-only commands) are stored in /sbin, /usr/sbin, and /usr/local/sbin and it requires limited access only for users who are focused for those tasks. See <a href="https://refspecs.linuxfoundation.org/FHS_3.0/fhs/ch03s16.html">here</a> for further details.</p></blockquote></div><p>Thank you for pointing me to this documentation.&nbsp; Everything is now very clear to me!</p>]]></content>
			<author>
				<name><![CDATA[ralessi]]></name>
			</author>
			<updated>2019-09-22T13:42:29Z</updated>
			<id>https://forums.hyperbola.info/viewtopic.php?pid=1121#p1121</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: postfix sendmail and FHS permissions]]></title>
			<link rel="alternate" href="https://forums.hyperbola.info/viewtopic.php?pid=1120#p1120" />
			<content type="html"><![CDATA[<div class="quotebox"><cite>ralessi wrote:</cite><blockquote><p>Is this intended? And is it safe or recommended to add users to the `adm` group when this was not necessary before? (I believe it is safe, but I just want to be sure.)</p></blockquote></div><p>It is intended because the utilities used for system administration (and other root-only commands) are stored in /sbin, /usr/sbin, and /usr/local/sbin and it requires limited access only for users who are focused for those tasks. See <a href="https://refspecs.linuxfoundation.org/FHS_3.0/fhs/ch03s16.html">here</a> for further details.</p>]]></content>
			<author>
				<name><![CDATA[emulatorman]]></name>
				<uri>https://forums.hyperbola.info/profile.php?id=61</uri>
			</author>
			<updated>2019-09-22T13:15:26Z</updated>
			<id>https://forums.hyperbola.info/viewtopic.php?pid=1120#p1120</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[postfix sendmail and FHS permissions]]></title>
			<link rel="alternate" href="https://forums.hyperbola.info/viewtopic.php?pid=1116#p1116" />
			<content type="html"><![CDATA[<p>I noticed that `postfix` was updated recently, with new permissions for `sendmail`:<br /></p><div class="codebox"><pre><code>$ ls -l /usr/sbin/sendmail 
-rwxr-xr-x 1 root root 26600 20 sept. 22:07 /usr/sbin/sendmail</code></pre></div><p>But given FHS restrictions on `/usr/sbin`:<br /></p><div class="codebox"><pre><code>$ ls -dl /usr/sbin
drwxr-x--- 2 root adm 12288 20 sept. 23:30 /usr/sbin</code></pre></div><p>`/usr/sbin/sendmail`, as every other command inside this directory, remains unaccessible to users who are not part of&nbsp; the `adm` group.</p><p>Is this intended? And is it safe or recommended to add users to the `adm` group when this was not necessary before? (I believe it is safe, but I just want to be sure.)</p>]]></content>
			<author>
				<name><![CDATA[ralessi]]></name>
			</author>
			<updated>2019-09-22T09:21:30Z</updated>
			<id>https://forums.hyperbola.info/viewtopic.php?pid=1116#p1116</id>
		</entry>
</feed>
