Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 6 Dec 2000 10:59:55 -0500 (EST)
From:      Matt Heckaman <matt@ARPA.MAIL.NET>
To:        mouss <usebsd@free.fr>
Cc:        FreeBSD-SECURITY <freebsd-security@FreeBSD.ORG>
Subject:   Re: [spam score 10.00/10.0 -pobox] Re: Fw:      NAPTHA  Advisory Updated - BindView RAZOR
Message-ID:  <Pine.BSF.4.21.0012061057230.76215-100000@epsilon.lucida.ca>
In-Reply-To: <4.3.0.20001206150604.05998d30@pop.free.fr>

next in thread | previous in thread | raw e-mail | index | archive | help
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Wed, 6 Dec 2000, mouss wrote:

: isn't enough to create an account for each server or group of servers,
: and use login.conf for the users?

For some things yes, but not for most. The daemons that must run as root?
It would be somewhat detrimental to put a restrictive fd limit on root. I
can picture finding a problem, switching to root, and not being able to
type a command because it's out of procs. :)

* Matt Heckaman   - mailto:matt@lucida.qc.ca  http://www.lucida.qc.ca/ *
* GPG fingerprint - A9BC F3A8 278E 22F2 9BDA  BFCF 74C3 2D31 C035 5390 *

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.4 (FreeBSD)
Comment: http://www.lucida.qc.ca/pgp

iD8DBQE6LmJ9dMMtMcA1U5ARAhFzAJ9ZpbjwvvJf1ofXpTZI+bI0MClFHgCffhDu
QWpcBaJYACBD37A5791nLzk=
=WkjR
-----END PGP SIGNATURE-----




To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.BSF.4.21.0012061057230.76215-100000>