From owner-cvs-sys Wed Jun 25 04:17:33 1997 Return-Path: Received: (from root@localhost) by hub.freebsd.org (8.8.5/8.8.5) id EAA17279 for cvs-sys-outgoing; Wed, 25 Jun 1997 04:17:33 -0700 (PDT) Received: from ocean.campus.luth.se (ocean.campus.luth.se [130.240.194.116]) by hub.freebsd.org (8.8.5/8.8.5) with ESMTP id EAA17274; Wed, 25 Jun 1997 04:17:22 -0700 (PDT) Received: (from karpen@localhost) by ocean.campus.luth.se (8.8.5/8.8.5) id LAA03564; Wed, 25 Jun 1997 11:18:12 +0200 (CEST) From: Mikael Karpberg Message-Id: <199706250918.LAA03564@ocean.campus.luth.se> Subject: Re: cvs commit: src/sys/kern kern_mib.c In-Reply-To: <199706250731.AAA22382@freefall.freebsd.org> from Joerg Wunsch at "Jun 25, 97 00:31:49 am" To: joerg@FreeBSD.ORG (Joerg Wunsch) Date: Wed, 25 Jun 1997 11:18:12 +0200 (CEST) Cc: cvs-committers@FreeBSD.ORG, cvs-all@FreeBSD.ORG, cvs-sys@FreeBSD.ORG X-Mailer: ELM [version 2.4ME+ PL31H (25)] MIME-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit Sender: owner-cvs-sys@FreeBSD.ORG X-Loop: FreeBSD.org Precedence: bulk According to Joerg Wunsch: > joerg 1997/06/25 00:31:49 PDT > > Modified files: > sys/kern kern_mib.c > Log: > Don't ever allow lowering the securelevel at all. Allowing it does > nothing good except of opening a can of (potential or real) security > holes. People maintaining a machine with higher security requirements > need to be on the console anyway, so there's no point in not forcing > them to reboot before starting maintenance. Being a security fix, will it be tagged into RELENG_2_2 also? /Mikael