From owner-svn-src-all@FreeBSD.ORG Thu Dec 6 11:52:32 2012 Return-Path: Delivered-To: svn-src-all@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [69.147.83.52]) by hub.freebsd.org (Postfix) with ESMTP id 9820FB57; Thu, 6 Dec 2012 11:52:32 +0000 (UTC) (envelope-from rwatson@FreeBSD.org) Received: from svn.freebsd.org (svn.freebsd.org [IPv6:2001:1900:2254:2068::e6a:0]) by mx1.freebsd.org (Postfix) with ESMTP id 623E48FC08; Thu, 6 Dec 2012 11:52:32 +0000 (UTC) Received: from svn.freebsd.org (localhost [127.0.0.1]) by svn.freebsd.org (8.14.5/8.14.5) with ESMTP id qB6BqWtW035290; Thu, 6 Dec 2012 11:52:32 GMT (envelope-from rwatson@svn.freebsd.org) Received: (from rwatson@localhost) by svn.freebsd.org (8.14.5/8.14.5/Submit) id qB6BqV1r035287; Thu, 6 Dec 2012 11:52:31 GMT (envelope-from rwatson@svn.freebsd.org) Message-Id: <201212061152.qB6BqV1r035287@svn.freebsd.org> From: Robert Watson Date: Thu, 6 Dec 2012 11:52:31 +0000 (UTC) To: src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-stable@freebsd.org, svn-src-stable-9@freebsd.org Subject: svn commit: r243947 - in stable/9/etc: . mail X-SVN-Group: stable-9 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-src-all@freebsd.org X-Mailman-Version: 2.1.14 Precedence: list List-Id: "SVN commit messages for the entire src tree \(except for " user" and " projects" \)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 06 Dec 2012 11:52:32 -0000 Author: rwatson Date: Thu Dec 6 11:52:31 2012 New Revision: 243947 URL: http://svnweb.freebsd.org/changeset/base/243947 Log: Early MFC of portions of r243752 adding an auditdistd user to stable/8 in order to ease future upgrades; the remainder of r243752 is left for a future MFC of the OpenBSM upgrade: Merge a number of changes required to hook up OpenBSM 1.2-alpha2's auditdistd (distributed audit daemon) to the build: - Manual cross references - Makefile for auditdistd - rc.d script, rc.conf entrie - New group and user for auditdistd; associated aliases, etc. The audit trail distribution daemon provides reliable, cryptographically protected (and sandboxed) delivery of audit tails from live clients to audit server hosts in order to both allow centralised analysis, and improve resilience in the event of client compromises: clients are not permitted to change trail contents after submission. Submitted by: pjd Sponsored by: The FreeBSD Foundation (auditdistd) Modified: stable/9/etc/ftpusers stable/9/etc/mail/aliases stable/9/etc/master.passwd Modified: stable/9/etc/ftpusers ============================================================================== --- stable/9/etc/ftpusers Thu Dec 6 08:45:43 2012 (r243946) +++ stable/9/etc/ftpusers Thu Dec 6 11:52:31 2012 (r243947) @@ -19,6 +19,7 @@ _pflogd _dhcp uucp pop +auditdistd www hast nobody Modified: stable/9/etc/mail/aliases ============================================================================== --- stable/9/etc/mail/aliases Thu Dec 6 08:45:43 2012 (r243946) +++ stable/9/etc/mail/aliases Thu Dec 6 11:52:31 2012 (r243947) @@ -26,6 +26,7 @@ postmaster: root # General redirections for pseudo accounts _dhcp: root _pflogd: root +auditdistd: root bin: root bind: root daemon: root Modified: stable/9/etc/master.passwd ============================================================================== --- stable/9/etc/master.passwd Thu Dec 6 08:45:43 2012 (r243946) +++ stable/9/etc/master.passwd Thu Dec 6 11:52:31 2012 (r243947) @@ -19,6 +19,7 @@ _pflogd:*:64:64::0:0:pflogd privsep user _dhcp:*:65:65::0:0:dhcp programs:/var/empty:/usr/sbin/nologin uucp:*:66:66::0:0:UUCP pseudo-user:/var/spool/uucppublic:/usr/local/libexec/uucp/uucico pop:*:68:6::0:0:Post Office Owner:/nonexistent:/usr/sbin/nologin +auditdistd:*:78:77::0:0:Auditdistd unprivileged user:/var/empty:/usr/sbin/nologin www:*:80:80::0:0:World Wide Web Owner:/nonexistent:/usr/sbin/nologin hast:*:845:845::0:0:HAST unprivileged user:/var/empty:/usr/sbin/nologin nobody:*:65534:65534::0:0:Unprivileged user:/nonexistent:/usr/sbin/nologin