From owner-freebsd-doc@FreeBSD.ORG Mon Aug 1 22:20:20 2005 Return-Path: X-Original-To: freebsd-doc@hub.freebsd.org Delivered-To: freebsd-doc@hub.freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id D15DD16A41F for ; Mon, 1 Aug 2005 22:20:20 +0000 (GMT) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (freefall.freebsd.org [216.136.204.21]) by mx1.FreeBSD.org (Postfix) with ESMTP id A070C43D46 for ; Mon, 1 Aug 2005 22:20:20 +0000 (GMT) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (gnats@localhost [127.0.0.1]) by freefall.freebsd.org (8.13.3/8.13.3) with ESMTP id j71MKKwt007819 for ; Mon, 1 Aug 2005 22:20:20 GMT (envelope-from gnats@freefall.freebsd.org) Received: (from gnats@localhost) by freefall.freebsd.org (8.13.3/8.13.1/Submit) id j71MKKk6007818; Mon, 1 Aug 2005 22:20:20 GMT (envelope-from gnats) Date: Mon, 1 Aug 2005 22:20:20 GMT Message-Id: <200508012220.j71MKKk6007818@freefall.freebsd.org> To: freebsd-doc@FreeBSD.org From: Ceri Davies Cc: Subject: Re: docs/84453: bsd_seeotheruids root user exempt from policy X-BeenThere: freebsd-doc@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list Reply-To: Ceri Davies List-Id: Documentation project List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 01 Aug 2005 22:20:20 -0000 The following reply was made to PR docs/84453; it has been noted by GNATS. From: Ceri Davies To: Mark Linimon , glaive@vaned.net Cc: freebsd-bugs@FreeBSD.org, freebsd-gnats-submit@freebsd.org Subject: Re: docs/84453: bsd_seeotheruids root user exempt from policy Date: Mon, 1 Aug 2005 23:11:37 +0100 On 1 Aug 2005, at 21:27, Mark Linimon wrote: > Synopsis: bsd_seeotheruids root user exempt from policy > > Responsible-Changed-From-To: freebsd-bugs->freebsd-doc > Responsible-Changed-By: linimon > Responsible-Changed-When: Mon Aug 1 21:27:15 GMT 2005 > Responsible-Changed-Why: > This sounds like a problem with the Handbook. More information is required. Simply loading the kernel module is not enough; the sysctl security.mac.seeotheruids.enabled must be set to 1 for the policy to be active. Could the submitter please post the output of "sysctl -a | grep security.mac" on the affected system? Ceri -- Only two things are infinite, the universe and human stupidity, and I'm not sure about the former. -- Einstein (attrib.)