From owner-freebsd-security@freebsd.org Fri Feb 26 07:30:14 2016 Return-Path: Delivered-To: freebsd-security@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 3BED0AB4690 for ; Fri, 26 Feb 2016 07:30:14 +0000 (UTC) (envelope-from terje@elde.net) Received: from rand.keepquiet.net (keepquiet.net [144.76.43.178]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client CN "keepquiet.net", Issuer "COMODO RSA Domain Validation Secure Server CA" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 06F48187F for ; Fri, 26 Feb 2016 07:30:12 +0000 (UTC) (envelope-from terje@elde.net) Received: from [10.96.74.209] (2.150.20.162.tmi.telenormobil.no [2.150.20.162]) (using TLSv1 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) (Authenticated sender: terje@elde.net) by rand.keepquiet.net (Postfix) with ESMTPSA id 4CF5BAD0; Fri, 26 Feb 2016 07:30:03 +0000 (UTC) Content-Type: text/plain; charset=us-ascii Mime-Version: 1.0 (1.0) Subject: Re: verify FreeBSD installation From: Terje Elde X-Mailer: iPhone Mail (13D20) In-Reply-To: <56CFE7AE.3080507@gmail.com> Date: Fri, 26 Feb 2016 08:30:01 +0100 Cc: freebsd-security@freebsd.org Content-Transfer-Encoding: quoted-printable Message-Id: <0977BC22-D5FC-42FB-B75F-455215479F86@elde.net> References: <56CD2EE3.5080009@gmail.com> <56CFE7AE.3080507@gmail.com> To: Robert Ayrapetyan X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.20 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 26 Feb 2016 07:30:14 -0000 > On 26 Feb 2016, at 06:50, Robert Ayrapetyan w= rote: >=20 > Yeah, finally I've decided to re-install from an official iso. > I've found some services in crontab I didn't liked at all - they were subm= itting a lot of info to a third-party servers (officially for monitoring pur= poses). > p.s. Under "instance" I mean a dedicated unmanaged server. With a dedicated unmanaged, a reinstall would be my preference as well. Ther= e's an interesting option for this, called mfsBSD. It can be a bit of hassle= to set it up the first time (just a bit), but once it's up, it'll give you a= n image that you can simply dd onto the harddrive(s), and boot from. It then= runs only in memory, no longer dependent on the drives, and allows you to s= sh in, and do an install just like you would from a dvd.=20 The reason that it can be a slight hassle, is that unless your provider has D= HCP, you'd have to configure IP etc in the image, so it'd be able to bring u= p networking correctly.=20 Other options that can be interesting for setups like this, is using geli fo= r disk-encryption.=20 Terje