Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 21 May 2004 13:24:56 +0000 (UTC)
From:      "Bjoern A. Zeeb" <bzeeb-lists@lists.zabbadoz.net>
To:        Ruslan Ermilov <ru@freebsd.org>
Cc:        freebsd-current@freebsd.org
Subject:   Re: Call for a hacker.... security.bsd.see_other_uids in jails only
Message-ID:  <Pine.BSF.4.53.0405211323440.58123@e0-0.zab2.int.zabbadoz.net>
In-Reply-To: <20040521090217.GB57989@ip.net.ua>
References:  <20040520220145.GN4567@genius.tao.org.uk> <20040521081419.GB89262@cell.sick.ru> <20040521090217.GB57989@ip.net.ua>

next in thread | previous in thread | raw e-mail | index | archive | help
On Fri, 21 May 2004, Ruslan Ermilov wrote:

> > A more general solution will be better, but harder to implement: make
> > some sysctl branches (e.g. security.bsd) local per jail, and possibility to
> > change them only from host machine.
> >
> I like the idea of per-jail sysctl MIB trees, e.g.:
>
> jail.<JID>.security.bsd

jail ID is not too good; we would need s.th. that could be treated
'perstistent' between reboots.

Perhaps not use sysctl at all ...

-- 
Bjoern A. Zeeb				bzeeb at Zabbadoz dot NeT

there is no 'do you really want to quit ?'-button in RL.



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.BSF.4.53.0405211323440.58123>