<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title><![CDATA[HyperForum — postfix sendmail and FHS permissions]]></title>
		<link>https://forums.hyperbola.info/viewtopic.php?id=240</link>
		<atom:link href="https://forums.hyperbola.info/extern.php?action=feed&amp;tid=240&amp;type=rss" rel="self" type="application/rss+xml" />
		<description><![CDATA[The most recent posts in postfix sendmail and FHS permissions.]]></description>
		<lastBuildDate>Sun, 22 Sep 2019 13:42:29 +0000</lastBuildDate>
		<generator>PunBB</generator>
		<item>
			<title><![CDATA[Re: postfix sendmail and FHS permissions]]></title>
			<link>https://forums.hyperbola.info/viewtopic.php?pid=1121#p1121</link>
			<description><![CDATA[<div class="quotebox"><cite>Emulatorman wrote:</cite><blockquote><p>It is intended because the utilities used for system administration (and other root-only commands) are stored in /sbin, /usr/sbin, and /usr/local/sbin and it requires limited access only for users who are focused for those tasks. See <a href="https://refspecs.linuxfoundation.org/FHS_3.0/fhs/ch03s16.html">here</a> for further details.</p></blockquote></div><p>Thank you for pointing me to this documentation.&nbsp; Everything is now very clear to me!</p>]]></description>
			<author><![CDATA[null@example.com (ralessi)]]></author>
			<pubDate>Sun, 22 Sep 2019 13:42:29 +0000</pubDate>
			<guid>https://forums.hyperbola.info/viewtopic.php?pid=1121#p1121</guid>
		</item>
		<item>
			<title><![CDATA[Re: postfix sendmail and FHS permissions]]></title>
			<link>https://forums.hyperbola.info/viewtopic.php?pid=1120#p1120</link>
			<description><![CDATA[<div class="quotebox"><cite>ralessi wrote:</cite><blockquote><p>Is this intended? And is it safe or recommended to add users to the `adm` group when this was not necessary before? (I believe it is safe, but I just want to be sure.)</p></blockquote></div><p>It is intended because the utilities used for system administration (and other root-only commands) are stored in /sbin, /usr/sbin, and /usr/local/sbin and it requires limited access only for users who are focused for those tasks. See <a href="https://refspecs.linuxfoundation.org/FHS_3.0/fhs/ch03s16.html">here</a> for further details.</p>]]></description>
			<author><![CDATA[null@example.com (emulatorman)]]></author>
			<pubDate>Sun, 22 Sep 2019 13:15:26 +0000</pubDate>
			<guid>https://forums.hyperbola.info/viewtopic.php?pid=1120#p1120</guid>
		</item>
		<item>
			<title><![CDATA[postfix sendmail and FHS permissions]]></title>
			<link>https://forums.hyperbola.info/viewtopic.php?pid=1116#p1116</link>
			<description><![CDATA[<p>I noticed that `postfix` was updated recently, with new permissions for `sendmail`:<br /></p><div class="codebox"><pre><code>$ ls -l /usr/sbin/sendmail 
-rwxr-xr-x 1 root root 26600 20 sept. 22:07 /usr/sbin/sendmail</code></pre></div><p>But given FHS restrictions on `/usr/sbin`:<br /></p><div class="codebox"><pre><code>$ ls -dl /usr/sbin
drwxr-x--- 2 root adm 12288 20 sept. 23:30 /usr/sbin</code></pre></div><p>`/usr/sbin/sendmail`, as every other command inside this directory, remains unaccessible to users who are not part of&nbsp; the `adm` group.</p><p>Is this intended? And is it safe or recommended to add users to the `adm` group when this was not necessary before? (I believe it is safe, but I just want to be sure.)</p>]]></description>
			<author><![CDATA[null@example.com (ralessi)]]></author>
			<pubDate>Sun, 22 Sep 2019 09:21:30 +0000</pubDate>
			<guid>https://forums.hyperbola.info/viewtopic.php?pid=1116#p1116</guid>
		</item>
	</channel>
</rss>
