Subject: Re: Chapter 8 security
To: NetBSD Security Technical Discussion List <tech-security@NetBSD.ORG>
From: Jan Schaumann <jschauma@netmeister.org>
List: current-users
Date: 04/18/2004 22:19:44
--vs0rQTeTompTJjtd
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

Luke Mewburn <lukem@NetBSD.org> wrote:
> On Sun, Apr 18, 2004 at 02:54:34PM -0400, Greg A. Woods wrote:
>   | The /etc/security support of /var/backups should even be sufficient f=
or
>   | the purposes of auditing "all system changes", and even the granulari=
ty
>   | can be adjusted as necessary; though perhaps a well planned and deplo=
yed
>   | tripwire install (or similar scheme, e.g. with mtree) would be even
>   | better.....
>=20
> NetBSD 2.0 has /etc/mtree/set.*, which contains the mtree information
> including permissions and SHA1 hashes for all the files in the given set.

Uuuh, it does?  Neat!  I was not aware.  We should publish the hashes
for each future release so that people can easily verify the integrity
of their binaries.

-Jan

--=20
If you are undertaking anything substantial, C is the only reasonable choice
of programming language.
	-- UNIX User's Supplementary Documents

--vs0rQTeTompTJjtd
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.3 (NetBSD)

iD8DBQFAgzdAfFtkr68iakwRAnd2AJ9eELS8DsfJCxKOWz5tj3+R1rMeVwCfT1DX
1v1FYDAAtT8KeuTeDPt8tU0=
=c9rL
-----END PGP SIGNATURE-----

--vs0rQTeTompTJjtd--