From owner-freebsd-security@FreeBSD.ORG Thu Sep 30 01:02:53 2004 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 1459916A4CE for ; Thu, 30 Sep 2004 01:02:53 +0000 (GMT) Received: from pittgoth.com (14.zlnp1.xdsl.nauticom.net [209.195.149.111]) by mx1.FreeBSD.org (Postfix) with ESMTP id A796F43D49 for ; Thu, 30 Sep 2004 01:02:52 +0000 (GMT) (envelope-from trhodes@FreeBSD.org) Received: from localhost ([192.168.0.5]) (authenticated bits=0) by pittgoth.com (8.12.10/8.12.10) with ESMTP id i8U12aex006584 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT); Wed, 29 Sep 2004 21:02:36 -0400 (EDT) (envelope-from trhodes@FreeBSD.org) Date: Wed, 29 Sep 2004 21:03:18 -0400 From: Tom Rhodes To: David Schultz Message-Id: <20040929210318.5c9c2ba1@localhost> In-Reply-To: <20040929235029.GA31828@VARK.MIT.EDU> References: <4159EABF.3030004@ai.net> <20040929235029.GA31828@VARK.MIT.EDU> X-Mailer: Sylpheed-Claws 0.9.12 (GTK+ 1.2.10; i386-portbld-freebsd5.2) Mime-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit X-Mailman-Approved-At: Thu, 30 Sep 2004 12:36:46 +0000 cc: dwbear75@gmail.com cc: freebsd-security@FreeBSD.org cc: David Pick cc: Deepak Jain cc: Alexander Langer cc: cjclark@alum.mit.edu Subject: Re: Kernel-loadable Root Kits X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Security issues [members-only posting] List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 30 Sep 2004 01:02:53 -0000 On Wed, 29 Sep 2004 19:50:29 -0400 David Schultz wrote: > On Wed, Sep 29, 2004, David Pick wrote: > > 6) securelevel *is* a great thing but sysadmins are tied to the > > hierarchy of levels chosen by the project, and one size does *not* > > fit all. As a more general mechanism I would suggest that there > > is a kernel-build option for *each* facility that can be locked > > by securelevel, which geves the level at which that facility > > becomes locked. > > Great idea. See mac(4). And don't forget to read the MAC chapter in the FreeBSD Handbook. :) -- Tom Rhodes