From owner-freebsd-stable@freebsd.org Wed Sep 23 10:44:56 2015 Return-Path: Delivered-To: freebsd-stable@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id DCD21A07127 for ; Wed, 23 Sep 2015 10:44:56 +0000 (UTC) (envelope-from lists@opsec.eu) Received: from mailman.ysv.freebsd.org (mailman.ysv.freebsd.org [IPv6:2001:1900:2254:206a::50:5]) by mx1.freebsd.org (Postfix) with ESMTP id C9162160F for ; Wed, 23 Sep 2015 10:44:56 +0000 (UTC) (envelope-from lists@opsec.eu) Received: by mailman.ysv.freebsd.org (Postfix) id C8061A07125; Wed, 23 Sep 2015 10:44:56 +0000 (UTC) Delivered-To: stable@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id C7A95A07124 for ; Wed, 23 Sep 2015 10:44:56 +0000 (UTC) (envelope-from lists@opsec.eu) Received: from home.opsec.eu (home.opsec.eu [IPv6:2001:14f8:200::1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 851F8160E for ; Wed, 23 Sep 2015 10:44:56 +0000 (UTC) (envelope-from lists@opsec.eu) Received: from pi by home.opsec.eu with local (Exim 4.86 (FreeBSD)) (envelope-from ) id 1ZehXi-000PLY-S8; Wed, 23 Sep 2015 12:44:54 +0200 Date: Wed, 23 Sep 2015 12:44:54 +0200 From: Kurt Jaeger To: Doug Hardie Cc: FreeBSD Stable ML Subject: Re: when the sshd hits the fan Message-ID: <20150923104454.GG36682@home.opsec.eu> References: <56026686.8030308@norma.perm.ru> <8CC54339-0028-4CE4-9AAD-2248CD4E2FC9@lafn.org> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <8CC54339-0028-4CE4-9AAD-2248CD4E2FC9@lafn.org> X-BeenThere: freebsd-stable@freebsd.org X-Mailman-Version: 2.1.20 Precedence: list List-Id: Production branch of FreeBSD source code List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 23 Sep 2015 10:44:57 -0000 Hi! > > I'm trying to understand why the sshd still starts after local daemons, > > out-of-the-box, and what it takes to make this extremely vital service > > to start before non-system (local) ones. I bet I'm not the first one to > > ask, so why isn't this already done ? Seems quite easy for me. > > The fix is quite simple: Add > > # BEFORE: mail > > to /etc/rc.d/sshd > > I tried to submit a PR on that about a year ago, but it never > seemed to make it into the PR system. It did enter the PR system. https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=190447 I'll have a look at it, it annoys me as well 8-} -- pi@opsec.eu +49 171 3101372 5 years to go !