Ukuba sengozini ku-chrony

Π’ chrony, ukuqaliswa kwephrothokholi ye-NTP esetshenziselwa ukuvumelanisa isikhathi esiqondile ekusabalaliseni okuhlukahlukene kwe-Linux, ikhonjiwe ubungozi (I-CVE-2020-14367), okukuvumela ukuthi ubhale phezu kwanoma yiliphi ifayela kusistimu ngokufinyelela ku-chrony yasendaweni yomsebenzisi ongenamalungelo. Ukuba sengozini kungasetshenziswa kuphela nge-chrony yomsebenzisi, enciphisa ubungozi bayo. Kodwa-ke, inkinga ibeka engcupheni ileveli yokuhlukaniswa ku-chrony futhi ingase isetshenziswe uma okunye ubungozi kukhonjwa kukhodi esetshenziswe ngemva kokuthi amalungelo asethwe kabusha.

Ukuba sengozini kubangelwa ukudalwa okungaphephile kwefayela le-pid, elidalwe esigabeni lapho i-chrony ingakasethi kabusha amalungelo futhi yayisebenza njengempande. Kulokhu, umkhombandlela we-/run/chrony, lapho kubhalwe khona ifayela le-pid, wadalwa ngamalungelo 0750 nge-systemd-tmpfiles noma lapho i-chronyd yethulwa ngokuhlanganyela nomsebenzisi neqembu elithi β€œchrony”. Ngakho-ke, uma unokufinyelela ku-chrony yomsebenzisi, kungenzeka ukufaka esikhundleni sefayela le-pid /run/chrony/chronyd.pid ngesixhumanisi esingokomfanekiso. Isixhumanisi esingokomfanekiso singakhomba noma yiliphi ifayela lesistimu elizobhalwa ngaphezulu lapho i-chronyd yethulwa.

impande# systemctl yeka i-chronyd.service
impande# sudo -u chrony /bin/bash

chrony$ cd /run/chrony
chrony$ ln -s /etc/shadow chronyd.pid
chrony$ ukuphuma

impande# /usr/sbin/chronyd -n
^C
# esikhundleni sokuqukethwe kwe-/etc/shadow i-ID yenqubo ye-chronyd izogcinwa
impande # ikati /etc/shadow
15287

Ukuba sengozini kuqedwe odabeni i-chrony 3.5.1. Izibuyekezo zephakheji ezilungisa ukuba sengozini ziyatholakala Fedora. Kuhlelo lokulungisa isibuyekezo se RHEL, Debian ΠΈ Ubuntu.

SUSE kanye ne-openSUSE inkinga ayingenwa kalula, njengoba isixhumanisi esingokomfanekiso se-chrony sidalwe ngqo ku-directory / run, ngaphandle kokusebenzisa ama-subdirectories engeziwe.

Source: opennet.ru

Engeza amazwana