From owner-freebsd-questions@freebsd.org Thu Oct 12 20:38:09 2017 Return-Path: Delivered-To: freebsd-questions@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id EDD7DE34170 for ; Thu, 12 Oct 2017 20:38:09 +0000 (UTC) (envelope-from mike@sentex.net) Received: from smarthost2.sentex.ca (smarthost2.sentex.ca [IPv6:2607:f3e0:80:80::2]) (using TLSv1 with cipher DHE-RSA-CAMELLIA256-SHA (256/256 bits)) (Client CN "smarthost.sentex.ca", Issuer "smarthost.sentex.ca" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 8CBDB6643E for ; Thu, 12 Oct 2017 20:38:09 +0000 (UTC) (envelope-from mike@sentex.net) Received: from lava.sentex.ca (lava.sentex.ca [IPv6:2607:f3e0:0:5::11]) by smarthost2.sentex.ca (8.15.2/8.15.2) with ESMTPS id v9CKc8mp076285 (version=TLSv1 cipher=DHE-RSA-CAMELLIA256-SHA bits=256 verify=NO) for ; Thu, 12 Oct 2017 16:38:08 -0400 (EDT) (envelope-from mike@sentex.net) Received: from [192.168.43.26] (saphire3.sentex.net [192.168.43.26]) by lava.sentex.ca (8.15.2/8.15.2) with ESMTP id v9CKc5K6036600; Thu, 12 Oct 2017 16:38:05 -0400 (EDT) (envelope-from mike@sentex.net) Subject: Re: Install-time "hardening" options To: "Ronald F. Guilmette" , freebsd-questions@freebsd.org References: <4436.1507830609@segfault.tristatelogic.com> From: Mike Tancsa Organization: Sentex Communications Message-ID: <21945e9b-6573-5f8d-9b6d-26bbb8bfd748@sentex.net> Date: Thu, 12 Oct 2017 16:38:05 -0400 User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Thunderbird/52.4.0 MIME-Version: 1.0 In-Reply-To: <4436.1507830609@segfault.tristatelogic.com> Content-Type: text/plain; charset=utf-8 Content-Language: en-US Content-Transfer-Encoding: 8bit X-Scanned-By: MIMEDefang 2.78 X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 12 Oct 2017 20:38:10 -0000 On 10/12/2017 1:50 PM, Ronald F. Guilmette wrote: > > (*) Hide processes running as other users > > Well, I mean, yea. Obviously. If you ain't root, then processes > belonging to other users are none of your damn business. So, um, > why is this even optional? One thing to be aware of is if you do any sort of process monitoring via nagios/nrpe, things wont work by default. But yes, a good idea. Just a little extra work for nrpe clients. > (*) Disable opening Syslogd network socket (disables remote logging) Is not the default -s and this options makes it -ss. "disable remote logging" as in the host you are configuring cannot send out messages to other syslogd servers. ---Mike -- ------------------- Mike Tancsa, tel +1 519 651 3400 Sentex Communications, mike@sentex.net Providing Internet services since 1994 www.sentex.net Cambridge, Ontario Canada http://www.tancsa.com/