2011-05-01 20:43:29 -04:00
|
|
|
ifchd, copyright (c) 2004-2011 Nicholas Kain. Licensed under GNU GPL.
|
2010-11-12 04:02:18 -05:00
|
|
|
|
|
|
|
Requirements:
|
|
|
|
|
|
|
|
Linux kernel (tested: 2.4, 2.6)
|
2010-11-12 09:39:33 -05:00
|
|
|
* libcap is required (available via ftp.kernel.org)
|
2010-11-12 04:02:18 -05:00
|
|
|
|
|
|
|
C99-compliant C compiler (for C99 struct subobject init)
|
2010-11-12 09:39:33 -05:00
|
|
|
* any modern GCC should be sufficient
|
2010-11-12 04:02:18 -05:00
|
|
|
|
2010-11-12 12:05:37 -05:00
|
|
|
CMake (tested: 2.8)
|
|
|
|
|
2010-11-12 14:33:17 -05:00
|
|
|
Tested with glibc. dietlibc is not compatible. I have not tested uclibc.
|
2010-11-12 04:02:18 -05:00
|
|
|
|
|
|
|
INTRODUCTION
|
|
|
|
------------
|
|
|
|
|
|
|
|
ndhc consists of a set of daemons that cooperate in order to provide
|
|
|
|
privilege-seperated dhcp client services. Each daemon runs with the minimal
|
|
|
|
necessary privileges in order to perform its task. Currently, ndhc consists of
|
|
|
|
two daemons: the eponymous ndhc and ifchd.
|
|
|
|
|
|
|
|
ndhc communicates with dhcp servers and handles the vagaries of the dhcp
|
|
|
|
client protocol. It runs as a non-root user inside a chroot. ndhc retains
|
|
|
|
only the minimum necessary set of privileges required to perform its duties.
|
|
|
|
These powers include the ability to bind to a low port, the ability to open a
|
|
|
|
raw socket, and the ability to communicate on broadcast channels. ndhc holds
|
|
|
|
no other powers and is restricted to a chroot that contains nothing more than a
|
2010-12-01 12:24:47 -05:00
|
|
|
domain socket filesystem object and a urandom device node.
|
2010-11-12 04:02:18 -05:00
|
|
|
|
|
|
|
ifchd handles interface change requests. It listens on a UNIX domain socket
|
|
|
|
for such requests, and denies any client that does not match an authorized gid,
|
|
|
|
uid, or pid. ifchd runs as a non-root user inside a chroot, and retains only
|
|
|
|
the power to configure network interfaces. ifchd is designed so that it has
|
|
|
|
the ability to service multiple client requests simultaneously; a single ifchd
|
|
|
|
is sufficient for multiple ndhc clients. Only exotic setups should require
|
|
|
|
this functionality, but it does exist.
|
|
|
|
|
|
|
|
Note that ndhc does not support the entire DHCP client protocol. Only the
|
|
|
|
minimum necessary featureset is implemented. This behavior should be familiar
|
|
|
|
to anyone who has used software that purports to be be secure.
|
|
|
|
|
|
|
|
USAGE
|
|
|
|
-----
|
|
|
|
|
2010-11-12 09:39:33 -05:00
|
|
|
1) Compile and install ifchd and ndhc.
|
2010-11-12 12:05:37 -05:00
|
|
|
a) Create a build directory:
|
|
|
|
mkdir build && cd build
|
|
|
|
b) Create the makefiles:
|
|
|
|
cmake ..
|
|
|
|
c) Build ifchd and ndhc:
|
|
|
|
make
|
|
|
|
d) Install the ifchd/ifchd and ndhc/ndhc executables in a normal place. I
|
|
|
|
would suggest /usr/sbin or /usr/local/sbin.
|
2010-11-12 04:02:18 -05:00
|
|
|
|
|
|
|
2) Time to create the jail in which ifchd and ndhc will run.
|
|
|
|
a) Become root and create new group "ifchd".
|
|
|
|
|
2010-11-12 09:39:33 -05:00
|
|
|
$ su -
|
|
|
|
# umask 077
|
|
|
|
# groupadd ifchd
|
|
|
|
|
2010-11-12 04:02:18 -05:00
|
|
|
b) Create new users "ifchd" and "dhcp". The primary group of these
|
|
|
|
users should be "ifchd".
|
|
|
|
|
2010-11-12 12:05:37 -05:00
|
|
|
# useradd -d /var/lib/ndhc -s /sbin/nologin -g ifchd ifchd
|
|
|
|
# useradd -d /var/lib/ndhc -s /sbin/nologin -g ifchd dhcp
|
2010-11-12 09:39:33 -05:00
|
|
|
|
2010-11-12 04:02:18 -05:00
|
|
|
b) Create the jail directory and set its ownership properly.
|
|
|
|
|
2010-11-12 09:39:33 -05:00
|
|
|
# mkdir /var/lib/ndhc
|
2011-05-01 20:43:29 -04:00
|
|
|
# chown root.root /var/lib/ndhc
|
2010-11-12 09:39:33 -05:00
|
|
|
# chmod a+rx /var/lib/ndhc
|
2011-05-01 20:43:29 -04:00
|
|
|
# cd /var/lib/ndhc
|
|
|
|
# mkdir var
|
|
|
|
# mkdir var/state
|
|
|
|
# mkdir var/run
|
|
|
|
# chown -R ifchd.ifchd var
|
|
|
|
# chmod -R a+rx var
|
2011-06-10 14:07:03 -04:00
|
|
|
# chmod g+w var/run
|
2010-11-12 09:39:33 -05:00
|
|
|
|
2010-11-12 04:02:18 -05:00
|
|
|
c) Create a urandom device for ndhc to use within the jail.
|
|
|
|
|
2010-11-12 09:39:33 -05:00
|
|
|
# mkdir dev
|
|
|
|
# mknod dev/urandom c 1 9
|
2010-11-12 13:24:07 -05:00
|
|
|
# mknod dev/null c 1 3
|
2010-11-12 09:39:33 -05:00
|
|
|
# chown -R root.root dev
|
|
|
|
# chmod a+rx dev
|
|
|
|
# chmod a+r dev/urandom
|
2010-11-12 13:24:07 -05:00
|
|
|
# chmod a+rw dev/null
|
2010-11-12 04:02:18 -05:00
|
|
|
|
2010-11-12 09:39:33 -05:00
|
|
|
d) (optional) If you wish for logging to properly work, you
|
|
|
|
will need to properly configure your logging daemon so that it
|
|
|
|
opens a domain socket in the proper location within the jail.
|
|
|
|
Since this varies per-daemon, I cannot provide a general
|
|
|
|
configuration.
|
2010-11-12 04:02:18 -05:00
|
|
|
|
|
|
|
3) At this point the jail is usable; ifchd and ndhc are ready to
|
|
|
|
be used. As an example of a sample configuration, here is my
|
|
|
|
rc.dhcp:
|
|
|
|
|
|
|
|
--START--
|
|
|
|
|
|
|
|
#!/bin/sh
|
|
|
|
case "$1" in
|
2010-11-12 09:39:33 -05:00
|
|
|
start)
|
2010-11-12 12:05:37 -05:00
|
|
|
ifchd -i wan0 -p /var/run/ifchd.pid -u ifchd -g ifchd -U dhcp \
|
|
|
|
-G ifchd -c /var/lib/ndhc &> /dev/null
|
|
|
|
ndhc -b -i wan0 -u dhcp -C /var/lib/ndhc &> /dev/null
|
2010-11-12 09:39:33 -05:00
|
|
|
;;
|
|
|
|
stop)
|
|
|
|
killall ndhc ifchd
|
|
|
|
;;
|
2010-11-12 04:02:18 -05:00
|
|
|
esac
|
|
|
|
|
|
|
|
--END--
|
|
|
|
|
|
|
|
This script works fine with my personal machines, which are set up
|
|
|
|
exactly as I have outlined above. If you have not entirely followed my
|
|
|
|
directions, the script will of course require modifications.
|
|
|
|
|
|
|
|
4o) If you encounter problems, I suggest running both ifchd and ndhc in the
|
|
|
|
foreground, and perhaps compiling ndhc with extra debugging output
|
|
|
|
(uncomment DEBUG=1 in the Makefile).
|
|
|
|
|
|
|
|
|
|
|
|
BEHAVIOR NOTES
|
|
|
|
--------------
|
|
|
|
|
|
|
|
ifchd does not enable updates of the local hostname and resolv.conf by default.
|
|
|
|
If you wish to enable these functions, use the --resolve (-r) and --hostname
|
|
|
|
(-o) flags. See ifchd --help.
|
|
|
|
|
|
|
|
ifchd can be set such that it only allows clients to configure particular
|
|
|
|
network interfaces. The --interface (-i) argument does the trick, and may
|
|
|
|
be used multiple times to allow multiple interfaces.
|
|
|
|
|
|
|
|
GRSECURITY NOTES
|
|
|
|
----------------
|
|
|
|
|
|
|
|
Make sure that CONFIG_GRKERNSEC_CHROOT_CAPS is disabled. Otherwise, ifchd will
|
|
|
|
lose its capabilities (in particular, the ability to reconfigure interfaces)
|
|
|
|
when it chroots.
|
|
|
|
|
|
|
|
|
|
|
|
PORTING NOTES
|
|
|
|
-------------
|
|
|
|
|
2011-05-01 20:43:29 -04:00
|
|
|
There are seven major functions that ifchd depends upon that are not generally
|
2010-11-12 04:02:18 -05:00
|
|
|
portable. First, it uses the SO_PEERCRED flag of getsockopt() to discriminate
|
|
|
|
authorized connections by uid, gid, and pid. Similar functionality exists in
|
|
|
|
at least the BSDs; however, it has a different API. Second, ifchd takes
|
|
|
|
advantage of Linux capabilities so that it does not need full root privileges.
|
2011-05-01 20:43:29 -04:00
|
|
|
Capabilities were a proposed POSIX feature that was not made part of the
|
|
|
|
official standard, so any implemention that may exist will be system-dependent.
|
|
|
|
Third and fourth, ifchd configures network interfaces and routes. Interface
|
|
|
|
and route configuration is entirely non-portable, usually requiring calls to
|
|
|
|
the catch-all ioctl(), and will almost certainly require platform-dependent
|
|
|
|
code. Fifth and sixth, both ifchd and ndhc use epoll() and signalfd(), which
|
|
|
|
are Linux-specific. Seventh, ndhc uses netlink sockets extensively for
|
|
|
|
both fetching data and hardware link state change notification events.
|
2010-11-12 04:02:18 -05:00
|
|
|
|
|
|
|
Some standard C libraries include a native implementation of strlcpy() and
|
2010-11-12 05:42:07 -05:00
|
|
|
strlcat(). Such defines may conflict with my implementations in strl.c/strl.h.
|
|
|
|
It is up to the user whether the standard C library implementations should be
|
|
|
|
used. Note that some machines implement strlcpy() and strlcat() with
|
|
|
|
nonstandard semantics (notably Solaris). On these systems, using the
|
|
|
|
system-provided implementations may lead to security problems. Such problems
|
|
|
|
are the fault of the vendor. If you are unsure whether your system is correct
|
|
|
|
or not, I suggest using the implementation that I provide.
|