From owner-freebsd-questions@FreeBSD.ORG Tue May 9 13:19:10 2006 Return-Path: X-Original-To: freebsd-questions@freebsd.org Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id EA0F416A42C for ; Tue, 9 May 2006 13:19:10 +0000 (UTC) (envelope-from jahilliya@gmail.com) Received: from wr-out-0506.google.com (wr-out-0506.google.com [64.233.184.233]) by mx1.FreeBSD.org (Postfix) with ESMTP id C6B6443D5A for ; Tue, 9 May 2006 13:18:54 +0000 (GMT) (envelope-from jahilliya@gmail.com) Received: by wr-out-0506.google.com with SMTP id 69so1156264wra for ; Tue, 09 May 2006 06:18:53 -0700 (PDT) DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=beta; d=gmail.com; h=received:message-id:date:from:to:subject:cc:in-reply-to:mime-version:content-type:references; b=Apgsm7Nv7rKlKWXOQSrt6Q0ymkO17/bTPK8FewmHQl2APfNNN5DBwiz6JG5Z1xEVi3oLFooe467D+a/D+aT+Z4PNgfVuhWikpO/eIbdnq05njzurf36oRLRx0iKMbZ3y+T3vdWPFYDoh3dUykU2m3G/HaNZBDrqo/ycnQIP2kBs= Received: by 10.54.124.5 with SMTP id w5mr1536518wrc; Tue, 09 May 2006 06:18:53 -0700 (PDT) Received: by 10.54.134.2 with HTTP; Tue, 9 May 2006 06:18:53 -0700 (PDT) Message-ID: Date: Tue, 9 May 2006 21:18:53 +0800 From: Jahilliya To: nospam@mgedv.net In-Reply-To: <000a01c67362$f3d1f3d0$01010101@avalon.lan> MIME-Version: 1.0 References: <000a01c67362$f3d1f3d0$01010101@avalon.lan> Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: quoted-printable Content-Disposition: inline X-Content-Filtered-By: Mailman/MimeDel 2.1.5 Cc: freebsd-questions@freebsd.org Subject: Re: kern.randompid: jot generation senseful? X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 09 May 2006 13:19:13 -0000 On 5/9/06, No@SPAM@mgEDV.net wrote: > > [asked on -security before, but no answer, maybe here's more traffic ;-)] > > hi, > > is a random pid generation really a security enhancement? > > if yes, would it make sense to setup something like: > --> sysctl kern.randompid=3D`jot -r 1 500 2000` > in cron to be executed every X mins/hrs? > > and finally, what are the recommended minimum (security) > and maximum (performance) values for kern.randompid? You can't change it once the system is running me thinks, so you'd run it a= t boot and that'd be that...