From owner-freebsd-questions@FreeBSD.ORG Sat Sep 24 01:28:53 2005 Return-Path: X-Original-To: freebsd-questions@freebsd.org Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id A47D116A41F for ; Sat, 24 Sep 2005 01:28:53 +0000 (GMT) (envelope-from malachid@gmail.com) Received: from zproxy.gmail.com (zproxy.gmail.com [64.233.162.193]) by mx1.FreeBSD.org (Postfix) with ESMTP id 3513743D48 for ; Sat, 24 Sep 2005 01:28:53 +0000 (GMT) (envelope-from malachid@gmail.com) Received: by zproxy.gmail.com with SMTP id f1so489598nzc for ; Fri, 23 Sep 2005 18:28:52 -0700 (PDT) DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=beta; d=gmail.com; h=received:message-id:date:from:reply-to:to:subject:cc:in-reply-to:mime-version:content-type:references; b=UmKK6LeDv9UkZpge64KDV2zi1cka71qhYkGlm/99RVB0yUrYckjk+zDb0Ovph5qLPewru6PEraevpPNBpVU2FFEXrWBTLC6r9U+a9wJ7ag2DdKEZ8WcRG37SBkWZ65FHOmosHTXjHRU3uSkM+SLa592oQ+UaYUWrcRYXvpEYXbU= Received: by 10.54.49.21 with SMTP id w21mr4179921wrw; Fri, 23 Sep 2005 18:28:52 -0700 (PDT) Received: by 10.54.79.1 with HTTP; Fri, 23 Sep 2005 18:28:52 -0700 (PDT) Message-ID: Date: Fri, 23 Sep 2005 18:28:52 -0700 From: =?ISO-8859-1?Q?Malachi_de_=C6lfweald?= To: sd In-Reply-To: <43341EB2.1050306@buc.com.ua> MIME-Version: 1.0 References: <20050923120059.2A61F16A421@hub.freebsd.org> <43341EB2.1050306@buc.com.ua> Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable Content-Disposition: inline X-Content-Filtered-By: Mailman/MimeDel 2.1.5 Cc: freebsd-questions@freebsd.org Subject: Re: Requesting advice on Jail technique. X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list Reply-To: =?ISO-8859-1?Q?Malachi_de_=C6lfweald?= List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 24 Sep 2005 01:28:53 -0000 I would like to provide as complete of a system as possible to the jail/domain owners.... What specifically do I need to ensure they DON'T hav= e access to? And if I give them access to the ports collection, how do I prevent them from just installing said binaries anyways? Another thing I was thinking... if I go forward with the unionfs, say, for the ports collection itself -- each jail could have their own configuration files, etc... but should I make the distfiles directory get updated so that we don't get huge amounts of that space replicated? Malachi