Subject: Re: Timezone for /etc/security
To: David Brownlee <abs@netbsd.org>
From: Curt Sampson <cjs@cynic.net>
List: tech-userlevel
Date: 10/03/2001 10:37:26
On Tue, 2 Oct 2001, David Brownlee wrote:

> 	Record the TZ somewhere in /var the first time it runs, and reuse
> 	that value.

Doesn't work. TZ is fine for display, but not for data storage. If you
store the timestamp information as an offset time and its timezone,
someone can effectively change the data stored by /etc/security by
changing the contents of a timezone file.

Tell you what: I'll make the change so that we store the information in
UTC, and if someone else thinks its worth the effort, he can add the
code that, when displaying the diffs, will convert the display to the
current timezone.

cjs
-- 
Curt Sampson  <cjs@cynic.net>   +81 3 5778 0123   http://www.netbsd.org
    Don't you know, in this new Dark Age, we're all light.  --XTC