From nicolas.williams@sun.com Wed Nov 11 12:49:58 2009
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nABKnvVF005274
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 11 Nov 2009 12:49:57 -0800 (PST)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id nABKnugT033230;
	Wed, 11 Nov 2009 13:49:56 -0700 (MST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KSY00D05PV71D00@brm-avmta-1.central.sun.com>; Wed,
 11 Nov 2009 13:49:55 -0700 (MST)
Received: from binky.Central.Sun.COM ([129.153.128.104])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KSY006KYPV6N130@brm-avmta-1.central.sun.com>; Wed,
 11 Nov 2009 13:49:54 -0700 (MST)
Received: from binky.Central.Sun.COM (localhost [127.0.0.1])
	by binky.Central.Sun.COM (8.14.3+Sun/8.14.3) with ESMTP id nABKjotI013878;
 Wed, 11 Nov 2009 14:45:50 -0600 (CST)
Received: (from nw141292@localhost)
	by binky.Central.Sun.COM (8.14.3+Sun/8.14.3/Submit) id nABKjo9Y013877; Wed,
 11 Nov 2009 14:45:50 -0600 (CST)
Date: Wed, 11 Nov 2009 14:45:50 -0600
From: Nicolas Williams <nicolas.williams@sun.com>
Subject: Re: smtp-notify: Email Notification Daemon for Software Events
 [PSARC/2009/619 FastTrack timeout 11/18/2009]
In-reply-to: <200911112044.nABKiDnb006526@nihil.sfbay.sun.com>
To: Liane Praza <lianep@nihil.sfbay.sun.com>
Cc: PSARC-ext@sun.com, Robert.Johnston@sun.com
Message-id: <20091111204549.GQ1105@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
Content-disposition: inline
X-PMX-Version: 5.4.1.325704
References: <200911112044.nABKiDnb006526@nihil.sfbay.sun.com>
X-Authentication-warning: binky.Central.Sun.COM: nw141292 set sender to
 Nicolas.Williams@sun.com using -f
User-Agent: Mutt/1.5.7i
Status: RO
Content-Length: 883

On Wed, Nov 11, 2009 at 12:44:13PM -0800, Liane Praza wrote:
>     4.11. Security Impact:
> 
> 	During normal operation smtp-notify must invoke sendmail to deliver
> 	email notifications.  Becuase sendmail is not privilege-aware and
> 	because sendmail must use setuid to set it's effective uid
> 	to the user whose spool it must write to, we are forced to run
> 	smtp-notify with all privileges.

Huh?  You mean that all privileges must remain in L?  Or all privileges
must remain asserted in E?  I don't understand why the latter would be
required, and as for the former, it should suffice to keep PROC_SETID in
L (since PROC_SETID is needed in L in order for exec()s of set-uid/set-
gid executables to affect the process' credentials).

Perhaps you mean that the smtp-notify processes must run with euid == 0
instead of noaccess so that sendmail allows it to send mail?

Nico
-- 

From lianep@nihil.sfbay.sun.com Wed Nov 11 12:51:48 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nABKplvr005288
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 11 Nov 2009 12:51:47 -0800 (PST)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id nABKphFM017031
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Wed, 11 Nov 2009 20:51:46 GMT
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KSY00D0DPY8A100@brm-avmta-1.central.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Wed, 11 Nov 2009 13:51:44 -0700 (MST)
Received: from dm-sfbay-02.sfbay.sun.com ([129.146.11.31])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KSY0066APY8MY50@brm-avmta-1.central.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Wed,
 11 Nov 2009 13:51:44 -0700 (MST)
Received: from nihil.sfbay.sun.com (nihil.SFBay.Sun.COM [129.146.228.161])
	by dm-sfbay-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4)
 with ESMTP id nABKphdZ023068; Wed, 11 Nov 2009 12:51:43 -0800 (PST)
Received: from nihil.sfbay.sun.com (localhost [127.0.0.1])
	by nihil.sfbay.sun.com (8.14.3+Sun/8.14.3) with ESMTP id nABKiD9q006529; Wed,
 11 Nov 2009 12:44:13 -0800 (PST)
Received: (from lianep@localhost)
	by nihil.sfbay.sun.com (8.14.3+Sun/8.14.3/Submit) id nABKiDnb006526; Wed,
 11 Nov 2009 12:44:13 -0800 (PST)
Date: Wed, 11 Nov 2009 12:44:13 -0800 (PST)
From: Liane Praza <lianep@nihil.sfbay.sun.com>
Subject: smtp-notify: Email Notification Daemon for Software Events
 [PSARC/2009/619 FastTrack timeout 11/18/2009]
To: PSARC-ext@sun.com
Cc: robert.johnston@sun.com
Message-id: <200911112044.nABKiDnb006526@nihil.sfbay.sun.com>
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 5223


Template Version: @(#)sac_nextcase 1.68 02/23/09 SMI
This information is Copyright 2009 Sun Microsystems
1. Introduction
    1.1. Project/Component Working Name:
	 smtp-notify: Email Notification Daemon for Software Events
    1.2. Name of Document Author/Supplier:
	 Author:  Robert Johnston
    1.3  Date of This Document:
	11 November, 2009
4. Technical Description

1. Introduction
   1.1. Project/Component Working Name:
	smtp-notify: Email Notification Daemon for Software Events

   1.2. Name of Document Author/Supplier:
        Author: Robert Johnston

   1.3. Date of This Document:
	11/10/2009
	
   1.5. Email Aliases:
    	1.5.1. Responsible Manager:
	sridhar.yedunuthula@sun.com

    	1.5.2. Responsible Engineer:
	robert.johnston@sun.com

	1.5.4. Interest List:
	swfma@sun.com

4. Technical Description:

    4.1. Details:

	smtp-notify is a small, lightweight daemon that is fully managed by the
	Service Management Facility (SMF).  It uses the interfaces delivered in
	libfmevent to subscribe to both software and FMA problem lifecycle
	events.  Upon receipt of an event, it produces an email notification
	based on a set of notification preferences which are stored in the
	SMF service configuration repository.
	
	The following email notification preferences can be set per event class
	(and per service instance for SMF service transition (STN) events):
	
	name		type		descr
	----		----		----
	active		boolean		toggles email notifications on/off
	to		string array	list of email recipients
	reply-to	string array	email addresses for Reply-to header
					(optional: defaults to root@localhost)
	msg_template	string		pathname of message body template
	
	For STN events, these properties are attached to the individual
	service.
	
	For all other software events and FMA events, these properties are
	attached to the instance svc:/system/fm/notify-params:default.  A set of
	default notification preferences for FMA events will be delivered in the
	manifest for the notify-params instance.  Users will be able to query
	and set notification preferences using svccfg(1M).
	
	By default, the message body will be based on a localized message
	template contained in the portable object files that are delivered in
	SUNWfmd.  smtp-notify will lookup the appropriate template (based on
	the event class) and fill in the template using elements from the event
	payload.
	
	The admin can optionally set the msg_template notification preference
	to the pathname of a user supplied message template.  This template can
	contain expansion macros (which are documented in the man page) which
	reference portions of the event payload.  These macros will be filled
	in by smtp-notify before sending the message.
	
	To facilitate email filtering, smtp-notify will create X-headers for
	the following components of the event payload for all event classes:
	
	Header name		Value
	-----------		-----
	X-FMEV-HOSTNAME		the name of the host on which the event occurred
	X-FMEV-CLASS		the event class
	X-FMEV-CODE		the Knowledge article message ID
	X-FMEV-SEVERITY		the severity of the event
	X-FMEV-UUID		the UUID of the event

	Notifications for STN events will include the following additional
	X-headers:
	
	Header name		Value
	-----------		-----
	X-FMEV-FMRI		the FMRI of the affected SMF service
	X-FMEV-FROM-STATE	the previous state of the service
	X-FMEV-TO-STATE		the new state of the service
	
	The smtp-notify daemon will be delivered in the SUNWfmd and
	SUNWfmdr packages.
	
	This case has been approved by the FMA Portfolio committee.

	This case seeks a patch binding.

    4.5. Interfaces:

        Interface                               Stability       Binding
        ---------------------------------------------------------------
 	service FMRI name			Committed	Patch
	msg template expansion macros		Committed	Patch
	X-headers				Committed	Patch

    4.11. Security Impact:

	During normal operation smtp-notify must invoke sendmail to deliver
	email notifications.  Becuase sendmail is not privilege-aware and
	because sendmail must use setuid to set it's effective uid
	to the user whose spool it must write to, we are forced to run
	smtp-notify with all privileges.
	
	The case will introduce the following new authorization for management
	of the smtp-notify service:
	
	solaris.smf.manage.smtp-notify
	
	This call also introduces the "Event Notification Agent Management"
	profile which will include the above authorization as well as the new
	authorization being added for the snmp-notify service.

5. Reference Documents:

smtp-notify(1M) man page and Sample email notifications are available
in the case directory.

libfmevent PSARC case (2009/573)
http://arc.opensolaris.org/caselog/PSARC/2009/573/

Software Events Notification Parameters CLI (2009/617)
http://arc.opensolaris.org/caselog/PSARC/2009/617/


6. Resources and Schedule:
   6.4. Product Approval Committee requested information:
   	6.4.1. Consolidation or Component Name:
		OS/Net

   6.5. ARC review type:
	Fasttrack
	
   6.6. ARC Exposure:
	open


6. Resources and Schedule
    6.4. Steering Committee requested information
   	6.4.1. Consolidation C-team Name:
		ON
    6.5. ARC review type: FastTrack
    6.6. ARC Exposure: open


From Robert.Johnston@sun.com Wed Nov 11 14:10:53 2009
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nABMAqee008863
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 11 Nov 2009 14:10:52 -0800 (PST)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail2sca.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id nABMAmSH007716
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Wed, 11 Nov 2009 14:10:52 -0800 (PST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KSY00L09TM3FD00@brm-avmta-1.central.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Wed, 11 Nov 2009 15:10:51 -0700 (MST)
Received: from brmea-mail-1.sun.com ([192.18.98.31])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KSY0065QTM2NAB0@brm-avmta-1.central.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Wed,
 11 Nov 2009 15:10:50 -0700 (MST)
Received: from fe-amer-10.sun.com ([192.18.109.80])
	by brmea-mail-1.sun.com (8.13.6+Sun/8.12.9) with ESMTP id nABMAoAe006969	for
 <PSARC-ext@sun.com>; Wed, 11 Nov 2009 22:10:50 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 id <0KSY00H00TKXSU00@mail-amer.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Wed, 11 Nov 2009 15:10:50 -0700 (MST)
Received: from [192.168.2.5] ([unknown] [67.181.48.220])
 by mail-amer.sun.com (Sun Java(tm) System Messaging Server 7u2-7.04 64bit
 (built Jul  2 2009)) with ESMTPSA id <0KSY007N9TKYBQ20@mail-amer.sun.com>; Wed,
 11 Nov 2009 15:10:10 -0700 (MST)
Date: Wed, 11 Nov 2009 14:10:10 -0800
From: Rob Johnston <Robert.Johnston@sun.com>
Subject: Re: smtp-notify: Email Notification Daemon for Software Events
 [PSARC/2009/619 FastTrack timeout 11/18/2009]
In-reply-to: <20091111204549.GQ1105@Sun.COM>
Sender: Robert.Johnston@sun.com
To: Nicolas Williams <Nicolas.Williams@sun.com>
Cc: Liane Praza <lianep@nihil.sfbay.sun.com>, PSARC-ext@sun.com
Message-id: <4AFB3642.1040606@sun.com>
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200911112044.nABKiDnb006526@nihil.sfbay.sun.com>
 <20091111204549.GQ1105@Sun.COM>
User-Agent: Thunderbird 2.0.0.23 (X11/20091013)
Status: RO
Content-Length: 1417

Nicolas Williams wrote:
> On Wed, Nov 11, 2009 at 12:44:13PM -0800, Liane Praza wrote:
>>     4.11. Security Impact:
>>
>> 	During normal operation smtp-notify must invoke sendmail to deliver
>> 	email notifications.  Becuase sendmail is not privilege-aware and
>> 	because sendmail must use setuid to set it's effective uid
>> 	to the user whose spool it must write to, we are forced to run
>> 	smtp-notify with all privileges.
> 
> Huh?  You mean that all privileges must remain in L?  Or all privileges
> must remain asserted in E?  I don't understand why the latter would be
> required, and as for the former, it should suffice to keep PROC_SETID in
> L (since PROC_SETID is needed in L in order for exec()s of set-uid/set-
> gid executables to affect the process' credentials).
> 
> Perhaps you mean that the smtp-notify processes must run with euid == 0
> instead of noaccess so that sendmail allows it to send mail?

Yes - I'm admittedly a newbie when it comes to privileges :)

I just spoke with Nicolas on the phone and he was kind enough to explain the 
privilege mechanism to me and give me some pointers for properly determining the 
minimum set of privileges needed.  Based on that conversation it seems that 
smtp-notify should be able to reduce it's E and P sets to just basic as long as 
it retains the PROC_SETID privilege in the L set.  I will test and verify this 
later today.

Thanks Nick!

rob


From liane.praza@sun.com Tue Nov 17 01:49:19 2009
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nAH9nJhw020226
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 17 Nov 2009 01:49:19 -0800 (PST)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail3mpk.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id nAH9nHqH027941;
	Tue, 17 Nov 2009 01:49:18 -0800 (PST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KT800B03ZA6I200@brm-avmta-1.central.sun.com>; Tue,
 17 Nov 2009 02:49:18 -0700 (MST)
Received: from jurassic-x4600.sfbay.sun.com ([129.146.17.63])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KT800A5EZA5J2D0@brm-avmta-1.central.sun.com>; Tue,
 17 Nov 2009 02:49:18 -0700 (MST)
Received: from [10.7.251.216] (punchin-lianep.SFBay.Sun.COM [10.7.251.216])
	by jurassic-x4600.sfbay.sun.com (8.14.3+Sun/8.14.3)
 with ESMTP id nAH9nFhX764284; Tue, 17 Nov 2009 01:49:15 -0800 (PST)
Date: Tue, 17 Nov 2009 01:49:17 -0800
From: Liane Praza <liane.praza@sun.com>
Subject: Re: smtp-notify: Email Notification Daemon for Software Events
 [PSARC/2009/619 FastTrack timeout 11/18/2009]
In-reply-to: <4AFB3642.1040606@sun.com>
To: Rob Johnston <Robert.Johnston@sun.com>
Cc: Nicolas Williams <Nicolas.Williams@sun.com>,
        Liane Praza <lianep@nihil.sfbay.sun.com>, PSARC-ext@sun.com
Message-id: <4B02719D.3050106@sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200911112044.nABKiDnb006526@nihil.sfbay.sun.com>
 <20091111204549.GQ1105@Sun.COM> <4AFB3642.1040606@sun.com>
User-Agent: Thunderbird 2.0.0.23 (X11/20091027)
Status: RO
Content-Length: 210

Rob's sent me updated materials which reflect the clarifications due 
to the conversation here around privileges and the removal of 
config/debug from the manpages.

I've put them in the case directory.

liane

From gww@sac.sfbay.sun.com Tue Nov 17 18:30:25 2009
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nAI2UPc2013320
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 17 Nov 2009 18:30:25 -0800 (PST)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail2sca.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id nAI2UOMT015020
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Tue, 17 Nov 2009 18:30:25 -0800 (PST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KTA00A1N9MPWK00@nwk-avmta-2.sfbay.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 17 Nov 2009 18:30:25 -0800 (PST)
Received: from dm-sfbay-01.sfbay.sun.com ([129.145.155.118])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KTA00KDA9MPS8F0@nwk-avmta-2.sfbay.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Tue,
 17 Nov 2009 18:30:25 -0800 (PST)
Received: from sac.sfbay.sun.com (sac.SFBay.Sun.COM [129.146.226.132])
	by dm-sfbay-01.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4)
 with ESMTP id nAI2UOl5022821; Tue, 17 Nov 2009 18:30:24 -0800 (PST)
Received: from sac.sfbay.sun.com (localhost [127.0.0.1])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nAI2UO05013317; Tue,
 17 Nov 2009 18:30:24 -0800 (PST)
Received: (from gww@localhost)	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8/Submit)
 id nAI2UMx8013316; Tue, 17 Nov 2009 18:30:22 -0800 (PST)
Date: Tue, 17 Nov 2009 18:30:22 -0800 (PST)
From: Gary Winiger <gww@sac.sfbay.sun.com>
Subject: Re: smtp-notify: Email Notification Daemon for Software Events
 [PSARC/2009/619 FastTrack timeout 11/18/2009]
To: Robert.Johnston@sun.com, liane.praza@sun.com
Cc: Nicolas.Williams@sun.com, PSARC-ext@sun.com, lianep@nihil.sfbay.sun.com
Message-id: <200911180230.nAI2UMx8013316@sac.sfbay.sun.com>
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 1022

> Rob's sent me updated materials which reflect the clarifications due 
> to the conversation here around privileges and the removal of 
> config/debug from the manpages.
> 
> I've put them in the case directory.

> 4.11. Security Impact:
> 	During daemon initialization, the smtp-notify daemon will reduce its
> 	privileges to the following minimal set:
> 
> 	afsr# ppriv 104651
> 	104651: /usr/lib/fm/notify/smtp-notify
> 	flags = PRIV_AWARE
> 		E: basic,proc_setid
> 		I: basic,proc_setid
> 		P: basic,proc_setid
> 		L: basic,proc_setid

	The updated materials don't state what uid(s)/gid(s) the service runs
	with.  If it starts with uid/gid 0 and changes it's uid/gid, what is
	the new uid?
	Note: proc_setid Allow a process to set its UIDs at will, assuming
		UID 0 requires all privileges to be asserted.
	Can this privilege reduction be done with a method context instead
	of by the daemon?  If so, why isn't that the choice.  If not,
	why not?

	Nit, I suspect there's a case dependency on PSARC/2009/617

Gary..

From Robert.Johnston@sun.com Wed Nov 18 08:54:21 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nAIGsKNO012620
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 18 Nov 2009 08:54:21 -0800 (PST)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id nAIGsIjK016624
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Wed, 18 Nov 2009 16:54:20 GMT
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KTB00K01DMJZY00@nwk-avmta-2.sfbay.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Wed, 18 Nov 2009 08:54:19 -0800 (PST)
Received: from brmea-mail-4.sun.com ([192.18.98.36])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KTB00HDBDMIJS50@nwk-avmta-2.sfbay.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Wed,
 18 Nov 2009 08:54:18 -0800 (PST)
Received: from fe-amer-09.sun.com ([192.18.109.79])
	by brmea-mail-4.sun.com (8.13.6+Sun/8.12.9) with ESMTP id nAIGsIkT008027	for
 <PSARC-ext@sun.com>; Wed, 18 Nov 2009 16:54:18 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 id <0KTB00L00D1DQI00@mail-amer.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Wed, 18 Nov 2009 09:54:18 -0700 (MST)
Received: from MacBookPro.local ([unknown] [67.181.40.130])
 by mail-amer.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 with ESMTPSA id <0KTB008BUDMED9F0@mail-amer.sun.com>; Wed,
 18 Nov 2009 09:54:15 -0700 (MST)
Date: Wed, 18 Nov 2009 08:54:14 -0800
From: Robert Johnston <Robert.Johnston@sun.com>
Subject: Re: smtp-notify: Email Notification Daemon for Software Events
 [PSARC/2009/619 FastTrack timeout 11/18/2009]
In-reply-to: <200911180230.nAI2UMx8013316@sac.sfbay.sun.com>
Sender: Robert.Johnston@sun.com
To: Gary Winiger <gww@sac.sfbay.sun.com>
Cc: Liane.Praza@sun.com, Nicolas.Williams@sun.com, PSARC-ext@sun.com,
        Robert.Johnston@sun.com
Message-id: <4B0426B6.60205@sun.com>
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200911180230.nAI2UMx8013316@sac.sfbay.sun.com>
User-Agent: Thunderbird 2.0.0.23 (Macintosh/20090812)
Status: RO
Content-Length: 1413

Hi Gary,

Thanks for looking at this - comments inline...


Gary Winiger wrote:
>> Rob's sent me updated materials which reflect the clarifications due 
>> to the conversation here around privileges and the removal of 
>> config/debug from the manpages.
>>
>> I've put them in the case directory.
> 
>> 4.11. Security Impact:
>> 	During daemon initialization, the smtp-notify daemon will reduce its
>> 	privileges to the following minimal set:
>>
>> 	afsr# ppriv 104651
>> 	104651: /usr/lib/fm/notify/smtp-notify
>> 	flags = PRIV_AWARE
>> 		E: basic,proc_setid
>> 		I: basic,proc_setid
>> 		P: basic,proc_setid
>> 		L: basic,proc_setid
> 
> 	The updated materials don't state what uid(s)/gid(s) the service runs
> 	with.  If it starts with uid/gid 0 and changes it's uid/gid, what is
> 	the new uid?

> 	Note: proc_setid Allow a process to set its UIDs at will, assuming
> 		UID 0 requires all privileges to be asserted.
> 	Can this privilege reduction be done with a method context instead
> 	of by the daemon?  If so, why isn't that the choice.  If not,
> 	why not?


The daemon needs to start as uid/gid 0, because it needs to create/bind a
sysevent channel during initialization.  Afterward doing this, it reduces
it's privilege set to the minimal set noted above and changes its uid/gid
to user noaccess (60002).


> 	Nit, I suspect there's a case dependency on PSARC/2009/617

Yes - correct.

thanks,

rob


From gww@sac.sfbay.sun.com Wed Nov 18 11:09:00 2009
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nAIJ90CU021884
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 18 Nov 2009 11:09:00 -0800 (PST)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail3mpk.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id nAIJ8vMt028551
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Wed, 18 Nov 2009 11:09:00 -0800 (PST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KTB00423JV0V800@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Wed, 18 Nov 2009 11:09:00 -0800 (PST)
Received: from dm-sfbay-02.sfbay.sun.com ([129.146.11.31])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KTB00HDPJUYQW50@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Wed,
 18 Nov 2009 11:08:58 -0800 (PST)
Received: from sac.sfbay.sun.com (sac.SFBay.Sun.COM [129.146.226.132])
	by dm-sfbay-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4)
 with ESMTP id nAIJ8via002198; Wed, 18 Nov 2009 11:08:57 -0800 (PST)
Received: from sac.sfbay.sun.com (localhost [127.0.0.1])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nAIJ8vdJ021881; Wed,
 18 Nov 2009 11:08:57 -0800 (PST)
Received: (from gww@localhost)	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8/Submit)
 id nAIJ8vGF021880; Wed, 18 Nov 2009 11:08:57 -0800 (PST)
Date: Wed, 18 Nov 2009 11:08:57 -0800 (PST)
From: Gary Winiger <gww@sac.sfbay.sun.com>
Subject: Re: smtp-notify: Email Notification Daemon for Software Events
 [PSARC/2009/619 FastTrack timeout 11/18/2009]
To: Robert.Johnston@sun.com
Cc: Liane.Praza@sun.com, Nicolas.Williams@sun.com, PSARC-ext@sun.com
Message-id: <200911181908.nAIJ8vGF021880@sac.sfbay.sun.com>
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 501

> > 	of by the daemon?  If so, why isn't that the choice.  If not,
> > 	why not?
> 
> 
> The daemon needs to start as uid/gid 0, because it needs to create/bind a
> sysevent channel during initialization.  Afterward doing this, it reduces
> it's privilege set to the minimal set noted above and changes its uid/gid
> to user noaccess (60002).

	As commented at today's PSARC meeting uid 0 and all privs is
	(unfortunately) required by the underlying channel initialization
	infrastructure.

+1
Gary..

From liane.praza@sun.com Fri Nov 20 11:23:07 2009
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nAKJN7ZR000278
	for <psarc-ext@sac.sfbay.sun.com>; Fri, 20 Nov 2009 11:23:07 -0800 (PST)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail2sca.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id nAKJN6Ua017386;
	Fri, 20 Nov 2009 11:23:07 -0800 (PST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KTF0010R9UIR400@nwk-avmta-1.sfbay.Sun.COM>; Fri,
 20 Nov 2009 11:23:06 -0800 (PST)
Received: from jurassic-x4600.sfbay.sun.com ([129.146.17.59])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KTF00EY69UG8Z40@nwk-avmta-1.sfbay.Sun.COM>; Fri,
 20 Nov 2009 11:23:04 -0800 (PST)
Received: from [129.146.228.161] (nihil.SFBay.Sun.COM [129.146.228.161])
	by jurassic-x4600.sfbay.sun.com (8.14.3+Sun/8.14.3)
 with ESMTP id nAKJN2oW998980; Fri, 20 Nov 2009 11:23:02 -0800 (PST)
Date: Fri, 20 Nov 2009 11:23:04 -0800
From: Liane Praza <liane.praza@sun.com>
Subject: Re: smtp-notify: Email Notification Daemon for Software Events
 [PSARC/2009/619 FastTrack timeout 11/18/2009]
In-reply-to: <200911181908.nAIJ8vGF021880@sac.sfbay.sun.com>
To: PSARC-ext@sun.com
Cc: Robert.Johnston@sun.com
Message-id: <4B06EC98.70501@sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200911181908.nAIJ8vGF021880@sac.sfbay.sun.com>
User-Agent: Thunderbird 2.0.0.23 (X11/20091027)
Status: RO
Content-Length: 134

This case was approved at this weeks meeting pending the requisite +1, 
which it now has.  I've marked it as approved.

thanks,
liane

