From owner-freebsd-security@FreeBSD.ORG Wed Feb 11 07:13:16 2004 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id E0A6916A4DD for ; Wed, 11 Feb 2004 07:13:16 -0800 (PST) Received: from redix.it (host49-169.pool8172.interbusiness.it [81.72.169.49]) by mx1.FreeBSD.org (Postfix) with SMTP id 2996543D2F for ; Wed, 11 Feb 2004 07:13:12 -0800 (PST) (envelope-from roberto@redix.it) Received: (qmail 25615 invoked by uid 72); 11 Feb 2004 15:13:05 -0000 Received: from 192.168.0.77 (SquirrelMail authenticated user roberto) by mail.redix.it with HTTP; Wed, 11 Feb 2004 16:13:05 +0100 (CET) Message-ID: <1293.192.168.0.77.1076512385.squirrel@mail.redix.it> In-Reply-To: References: <1171.192.168.0.77.1076505166.squirrel@mail.redix.it> Date: Wed, 11 Feb 2004 16:13:05 +0100 (CET) From: roberto@redix.it To: "Nigel Houghton" User-Agent: SquirrelMail/1.4.2 MIME-Version: 1.0 Content-Type: text/plain;charset=iso-8859-1 Content-Transfer-Encoding: 8bit X-Priority: 3 Importance: Normal cc: freebsd-security@freebsd.org Subject: Re: Question about securelevel X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Security issues [members-only posting] List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 11 Feb 2004 15:13:17 -0000 > > Change the "console" line in /etc/ttys from "secure" to "insecure", that > will make your administrator enter the root password when booting to > single user. > > When using securelevel, you might also want to use a script to set the > immutable flag on various parts of the file system. > > There's also much more to securing a box than just using securelevel. > 1- OK I've already set console to insecure, I do not like the single user mode offer a shell without password. 2- But instead of set the immutable flags over several files, seems to me more simple (and not error prone) to set the root file system read-only (simple to do) and to find a way it could not be remounted rw while securelevel == 3! 3- OK agree with you: there's also much more to securing a box than just using securelevel, but using a securelevel+readonly file system, is a step foreward in security? Regards Roberto