From owner-freebsd-questions@FreeBSD.ORG Sun Feb 11 14:08:10 2007 Return-Path: X-Original-To: freebsd-questions@freebsd.org Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [69.147.83.52]) by hub.freebsd.org (Postfix) with ESMTP id 612FA16A401 for ; Sun, 11 Feb 2007 14:08:10 +0000 (UTC) (envelope-from wmoran@collaborativefusion.com) Received: from mx00.pub.collaborativefusion.com (mx00.pub.collaborativefusion.com [206.210.89.199]) by mx1.freebsd.org (Postfix) with ESMTP id 107CE13C474 for ; Sun, 11 Feb 2007 14:08:09 +0000 (UTC) (envelope-from wmoran@collaborativefusion.com) Received: from working (c-71-60-174-60.hsd1.pa.comcast.net [71.60.174.60]) (AUTH: LOGIN wmoran, TLS: TLSv1/SSLv3,256bits,AES256-SHA) by wingspan with esmtp; Sun, 11 Feb 2007 09:08:09 -0500 id 00056405.45CF2349.00003A8C Date: Sun, 11 Feb 2007 09:08:07 -0500 From: Bill Moran To: Dino Vliet Message-Id: <20070211090807.8376601f.wmoran@collaborativefusion.com> In-Reply-To: <700107.12325.qm@web51115.mail.yahoo.com> References: <700107.12325.qm@web51115.mail.yahoo.com> Organization: Collaborative Fusion Inc. X-Mailer: Sylpheed version 2.2.10 (GTK+ 2.10.6; i386-portbld-freebsd6.2) Mime-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit Cc: freebsd-questions@freebsd.org Subject: Re: jail question X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 11 Feb 2007 14:08:10 -0000 Dino Vliet wrote: > > Hi folks, > > I'm installing a nice system to use as my multimedia > box and already succeeded with geom-mirror. I want to > use a jail to isolate the p2p applications like > amule/emule and want to make sure that they only write > to an encrypted disk (currently RTFM on geli and gbde) > > However, I was wondering what happens with a jail if I > update the host system due to a security issue or > something else (recompile kernel and install world). > Do I need to define the jail again? If not, won't the > files in the jail stay at their previous versions > although the host system has been updated to a new > version? Yes, that is a problem you have to deal with. Have a look at the ezjail port, which makes this a lot easier to deal with. -Bill