From owner-freebsd-questions@FreeBSD.ORG Tue May 9 14:32:23 2006 Return-Path: X-Original-To: freebsd-questions@freebsd.org Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 286CE16A404 for ; Tue, 9 May 2006 14:32:23 +0000 (UTC) (envelope-from erikt@owl.midgard.homeip.net) Received: from pne-smtpout2-sn1.fre.skanova.net (pne-smtpout2-sn1.fre.skanova.net [81.228.11.159]) by mx1.FreeBSD.org (Postfix) with ESMTP id 6A6A843D49 for ; Tue, 9 May 2006 14:32:22 +0000 (GMT) (envelope-from erikt@owl.midgard.homeip.net) Received: from falcon.midgard.homeip.net (83.253.29.241) by pne-smtpout2-sn1.fre.skanova.net (7.2.072.1) id 4460A18400002670 for freebsd-questions@freebsd.org; Tue, 9 May 2006 16:32:21 +0200 Received: (qmail 5722 invoked from network); 9 May 2006 16:32:20 +0200 Received: from owl.midgard.homeip.net (10.1.5.7) by falcon.midgard.homeip.net with SMTP; 9 May 2006 16:32:20 +0200 Received: (qmail 31259 invoked by uid 1001); 9 May 2006 16:32:20 +0200 Date: Tue, 9 May 2006 16:32:20 +0200 From: Erik Trulsson To: "No@SPAM@mgEDV.net" Message-ID: <20060509143220.GA31226@owl.midgard.homeip.net> Mail-Followup-To: "No@SPAM@mgEDV.net" , freebsd-questions@freebsd.org References: <000a01c67362$f3d1f3d0$01010101@avalon.lan> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <000a01c67362$f3d1f3d0$01010101@avalon.lan> User-Agent: Mutt/1.5.11 Cc: freebsd-questions@freebsd.org Subject: Re: kern.randompid: jot generation senseful? X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 09 May 2006 14:32:23 -0000 On Tue, May 09, 2006 at 02:20:25PM +0200, No@SPAM@mgEDV.net wrote: > [asked on -security before, but no answer, maybe here's more traffic ;-)] > > hi, > > is a random pid generation really a security enhancement? Yes, but a fairly minor one. > > if yes, would it make sense to setup something like: > --> sysctl kern.randompid=`jot -r 1 500 2000` > in cron to be executed every X mins/hrs? No, that would not make any sense. What would you be expecting to achieve by that? > > and finally, what are the recommended minimum (security) > and maximum (performance) values for kern.randompid? -- Erik Trulsson ertr1013@student.uu.se