next up previous
$B $B?7$7$$%+!<%M%k$GN)$A>e$2$k(B $B>e$X(B: LIDS$B$N%$%s%9%H!<%k(B $BLa$k(B: kernel$B$N%3%s%Q%$%k(B

$B:F5/F0A0$N%k!<%k@_Dj(B

$B0J2<$N:n6H$O!"(Broot$B$G9T$$$^$9!#(B $B$^$:!"(B/etc/lids/lids.conf$B$r:n@.$7$F$"$2$^$9!#(B
touch /etc/lids/lids.conf
$B$^$?!":F5/F0;~$K:GDc8BI,MW$J%k!<%k$r@_Dj$7$F$"$2$^$9!#0J2<$N%k!<%k$O(B
http://www.lids/org/lids-faq/LIDS-FAQ.html
$B$r;29M$K!"(BRedHat Linux9$BMQ$K%Q%9$rJQ99$7$?$b$N$G$9!#(B
/sbin/lidsconf -A -o /sbin			-j READONLY
/sbin/lidsconf -A -o /bin			-j READONLY

/sbin/lidsconf -A -o /usr			-j READONLY
/sbin/lidsconf -A -o /lib			-j READONLY

/sbin/lidsconf -A -o /etc			-j READONLY
/sbin/lidsconf -A -o /usr/local/etc		-j READONLY
/sbin/lidsconf -A -o /etc/shadow		-j DENY
/sbin/lidsconf -A -o /etc/grub.conf		-j DENY
/sbin/lidsconf -A -o /boot/grub/grub.conf	-j DENY

/sbin/lidsconf -A -s /bin/login -o /etc/shadow	-j READONLY
/sbin/lidsconf -A -s /usr/bin/vlock -o /etc/shadow	-j READONLY
/sbin/lidsconf -A -s /bin/su -o /etc/shadow	-j READONLY
/sbin/lidsconf -A -s /bin/su -o CAP_SETUID	-j GRANT
/sbin/lidsconf -A -s /bin/su -o CAP_SETGID	-j GRANT

/sbin/lidsconf -A -o /boot			-j READONLY

/sbin/lidsconf -A -o /root			-j READONLY
/sbin/lidsconf -A -o /bin/bash -o /root/.bash_history	-j READONLY

/sbin/lidsconf -A -o /var/log			-j APPEND
/sbin/lidsconf -A -s /bin/login -o /var/log/wtmp	-j WRITE
/sbin/lidsconf -A -s /bin/login -o /var/log/lastlog	-j WRITE
/sbin/lidsconf -A -s /bin/init -o /var/log/wtmp		-j WRITE
/sbin/lidsconf -A -s /bin/init -o /var/log/lastlog	-j WRITE
/sbin/lidsconf -A -s /bin/halt -o /var/log/wtmp		-j WRITE
/sbin/lidsconf -A -s /bin/halt -o /var/log/lastlog	-j WRITE
/sbin/lidsconf -A -s /etc/rc.d/rc.sysint  -o /var/log/wtmp -i 1	-j WRITE
/sbin/lidsconf -A -s /etc/rc.d/rc.sysint  -o /var/log/lastlog -i 1	-j WRITE

/sbin/lidsconf -A -s /sbin/hwlock  -o /etc/adjtime 	-j WRITE

/sbin/lidsconf -A -s /sbin/init  -o CAP_INIT_KILL 	-j GRANT
/sbin/lidsconf -A -s /sbin/init  -o CAP_KILL 	-j GRANT

/sbin/lidsconf -A -s /etc/rc.d/init.d/halt -o CAP_INIT_KILL -i 1 	-j GRANT
/sbin/lidsconf -A -s /etc/rc.d/init.d/halt -o CAP_KILL -i 1 	-j GRANT
/sbin/lidsconf -A -s /etc/rc.d/init.d/halt -o CAP_NET_ADMIN -i 1 	-j GRANT
/sbin/lidsconf -A -s /etc/rc.d/init.d/halt -o CAP_SYS_ADMIN -i 1 	-j GRANT

/sbin/lidsconf -A -s /sbin/update -o CAP_SYS_ADMIN 	-j GRANT

/sbin/lidsconf -A -o /etc/lids			-j DENY 

/sbin/lidsconf -A -o /home/omok			-j READONLY

/sbin/lidsconf -A -s /bin/init -o /etc/initrunlvl		-j APPEND
$B:G8e$K!"@_Dj%U%!%$%k$r99?7$7$F!"H?1G$5$;$^$9!#(B
lidsconf -U


Kazuki Omo $BJ?@.(B15$BG/(B5$B7n(B16$BF|(B