Discussions
Categories
Groups
Community Home
Categories
INTERNAL ENABLEMENT
POPULAR
PUBLIC CLOUD
PRIVATE CLOUD
Quick Links
MY LINKS
HELPFUL TIPS
Back to website
Home
Web CMS (TeamSite)
suexec for iwui
Valentine
Here is the problem. We need to have one script that any user on the system should be able to run and this script will go into the users workarea and do some magic.
The problem is that when the script is invoked from the web interface, it is running as iwui user, and, if we have permissions set to 770) iwui won't be able to do anything.
- I can have a SUID set for the script, but I do not want to do that.
- I can add iwui user into all groups, but that is not very good either.
Is there any way to have suexec in iw-webd?
Find more posts tagged with
Comments
Adam Stoller
Is there some reason why you can't have the script chmod'd 775 (or 755 or 555) ?
--fish
Senior Consultant, Quotient Inc.
http://www.quotient-inc.com
Valentine
oops... I was not very clear.
All of our workareas and branches are 770.
The inline's commands from the DCT are executed as iwui user, and these scripts are not able to access the files in the workareas.
Log.jpg
diago
Hello
if you are on solaris 8 there s a solution :
using solaris roles mechanisms and expect perl librarie
to execute specifics commands as root only by iw user
you write the script to do "the magical thing"
you create a privilege to execute this script as root
you create a role and assign the privilege
you assign the role to iw user
you write a perl script using expect command
to do basically " su role ; exec magical script ; exit "
regards
diago
Valentine
Hmm.. I am not too familiar with ACL's in Solaris.
I think that doing sudo will be sufficient for our needs. IW_USER environment variable is set during the execution of the script, and I think I can utilize that with sudo by writing some sort of a wrapper.
I'll read up on ACL's and RBAC and refresh the course material
well ... if anybody is interested here is the script that I have.
#!/bin/sh
if [ $# = 0 ]; then
/usr/bin/echo "Usage: `basename $0` cmd parameters"
exit 0
fi
if [ -x $1 ] && [ -n $IW_USER ]; then
/usr/local/bin/sudo -u $IW_USER $1 $2 $3 $4 $5 $6 $7 $8 $9
else
/usr/bin/echo "Supply the script to run"
fi