Subject: Re: tcpwrappers
To: NetBSD-Mac68K List <port-mac68k@netbsd.org>
From: Josh Kuperman <josh@saratoga.lib.ny.us>
List: port-mac68k
Date: 02/11/2001 15:18:01
Considering all the daemons in /etc/inetd.conf are commented out to
begin with. a good thing for security. Perhaps the hosts.allow file
should be distributed with commented out examples but have one
uncommented out line:

ALL:ALL:DENY 

which would force uncommenting out or creating a line to allow any
access to any of the inetd daemons. This seems simply consistent with
the philosopy behind not starting up a mess of daemons as the
default. It would also make it cleared that tcpwrappers is built
in. (Which would be a help for people like me who look for refereneces
to tcpd in inetd.conf.)

On Sun, Feb 11, 2001 at 11:33:38AM -0800, Roger Fischer wrote:
> At 12:07 PM -0800 2/10/01, Daniel Parks wrote:
> >I haven't tried it with tcpwrappers yet, as I didn't
> >realize that it was built in to inetd.
> 
> Hmmm, after the previous discussions about TCP Wrappers, maybe
> the etc.tgz set should contain skeleton /etc/hosts.allow and
> /etc/hosts.deny files that contain some comments and no entries?
> 
> comments?
> 
> - Roger
> 

-- 
Josh Kuperman                       
josh@saratoga.lib.ny.us