From owner-freebsd-questions Mon Nov 26 6:28:20 2001 Delivered-To: freebsd-questions@freebsd.org Received: from dire.bris.ac.uk (dire.bris.ac.uk [137.222.10.60]) by hub.freebsd.org (Postfix) with ESMTP id 2489D37B41A for ; Mon, 26 Nov 2001 06:28:16 -0800 (PST) Received: from mail.ilrt.bris.ac.uk by dire.bris.ac.uk with SMTP-PRIV with ESMTP; Mon, 26 Nov 2001 14:28:09 +0000 Received: from cmjg (helo=localhost) by mail.ilrt.bris.ac.uk with local-esmtp (Exim 3.16 #1) id 168MiJ-0003XD-00; Mon, 26 Nov 2001 14:26:27 +0000 Date: Mon, 26 Nov 2001 14:26:26 +0000 (GMT) From: Jan Grant X-X-Sender: To: Anthony Atkielski Cc: FreeBSD Questions Subject: Re: What is the best secure_level setting? In-Reply-To: <00c201c17681$91287110$0a00000a@atkielski.com> Message-ID: MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII Sender: owner-freebsd-questions@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.ORG On Mon, 26 Nov 2001, Anthony Atkielski wrote: > I am looking at secure_level in FreeBSD and wondering what setting is > appropriate. The default seems to be the lowest possible setting of -1, but I > don't see any obvious reason why I can't run at +1. What levels do you all run > your systems at normally? > > I've already been warned that X servers won't run on a machine at > secure_level=1, but for me that's just another reason not to use X servers on > the host machine, not a reason to keep the secure_level lower. As always, it depends on your intended use for the system. There's additional frustration to work around when updating your system at a higher secure level, but this is pretty irrelevant if you're sitting at the console. "As high as is convenient" is the right number to use, where "convenience" includes a risk assessment in the case of a system compromise. -- jan grant, ILRT, University of Bristol. http://www.ilrt.bris.ac.uk/ Tel +44(0)117 9287088 Fax +44 (0)117 9287112 RFC822 jan.grant@bris.ac.uk Leverage that synergy! Ooh yeah, looking good! Now stretch - and relax. To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-questions" in the body of the message