diff options
author | Özgür Kesim <oec@codeblau.de> | 2016-03-04 09:16:30 +0100 |
---|---|---|
committer | Özgür Kesim <oec@codeblau.de> | 2016-03-04 09:16:30 +0100 |
commit | 8373a555015e7286d9335d23f59101de07572fac (patch) | |
tree | ec013fc37bb8cc875185b7c7b37f70bc23c2d67d /tlsserver.go | |
parent | f30a09097d73ed46e6cbf83f9571124c3800a028 (diff) |
rely on setcap rather than setuid/setgid
Diffstat (limited to 'tlsserver.go')
-rw-r--r-- | tlsserver.go | 40 |
1 files changed, 25 insertions, 15 deletions
diff --git a/tlsserver.go b/tlsserver.go index 452aead..4564a4f 100644 --- a/tlsserver.go +++ b/tlsserver.go @@ -15,8 +15,11 @@ var ( cfile = flag.String("cert", "cert.pem", "Certificate file in PEM format") kfile = flag.String("key", "key.pem", "Key file in PEM format") port = flag.Int("port", 1234, "Port to bind to") - uid = flag.Int("uid", -1, "UID to run under") - gid = flag.Int("gid", -1, "GID to run under") + /* + Rather than using setuid/setgid we rely on setcap CAP_NET_BIND_SERVICE + uid = flag.Int("uid", -1, "UID to run under") + gid = flag.Int("gid", -1, "GID to run under") + */ args []string nargs int ) @@ -53,22 +56,28 @@ func main() { } defer sock.Close() - // set uid/gid - if *gid >= 0 { - err := setgid(*gid) // syscall.Setgid(*gid) - if err != nil { - fmt.Println("Couldn't setgid to", *gid, ":", err) - os.Exit(4) + /* + The right way to handle/drop privileges is to start with a + low-privileged user and use setcap CAP_NET_BIND_SERVICE on the + binary to allow for the listen-operation. + + // set uid/gid + if *gid >= 0 { + err := setgid(*gid) // syscall.Setgid(*gid) + if err != nil { + fmt.Println("Couldn't setgid to", *gid, ":", err) + os.Exit(4) + } } - } - if *uid >= 0 { - err := setuid(*uid) // syscall.Setuid(*uid) - if err != nil { - fmt.Println("Couldn't setuid to", *uid, ":", err) - os.Exit(4) + if *uid >= 0 { + err := setuid(*uid) // syscall.Setuid(*uid) + if err != nil { + fmt.Println("Couldn't setuid to", *uid, ":", err) + os.Exit(4) + } } - } + */ // accept-loop for { @@ -91,6 +100,7 @@ func handleConnection(conn net.Conn) { cmd.Stdin = conn cmd.Stdout = conn cmd.Stderr = os.Stderr + cmd.SysProcAttr = &syscall.SysProcAttr{} // prepare environment according to tcp-environ(5) lh, lp, err := net.SplitHostPort(conn.LocalAddr().String()) |