[OpenAFS] openafs-1.4.4 RHEL RPM still installs nonempty SuidCells

Berthold Cogel cogel@rrz.uni-koeln.de
Tue, 22 May 2007 10:35:14 +0200


Hello!

At least the RHEL 3 package still installs a nonempty SuidCells file:

athena.mit.edu
net.mit.edu
sipb.mit.edu
dev.mit.edu
ops.mit.edu

I still think that this is a security issue! If the file is read only
during startup this is problem and I have to clean up after each
installation or update on my systems before starting the client.
If I can reconfigure the running client with some fs command, I can run
a cleanup script with cron or cfengine. But until now, I haven't found
the command to do this.

IMHO the file should be left empty during installation/update.

Regards,
Berthold Cogel