Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 26 Feb 2016 08:30:01 +0100
From:      Terje Elde <terje@elde.net>
To:        Robert Ayrapetyan <robert.ayrapetyan@gmail.com>
Cc:        freebsd-security@freebsd.org
Subject:   Re: verify FreeBSD installation
Message-ID:  <0977BC22-D5FC-42FB-B75F-455215479F86@elde.net>
In-Reply-To: <56CFE7AE.3080507@gmail.com>
References:  <56CD2EE3.5080009@gmail.com> <A6D06224-5502-4CAC-A88D-951E25466D51@elde.net> <56CFE7AE.3080507@gmail.com>

next in thread | previous in thread | raw e-mail | index | archive | help


> On 26 Feb 2016, at 06:50, Robert Ayrapetyan <robert.ayrapetyan@gmail.com> wrote:
> 
> Yeah, finally I've decided to re-install from an official iso.
> I've found some services in crontab I didn't liked at all - they were submitting a lot of info to a third-party servers (officially for monitoring purposes).
> p.s. Under "instance" I mean a dedicated unmanaged server.

With a dedicated unmanaged, a reinstall would be my preference as well. There's an interesting option for this, called mfsBSD. It can be a bit of hassle to set it up the first time (just a bit), but once it's up, it'll give you an image that you can simply dd onto the harddrive(s), and boot from. It then runs only in memory, no longer dependent on the drives, and allows you to ssh in, and do an install just like you would from a dvd. 

The reason that it can be a slight hassle, is that unless your provider has DHCP, you'd have to configure IP etc in the image, so it'd be able to bring up networking correctly. 

Other options that can be interesting for setups like this, is using geli for disk-encryption. 

Terje




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?0977BC22-D5FC-42FB-B75F-455215479F86>