Subject: Re: Chapter 8 security
To: NetBSD Security Technical Discussion List <tech-security@NetBSD.ORG>
From: Jan Schaumann <jschauma@netmeister.org>
List: current-users
Date: 04/18/2004 22:19:44
--vs0rQTeTompTJjtd
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable
Luke Mewburn <lukem@NetBSD.org> wrote:
> On Sun, Apr 18, 2004 at 02:54:34PM -0400, Greg A. Woods wrote:
> | The /etc/security support of /var/backups should even be sufficient f=
or
> | the purposes of auditing "all system changes", and even the granulari=
ty
> | can be adjusted as necessary; though perhaps a well planned and deplo=
yed
> | tripwire install (or similar scheme, e.g. with mtree) would be even
> | better.....
>=20
> NetBSD 2.0 has /etc/mtree/set.*, which contains the mtree information
> including permissions and SHA1 hashes for all the files in the given set.
Uuuh, it does? Neat! I was not aware. We should publish the hashes
for each future release so that people can easily verify the integrity
of their binaries.
-Jan
--=20
If you are undertaking anything substantial, C is the only reasonable choice
of programming language.
-- UNIX User's Supplementary Documents
--vs0rQTeTompTJjtd
Content-Type: application/pgp-signature
Content-Disposition: inline
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.3 (NetBSD)
iD8DBQFAgzdAfFtkr68iakwRAnd2AJ9eELS8DsfJCxKOWz5tj3+R1rMeVwCfT1DX
1v1FYDAAtT8KeuTeDPt8tU0=
=c9rL
-----END PGP SIGNATURE-----
--vs0rQTeTompTJjtd--