From owner-cvs-ports@FreeBSD.ORG Wed Jun 27 18:39:36 2012 Return-Path: Delivered-To: cvs-ports@FreeBSD.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 5C32F106567B; Wed, 27 Jun 2012 18:39:36 +0000 (UTC) (envelope-from hilko.meyer@gmx.de) Received: from kirk.hochpass.uni-hannover.de (kirk.hochpass.uni-hannover.de [130.75.81.215]) by mx1.freebsd.org (Postfix) with ESMTP id E68238FC18; Wed, 27 Jun 2012 18:39:35 +0000 (UTC) Received: from ROGERS.hochpass.uni-hannover.de (rogers.hochpass.uni-hannover.de [130.75.81.217]) by kirk.hochpass.uni-hannover.de (8.14.4/8.14.4) with SMTP id q5RIdSZU036287; Wed, 27 Jun 2012 20:39:28 +0200 (CEST) (envelope-from hilko.meyer@gmx.de) From: Hilko Meyer To: Xin LI Date: Wed, 27 Jun 2012 20:39:27 +0200 Message-ID: References: <201206270022.q5R0Mt8X097020@repoman.freebsd.org> In-Reply-To: <201206270022.q5R0Mt8X097020@repoman.freebsd.org> X-Mailer: Forte Agent 1.93/32.576 English (American) MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: 7bit Cc: cvs-ports@FreeBSD.org Subject: Re: cvs commit: ports/security/sshguard Makefile ports/security/sshguard/files pkg-message.in sshguard.in X-BeenThere: cvs-ports@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: CVS commit messages for the ports tree List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 27 Jun 2012 18:39:36 -0000 Hi On Wed, 27 Jun 2012 00:22:55 +0000 (UTC), in gmane.os.freebsd.devel.cvs you wrote: >delphij 2012-06-27 00:22:55 UTC > > FreeBSD ports repository > > Modified files: > security/sshguard Makefile > security/sshguard/files pkg-message.in > Added files: > security/sshguard/files sshguard.in > Log: > Add a rc.d script to daemonize sshguard. Thanks for adding a rc.d script for sshguard making it unnecessary to edit syslog.conf after every update. But after looking to the script I see some problems. We are using this command: | auth.info;authpriv.info |exec /usr/local/sbin/sshguard -p 4200 -s 3600 -w 1.2.3.4/26 >From my understanding the rc.d script expects only a filename for whitelisting. But via the -w command-line option it is possible to add explicit addresses, host names, address blocks or a file name. Also the script enables permanent blacklisting unconditionally without an option to disable it. regards, Hilko