Welcome to Linux Forums! With a comprehensive Linux Forum, information on various types of Linux software and many Linux Reviews articles, we have all the knowledge you need a click away, or accessible via our knowledgeable members.
Find the answer to your Linux question:
New to Linux Forums? Register here for free!
    Linux Forums > Your Distro > Ubuntu Help > Any way to encrypt a file so that no one can decrypt it.

Forgot Password?
 Ubuntu Help   Discussion and help about Ubuntu, Kubuntu, Xubuntu, and all the Ubuntu family

Site Navigation
Linux Articles
Linux Forums
Linux Downloads
Linux Hosting
Free Magazines
Job Board
IRC Chat
RSS Feeds


Linux Forum Topics
Linux Forums
Your Distro
Linux Resources
GNU Linux Zone
The Community
Reply
 
Thread Tools Display Modes
Old 08-07-2007   #11 (permalink)
Linux Guru
 
anomie's Avatar
 
Join Date: Mar 2005
Location: Texas
Posts: 1,697
Quote:
Originally Posted by kakariko81280 View Post
I don't want to be pessimistic, but I don't think there is a way to achieve exactly what you are after.
Agreed.

Quote:
Originally Posted by bigtomrodney
Surely you can be more discriminating in the /etc/sudoers file? Grant users only the root permission for what they need?
Agreed.

What you're trying to do here is tricky as hell. You have lots of full-on sudoers on the box? So you're trying to hide from lots of folks with root access. That will not work without lots of help from your friendly selinux administrator.

Given the hairy scenario that you describe, I'd say you are actually going to want to run the script from a different box. Something is wrong with the whole picture.
anomie is offline  


Reply With Quote
Old 08-07-2007   #12 (permalink)
/etc/init.d/moderator
 
bigtomrodney's Avatar
 
Join Date: Nov 2004
Location: Sunny South-East of Ireland
Posts: 6,038
At the risk of sounding cruel this is poorly implemented security. Actually this is non existant security. With root permission a user can become any other user. Encryption is not the answer and as I mentioned already there is a definite need to reel in the permissions to an absolute necessity. You may find a workaround to allow you to proceed in the direction you are going but remember it will only be that - a workaround. I would strongly rethink the security policy going forward.
__________________
Registered Linux user #378740
New members read here / Forum Rules
#linuxforums on irc.freenode.net
bigtomrodney is offline   Reply With Quote
Old 08-08-2007   #13 (permalink)
Linux Enthusiast
 
Join Date: Jul 2005
Location: Maryland
Posts: 517
How about storing that file on another server where users don't have sudo permissions? And then let them (or script, or whatever) access the file remotely but only with certain permissions (controlled by the server where the file is).
pavlo_7 is offline   Reply With Quote
Old 08-08-2007   #14 (permalink)
Just Joined!
 
LoneWolf93's Avatar
 
Join Date: Jul 2007
Location: Malta
Posts: 11
Quote:
Originally Posted by thusi02 View Post
Hi devils_casper,

Thank you for your reply. However, solution does not work as well. I have looked into this however, since there is a way to decrypt the file this will not work. Basically I want a one way ticket. I want to be able to encrypt the file and have it execute. However, I do not want there to be anyway of decrypting the file. So I want a member of the team to put their password into the file and encrypt the file and be safe that no one else is going to come along that has sudo access on the system to be able to decrypt the file. This is where the dilemma is.

Any thoughts?

Cheers,
Nathan.
The only plausible solution that crosses my mind at the moment is writing a script/program and hard code the encryption yourself in it (obviously in a way in which it is not retrievable from the output) and compile it. That way you've just "locked the door which has no key", even though there might be some techniques to analyze it and break to the source-code it's the safest way I can come up with meeting your problem specification. Hope it helps!

LW
LoneWolf93 is offline   Reply With Quote
Old 08-08-2007   #15 (permalink)
Just Joined!
 
Join Date: Jul 2006
Posts: 6
Hi bigtomrodney,

Thank you for that suggestion on the restrictive sudoers file. I am taking that approach and have restricted the users from shells, and su. I would ideally like each user to have a script of their own in the home directories and chmod the directory to 700 for them. However with ubuntu does anyone know how to restrict sudo from accessing home directories of other users? Also from preventing sudo from chowning and chmoding the home directories only?

Thank you
Regards,

Nathan.
thusi02 is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Free Magazines
Run Your Own Web Server Using Linux & Apache - Free 191 Page Preview
Learn about everything you'll need to build and maintain your Linux servers, and to deploy Web applications to them.
subscribe
Open Source Security Myths Dispelled
Dispel the five major myths surrounding Open Source Security and gain the tools necessary to make a truly informed decision for your IT organization
subscribe
InformationWeek
InformationWeek is the only newsweekly you'll need to stay on top of the latest developments in information technology.
subscribe



All times are GMT. The time now is 11:31 AM.






© 2000 - 2009 - All Rights Reserved - Property of  MAS Media

Content Relevant URLs by vBSEO 3.3.0 RC2