Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 7 of 7
  1. #1
    Member
    Join Date
    Nov 2007
    Posts
    47

    Default Using /scripts/securetmp to secure /tmp

    When I run this script, I get the following:

    root@server [~]# /scripts/securetmp
    Would you like to secure /tmp & /var/tmp at boot time? (y/n) y
    Would you like to secure /tmp & /var/tmp now? (y/n) y
    Securing /tmp & /var/tmp
    The system does not support loop devices.

    Then the script exits without applying any changes.

    Has anyone else seen this issue?

    Regards,

    Al

  2. #2
    cPanel Development cpanelkenneth's Avatar
    Join Date
    Apr 2006
    Posts
    3,788
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    The problem is clearly stated: your system lacks support for loop devices. This means the loopback file created by securetmp cannot be mounted and used. You'll need to contact your host provider to get this resolved.

  3. #3
    Member
    Join Date
    Nov 2007
    Posts
    47

    Default

    Hi Kenneth, thanks for the speedy response.

    The system is running on a Centos VPS, and I have root access.

    Could anyone enlighten me on how to enable support for loop devices so that I can run this script?

    Is this a common issue when this script is used to secure /tmp ?

    Regards,

    Al

  4. #4
    cPanel Development cpanelkenneth's Avatar
    Join Date
    Apr 2006
    Posts
    3,788
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    If you are using Virtuozzo, I believe this must be done from the host node, rather than inside the guest.

  5. #5
    Member
    Join Date
    Nov 2007
    Posts
    47

    Default

    Thanks again for your reply Kenneth.

    I am using Virtuozzo and I also have root access to the host node (I have 3 WHM / Centos VPS's on it).

    I have tried googling around and searching other sites for how to enable loop support but I can't seem to find any information on this.

    On the node I entered:

    modprobe loop

    to enable the loop kernel module on the node. lsmod shows the loop module as being loaded. I restarted the VE then reran the script but still the same thing. I'm wondering if there is further configuration required to enable loop on the guest VEs?

    I also tried adding:

    BINDMOUNT="/tmp,nosuid,noexec,nodev /var/tmp,nosuid,noexec,nodev "

    to vz.conf on the node, still no luck securing /tmp

    Really, I'm wondering how other VPS based cpanel admins deal with securing /tmp? Given the large number of Virtuozzo VPS's in use, this issue must crop up a fair bit?

    My apologies if this is a little off topic,

  6. #6
    cPanel Development cpanelkenneth's Avatar
    Join Date
    Apr 2006
    Posts
    3,788
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Hmmm, it may not be possible on Virtuozzo systems. I know we added the loop device detection specifically for VPS environments. From your description I do believe it was for Virtuozzo.

  7. #7
    Member
    Join Date
    Nov 2007
    Posts
    47

    Default

    That would make sense.

    I'll keep looking and post back if I find a solution.

    Al

Similar Threads & Tags
Similar threads

  1. Secure temp (/scripts/securetmp) not working!!!!
    By jols in forum cPanel and WHM Discussions
    Replies: 12
    Last Post: 12-21-2006, 10:53 PM
  2. How to know if tmp is secure with /scripts/securetmp
    By demomen in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 01-17-2006, 08:35 PM
  3. Create /tmp partition as noexec or /scripts/securetmp
    By webignition in forum cPanel and WHM Discussions
    Replies: 6
    Last Post: 04-19-2005, 03:28 AM
  4. How large is /tmp when created with /scripts/securetmp?
    By knipper in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 04-19-2004, 09:50 AM
  5. /scripts/securetmp restores with incorrect /tmp permissions
    By mr.wonderful in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 02-14-2004, 04:18 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube