Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 201496 - app-backup/bacula - default configuration runs as root!
Summary: app-backup/bacula - default configuration runs as root!
Status: RESOLVED WONTFIX
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: New packages (show other bugs)
Hardware: All Linux
: High minor
Assignee: Wolfram Schlich (RETIRED)
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2007-12-06 16:56 UTC by Daniel Beckham
Modified: 2007-12-07 12:09 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Daniel Beckham 2007-12-06 16:56:33 UTC
The default configuration files for app-backup/bacula (2.2.6) install configuration files that cause bacula to run as root!  Bacula is a network backup monitor and running any network service as root is a serious security hole and should only be done knowing the risks and taking appropriate steps to protect the system.  

I imagine the reason the package maintainer decided to do this was because bacula is a backup tool and is expected to be able to read superuser privileged files.  This is perfectly fine, but should be something the system administrator  chooses to do and does with the knowledge of what risks he is taking.  The bacula package SHOULD NEVER make this assumption for an admin.

The ebuild should create a "bacula" user along with the bacula group and default to running as this user.  The system administrator can then decide how to proceed without compromising security from the start.

Reproducible: Always

Steps to Reproduce:

Actual Results:  
Bacula runs as root!
Comment 1 Jakub Moc (RETIRED) gentoo-dev 2007-12-06 19:47:31 UTC
Yeah, running it as user who lacks permissions to perform the backup will definitely rock... :P
Comment 2 Wolfram Schlich (RETIRED) gentoo-dev 2007-12-07 12:09:23 UTC
Ok, that's a really good laugh, but nothing more, sorry.