From owner-freebsd-security@FreeBSD.ORG Mon Jul 12 18:29:52 2010 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 905E91065676 for ; Mon, 12 Jul 2010 18:29:52 +0000 (UTC) (envelope-from fernan.aguero@gmail.com) Received: from mail-ey0-f182.google.com (mail-ey0-f182.google.com [209.85.215.182]) by mx1.freebsd.org (Postfix) with ESMTP id 255C68FC1B for ; Mon, 12 Jul 2010 18:29:51 +0000 (UTC) Received: by eyh6 with SMTP id 6so690805eyh.13 for ; Mon, 12 Jul 2010 11:29:51 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:received:mime-version:received:from:date :message-id:subject:to:content-type; bh=Vd/fvEP3Hm76sNxyPfg6+0p4tdiHOy6dtczdPiKg8pE=; b=u5Xm4modE47fIdAGNB61tlwFbNU2u/H/hI+WxTEBp9Hydg8aOW+E7tMlr1B5jDXC7I j+NPW4B6bZauOlyeteszMibFfjYRzPHO5NxBIj7kgVHken0+7SH9eVXZ4xnyGF0/LkXC WMJ3U9C7Sf2Aqsuhr4pVkvZ/NVYppdwp4AUn8= DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=mime-version:from:date:message-id:subject:to:content-type; b=Q6/RF9a0eHmc+ZZ3AFBkVdi7D+KF98fT3AFOEXPNq127sRDXue64BKXNYawEPmwYAc Iuldridl6lQ3A/QGuR5Z4r0OXlJ28srmMhGicwgUxPOp9HytUVZ1o4lbcXaP+I9I/vjp SnzjvNCeGLZZL0RE71rusZo19mOaX2+ueTq5U= Received: by 10.213.32.140 with SMTP id c12mr1732548ebd.95.1278957903671; Mon, 12 Jul 2010 11:05:03 -0700 (PDT) MIME-Version: 1.0 Received: by 10.213.11.11 with HTTP; Mon, 12 Jul 2010 11:04:43 -0700 (PDT) From: Fernan Aguero Date: Mon, 12 Jul 2010 15:04:43 -0300 Message-ID: To: freebsd-security@freebsd.org Content-Type: text/plain; charset=ISO-8859-1 Subject: disable (new)syslog rotation and raise securelevel ... possible? X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 12 Jul 2010 18:29:52 -0000 Hi, I'd like to harden my FreeBSD installation, and thus would like to, e.g. i) chflags sappnd /var/log/* ii) raise the securelevel of the system Is this possible? I've read elsewhere that newsyslog would not work in such a system ... what are the possible workarounds? I wouldn't bother taking the system down once a week or every other week, and manually lowering the securelevel, running newsyslog, etc. Is there a guide somewhere on how to go about this? Thanks! -- fernan