From owner-freebsd-security@FreeBSD.ORG Tue Jan 22 16:33:33 2008 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 061F616A41A for ; Tue, 22 Jan 2008 16:33:33 +0000 (UTC) (envelope-from wes@opensail.org) Received: from mail6.dotsterhost.com (mail6.dotsterhost.com [72.5.54.120]) by mx1.freebsd.org (Postfix) with SMTP id A0D0713C468 for ; Tue, 22 Jan 2008 16:33:32 +0000 (UTC) (envelope-from wes@opensail.org) Received: (qmail 9734 invoked from network); 22 Jan 2008 16:33:31 -0000 Received: from unknown (HELO scurvy.softweyr.com) (wes@opensail.org@[66.27.101.161]) by 72.5.54.120 with SMTP; 22 Jan 2008 16:33:31 -0000 Message-Id: From: Wes Peters To: =?ISO-8859-1?Q?Dag-Erling_Sm=F8rgrav?= In-Reply-To: <86bq7fntxx.fsf@ds4.des.no> Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: quoted-printable Mime-Version: 1.0 (Apple Message framework v915) Date: Tue, 22 Jan 2008 08:33:30 -0800 References: <20080120120016.6EBDA16A4DF@hub.freebsd.org> <9019C94F-5618-44F3-9590-D63C19A36B60@opensail.org> <86bq7fntxx.fsf@ds4.des.no> X-Mailer: Apple Mail (2.915) Cc: freebsd-security@freebsd.org Subject: Re: ident daemon: oIdentd creating a lot of processes X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 22 Jan 2008 16:33:33 -0000 On Jan 21, 2008, at 6:18 AM, Dag-Erling Sm=F8rgrav wrote: > Wes Peters writes: >> Fabian Wenk writes: >>> Is there a reason why you do not use the identd from FreeBSD itself? >> Alternativey, use 'liedentd' from ports and it won't give away >> information about your users. It also won't create any additional >> processes - I promise. > > uh, inetd's own identd can also be configured to not reveal any > information, and doesn't create any additional processes either, so > what's your upside? Not having to run inetd? No configuration? Simple, easy to audit code? -- Where am I, and what am I doing in this handbasket? Wes Peters = wes@opensail.org