Re: Question about securelevel

From: Jim Zajkowski (jim_at_jimz.net)
Date: 02/11/04

  • Next message: Patrick Proniewski: "Re: Question about securelevel"
    Date: Wed, 11 Feb 2004 10:35:07 -0500
    To: freebsd-security@freebsd.org
    
    

    On Feb 11, 2004, at 10:24 AM, roberto@redix.it wrote:

    > Yes I agree with you: a secure system should be read-only fs, but to
    > overcome the drawbacks of a CDROM, I can use a standard hardisk with a
    > read-only file system while securelevel==3. The writable file system
    > should be available in single user mode only on console.

    If I figure out how to make your filesystem remount read-write without
    a reboot, the game is over.

    Running off a CD with a server which has a drive which cannot write
    discs, it doesn't much matter if I figured out how to change the RO
    mount or not, since the media itself cannot be written to [1]. Defense
    in depth.

    --Jim

    [1] I suppose those flash-IDE thingamabobs that have a switch to toggle
    to read-only work just as well here too.

    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"


  • Next message: Patrick Proniewski: "Re: Question about securelevel"

    Relevant Pages

    • Re: Question about securelevel
      ... >> overcome the drawbacks of a CDROM, I can use a standard hardisk with a ... >> should be available in single user mode only on console. ...
      (FreeBSD-Security)
    • Re: Origin 2000 Rack with 2 Modules...
      ... My problem was that I needed to get a good CDROM on the bottom module ... so I swapped the MSC w/Good CDROM from the TOPto the ... But the Rack didn't come up...I didn't even get the console ...
      (comp.sys.sgi.hardware)
    • No console when rebooted into single user mode?
      ... single user mode, they seem to lose their consoles. ... Quick summary is that these two machines when rebooted into single ... the console, as soon as it's time to enter root's password. ...
      (SunManagers)
    • chroot and remove package?
      ... In single user mode, booted from CDROM, I am trying to remove a package that ... ok boot cdrom -s ... Use chroot to run pkgrm and remove unwanted patch. ... Pkgrm: ERROR: no package associated with ...
      (SunManagers)
    • Re: Problem install Sol 9 on Ultra 60. HELP PLS
      ... boot in single user mode and run format/label disk ... >this should boot to single user mode from the CDROM. ... >disks unless they are re-labelled using format. ...
      (comp.sys.sun.hardware)