The user-space tools for configuring and administering a LIDS-enabled kernel are lidsconf and lidsadm.
All the information contained in this section is available from the man page for lidsconf (man 8 lidsconf) or from command-line help (standard: lidsconf -h, or more information: lidsconf -H).
lidsconf -A [acl_type] [-s subject] -o object [-d] [-i level] -j ACTION lidsconf -C lidsconf -D [acl_type] [-s file] [-o file] lidsconf -Z [acl_type] lidsconf -U lidsconf -L [acl_type] [-e] lidsconf -P lidsconf -S [acl_type] lidsconf -v lidsconf -[h|H]where
-A, --add To add an entry -C, --check To check all entries -D, --delete To delete an entry -Z, --zero To delete all entries -U, --update To update dev/inode numbers -L, --list To list all entries -P, --passwd To set a new password -S, --script To write a script for all entries -v, --version To show the version -h, --help To list this help -H, --morehelp To list this help with CAP/SOCKET nameand
-s, --subject subj can be any program, must be a file -o, --object [obj] can be a file, directory or Capability, Socket Nameand ACTION can be
-j, --jump DENY deny access READONLY read only APPEND append only WRITE writable GRANT grant capability to subject IGNORE ignore any permissions set on this object DISABLE disable some extension featureFinally:
-i, --inheritance Inheritance level -e, --extended Extended list
All the information contained in this section is available from the man page for lidsadm (man 8 lidsadm) or from command-line help (lidsconf -h).
lidsadm -[S|I] -- [+|-][LIDS_FLAG] [...] lidsadm -V lidsadm -hwhere
-S To submit a password to switch some protections -I To switch some protections without submitting password (sealing time) -V To view current LIDS state (caps/flags) -v To show the version -h To list this helpand the available LIDS flags are
LIDS de-/activate LIDS locally (the shell & childs) LIDS_GLOBAL de-/activate LIDS entirely RELOAD_CONF reload config. file and inode/dev of protected programs POSTBOOT de-/activate LIDS learning mode SHUTDOWN de-/activate LIDS learning mode ACL_DISCOVERY de-/activate LIDS learning mode
...previous | up (conts) | next... |