|
|
7c66a1 |
diff --git a/amandad-src/amandad.c b/amandad-src/amandad.c
|
|
|
7c66a1 |
index d864c3f..4a899fb 100644
|
|
|
7c66a1 |
--- a/amandad-src/amandad.c
|
|
|
7c66a1 |
+++ b/amandad-src/amandad.c
|
|
|
7c66a1 |
@@ -456,7 +456,7 @@ main(
|
|
|
7c66a1 |
}
|
|
|
7c66a1 |
|
|
|
7c66a1 |
#ifndef SINGLE_USERID
|
|
|
7c66a1 |
- if (geteuid() == 0) {
|
|
|
7c66a1 |
+ if (getuid() == 0) {
|
|
|
7c66a1 |
if (strcasecmp(auth, "krb5") != 0) {
|
|
|
7c66a1 |
struct passwd *pwd;
|
|
|
7c66a1 |
/* lookup our local user name */
|
|
|
7c66a1 |
diff --git a/common-src/krb5-security.c b/common-src/krb5-security.c
|
|
|
7c66a1 |
index c3075fa..8d3b18a 100644
|
|
|
7c66a1 |
--- a/common-src/krb5-security.c
|
|
|
7c66a1 |
+++ b/common-src/krb5-security.c
|
|
|
7c66a1 |
@@ -334,6 +334,7 @@ krb5_accept(
|
|
|
7c66a1 |
char hostname[NI_MAXHOST];
|
|
|
7c66a1 |
int result;
|
|
|
7c66a1 |
char *errmsg = NULL;
|
|
|
7c66a1 |
+ struct passwd *pw;
|
|
|
7c66a1 |
|
|
|
7c66a1 |
krb5_init();
|
|
|
7c66a1 |
|
|
|
7c66a1 |
@@ -372,6 +373,12 @@ krb5_accept(
|
|
|
7c66a1 |
error("gss_server failed: %s\n", rc->errmsg);
|
|
|
7c66a1 |
rc->accept_fn = fn;
|
|
|
7c66a1 |
sec_tcp_conn_read(rc);
|
|
|
7c66a1 |
+
|
|
|
7c66a1 |
+ /* totally drop privileges at this point
|
|
|
7c66a1 |
+ *(making the userid equal to the dumpuser)
|
|
|
7c66a1 |
+ */
|
|
|
7c66a1 |
+ pw = getpwnam(CLIENT_LOGIN);
|
|
|
7c66a1 |
+ setreuid(pw->pw_uid, pw->pw_uid);
|
|
|
7c66a1 |
}
|
|
|
7c66a1 |
|
|
|
7c66a1 |
/*
|
|
|
7c66a1 |
@@ -712,7 +719,7 @@ krb5_init(void)
|
|
|
7c66a1 |
beenhere = 1;
|
|
|
7c66a1 |
|
|
|
7c66a1 |
#ifndef BROKEN_MEMORY_CCACHE
|
|
|
7c66a1 |
- putenv(stralloc("KRB5_ENV_CCNAME=MEMORY:amanda_ccache"));
|
|
|
7c66a1 |
+ putenv(stralloc(KRB5_ENV_CCNAME"=MEMORY:amanda_ccache"));
|
|
|
7c66a1 |
#else
|
|
|
7c66a1 |
/*
|
|
|
7c66a1 |
* MEMORY ccaches seem buggy and cause a lot of internal heap
|
|
|
7c66a1 |
@@ -727,7 +734,7 @@ krb5_init(void)
|
|
|
7c66a1 |
char *ccache;
|
|
|
7c66a1 |
ccache = malloc(128);
|
|
|
7c66a1 |
g_snprintf(ccache, SIZEOF(ccache),
|
|
|
7c66a1 |
- "KRB5_ENV_CCNAME=FILE:/tmp/amanda_ccache.%ld.%ld",
|
|
|
7c66a1 |
+ KRB5_ENV_CCNAME"=FILE:/tmp/amanda_ccache.%ld.%ld",
|
|
|
7c66a1 |
(long)geteuid(), (long)getpid());
|
|
|
7c66a1 |
putenv(ccache);
|
|
|
7c66a1 |
}
|