Subject: Re: symlink complaints in /etc/security
To: Curt Sampson <cjs@cynic.net>
From: Perry E.Metzger <perry@piermont.com>
List: tech-security
Date: 12/07/2003 19:34:26
Curt Sampson <cjs@cynic.net> writes:
>> What do people think of my making check_mtree_follow_symlinks=YES the
>> default in security.conf, and changing /etc/localtime in special to
>> "file" so that doesn't bitch?
>
> Yes. Slightly better, perhaps, but also slightly more work, would be to
> have some way of marking files such as /etc/localtime as "should be a
> symlink--do not follow".

We have such a way of marking it already -- that's what "link" in the
special file means already -- but mtree doesn't do the right thing. If
someone could fix that, we would win. Care to take a crack at it?

Perry