From owner-freebsd-stable Thu Feb 22 18:16:35 2001 Delivered-To: freebsd-stable@freebsd.org Received: from obsecurity.dyndns.org (adsl-64-165-226-53.dsl.lsan03.pacbell.net [64.165.226.53]) by hub.freebsd.org (Postfix) with ESMTP id A426337B401 for ; Thu, 22 Feb 2001 18:16:31 -0800 (PST) (envelope-from kris@obsecurity.org) Received: by obsecurity.dyndns.org (Postfix, from userid 1000) id A0D9466C34; Thu, 22 Feb 2001 18:16:30 -0800 (PST) Date: Thu, 22 Feb 2001 18:16:30 -0800 From: Kris Kennaway To: "Albert Everett, Web International Inc." Cc: freebsd-stable@freebsd.org Subject: Re: Xserver won't start Message-ID: <20010222181630.A11548@mollari.cthul.hu> References: <20010221210050.G66731@mollari.cthul.hu>; <20010221194958.A41180@telocity.com> <20010222135643.A92188@nihilist.org> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-md5; protocol="application/pgp-signature"; boundary="5mCyUwZo2JvN/JJP" Content-Disposition: inline User-Agent: Mutt/1.2.5i In-Reply-To: ; from aeverett@webintl.com on Thu, Feb 22, 2001 at 04:56:20PM -0600 Sender: owner-freebsd-stable@FreeBSD.ORG Precedence: bulk X-Loop: FreeBSD.ORG --5mCyUwZo2JvN/JJP Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Thu, Feb 22, 2001 at 04:56:20PM -0600, Albert Everett, Web International= Inc. wrote: > Amen. >=20 > >On Wed, Feb 21, 2001 at 09:00:50PM -0800, Kris Kennaway wrote: > >> > >> Don't do this; install the Xwrapper port instead -- the setuid bit was > >> removed from the XFree86 in favour of the Xwrapper port for a reason > >> (improved security). > > > >So why not make the XFree86-4 port depend on Xwrapper so confusion > >like this can be avoided? Because if you run X via xdm/kdm/wdm/etc you don't need it, and even having Xwrapper doesn't completely remove the security risk (you still have a setuid root binary which can only remove some potential sources of exploit). Read the message which explains this when you install XFree86-4, please. Kris --5mCyUwZo2JvN/JJP Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.4 (FreeBSD) Comment: For info see http://www.gnupg.org iD8DBQE6lcf+Wry0BWjoQKURAi6sAJ9w7O3FIdyJDhYPQw3AfTw3KqeqJgCfTszz WQrm/P19SUknIQG1O6ao99k= =aomL -----END PGP SIGNATURE----- --5mCyUwZo2JvN/JJP-- To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-stable" in the body of the message