From owner-freebsd-questions@FreeBSD.ORG Tue Jul 19 14:32:51 2011 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id A7A66106564A for ; Tue, 19 Jul 2011 14:32:51 +0000 (UTC) (envelope-from nec556@retena.com) Received: from resmaa13.ono.com (smtp13.ono.com [62.42.230.16]) by mx1.freebsd.org (Postfix) with ESMTP id 365478FC08 for ; Tue, 19 Jul 2011 14:32:50 +0000 (UTC) Received: from GogPortatil.retena.com (188.76.0.243) by resmaa13.ono.com (8.5.113) (authenticated as nec556@retena.com) id 4D6348DC01AE3AC4 for freebsd-questions@freebsd.org; Tue, 19 Jul 2011 16:32:49 +0200 Message-ID: <4D6348DC01AE3AC4@> (added by postmaster@resmaa13.ono.com) X-Mailer: QUALCOMM Windows Eudora Version 7.1.0.9 Date: Tue, 19 Jul 2011 13:54:45 +0200 To: freebsd-questions@freebsd.org From: Eduardo Morras In-Reply-To: <4E254C5D.3030501@dichotomia.fr> References: <20110717071059.25971662@scorpio> <4E22DFE9.7050007@pathscale.com> <201107172016.30727.lobo@bsd.com.br> <4E23989F.7010701@gmail.com> <4e242fab.s4vpgxxZEUq0LFDq%perryh@pluto.rain.com> <1311017168.44397.YahooMailRC@web36508.mail.mud.yahoo.com> <23159_1311031267_4E24BFE3_23159_38_1_D9B37353831173459FDAA836D3B43499C5218659@WADPMBXV0.waddell.com> <4E24C416.9020207@dichotomia.fr> <20110719081116.3fdf3ef1.freebsd@edvax.de> <4E254C5D.3030501@dichotomia.fr> Mime-Version: 1.0 Content-Type: text/plain; charset="us-ascii"; format=flowed X-Antivirus: AVG for E-mail 10.0.1390 [1518/3773] Subject: Re: Lennart Poettering: BSD Isn't Relevant Anymore X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 19 Jul 2011 14:32:51 -0000 At 11:20 19/07/2011, Jerome Herman wrote: >>>A FreeBSD distro with LDAP, ACL and MAC management would be nice though. >>You could create a port that brings all this functionality >>in one rush. Remember that the ports collection is more than >>just about installing software - it can be used to even >>bring such features to the system and configure them. >A port that would reboot in single user, use tunefs to activate ACL >here and there, activate MAC and move most users to an LDAP auth ? I >don't think so. >Actually I would be scared if such a port was accepted in the port tree. Perhaps a jail based distribution, the port creates a jail, sets acl and mac on a new dedicated disk/slice/partition/mount point/whatever and moves users to the ldap. Currently FreeNAS, pfsense, nor monowall don't allow installation in a jail, it could be great.