[X2go-dev] pending x2goprint patch / Possible security issues

Mike Gabriel mike.gabriel at das-netzwerkteam.de
Wed Apr 13 17:43:14 CEST 2011


Hi Morty,

On Mi 13 Apr 2011 16:46:00 CEST Moritz Struebe wrote:

> I also don't really see why x2goprint needs to be root.

The cups-x2go/x2goprint principle is as follows:

   o cups-x2go can run on x2goserver or on another print server
   o cups creates a PDF (as root)
   o cups-x2go scp-copies the file to x2gprint at x2goserver which might be local
   o cups-x2go calls x2goprint on x2goserver
   o x2goprint (as user x2goprint) will pick up the print job
   o ... move it to /tmp/...
   o chown to the x2go session user
   o ... and move the print job to the x2goclient (sshfs)

   => the chown part needs root privs...

Maybe we should really start thinking about a non-sudo way of getting  
the print job from the cups server to the x2goserver to the client...

Greets,
Mike


-- 

DAS-NETZWERKTEAM
mike gabriel, dorfstr. 27, 24245 barmissen
fon: +49 (4302) 281418, fax: +49 (4302) 281419

GnuPG Key ID 0xB588399B
mail: mike.gabriel at das-netzwerkteam.de, http://das-netzwerkteam.de

freeBusy:
https://mail.das-netzwerkteam.de/freebusy/m.gabriel%40das-netzwerkteam.de.xfb
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 490 bytes
Desc: Digitale PGP-Unterschrift
URL: <http://lists.x2go.org/pipermail/x2go-dev/attachments/20110413/1f2319b1/attachment.pgp>


More information about the x2go-dev mailing list