/tmp and /var/tmp Server Check Warning

This forum is only for reproducible bugs with csf and lfd (i.e. not iptables problems, lack of understanding how to use a feature, etc). Posts must be accompanied with full technical details of the problem and how it can be recreated. Any posts not adhering to this, or not considered bugs, will be moved to the General Discussion (csf) forum.
Post Reply
wisperz
Junior Member
Posts: 1
Joined: 15 Nov 2007, 12:45

/tmp and /var/tmp Server Check Warning

Post by wisperz »

Hi,

I was just installing config server and try to comply to all its setting suggestion.
All of checking are greens except for :

/tmp should be mounted as a separate filesystem. Consider using /scripts/securetmp

and

/var/tmp isn't mounted with the noexec,nosuid options (currently: none). You should consider adding a mountpoint into /etc/fstab for /var/tmp with those options.

I'm running a Virtuozzo VPS server with WHM/CPanel.
I have try to update the /etc/fstab by adding the noexec,nosuid option to the /tmp and /var/tmp line but no luck. The warning are still there.

I have mentioned this to the host support and according to them, the Virtuozzo is treating the mount differently, not using the fstab or /etc/sysconfig/vz.

I wonder if this is a CFS bug or the VPS mis-setup.

I just knowing the fact that I don't have the access to "vzup2date" utilities, so I can't even know if the Virtuozzo is v3 SP1 or not.

I also want to know the truth if all Virtuozzo VPS user don't have access to vzup2date.

Any advise on these matter would be much appreciated.
chirpy
Moderator
Posts: 3537
Joined: 09 Dec 2006, 18:13

Post by chirpy »

You can't do it on a client VPS, that is something your VPS Host has to do for you.
tomfra
Junior Member
Posts: 16
Joined: 29 Dec 2006, 12:16

Post by tomfra »

chirpy wrote:You can't do it on a client VPS, that is something your VPS Host has to do for you.
Not really. Look at http://forum.lxlabs.com/index.php?t=msg ... #msg_13586 , I posted a solution there. Although on a VPS server you indeed can't mount new partisions, securing /tmp via bindmount will still work.

I've heard you need kernel 2.6.16+ for this trick but that shouldn't be a problem for most people I guess.

Tomas
persianwhois
Junior Member
Posts: 39
Joined: 11 May 2008, 14:07

Post by persianwhois »

chirpy wrote:You can't do it on a client VPS, that is something your VPS Host has to do for you.
How can resolve /tmp warning on deicated servers?
Post Reply