0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 - Implementation and Security...

Why setuid-root wrapper?

  1. Original web environment was not chroot

  2. Only root can perform setuid to run as unique userid

  3. Root-only access to private data,

    userid database, usage log, secret for I/O crypto token