Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 1 Aug 2001 19:19:56 -0700 (PDT)
From:      Robert Watson <rwatson@FreeBSD.org>
To:        cvs-committers@FreeBSD.org, cvs-all@FreeBSD.org
Subject:   cvs commit: src/etc inetd.conf
Message-ID:  <200108020219.f722Jun16596@freefall.freebsd.org>

next in thread | raw e-mail | index | archive | help
rwatson     2001/08/01 19:19:56 PDT

  Modified files:
    etc                  inetd.conf 
  Log:
  Default to disabling all inetd.conf entries, in particular, telnetd
  and ftpd.  This more conservative default reduces the exposure of
  freshly installed machines, which is especially valuable for machines
  that receive minimal further configuration before being put into
  production.  Generally speaking, SSH has superseded the use of both
  telnet and ftp in many environments.  In light of recent remotely
  exploitable security holes in both telnetd and ftpd, this choice
  retains flexibility (both telnetd and ftpd daemons remain installed
  and easily enableable) while protecting users who don't need the
  additional risk.  This change brings our configuration into line with
  the majority of other UNIX vendors, including OpenBSD and NetBSD.
  
  To address the concerns of those requiring remote access via telnet
  from first install, changes will shortly be committed to sysinstall
  to provide the ability to edit inetd.conf during the installation
  process, allowing telnetd and ftp to be re-enabled during the
  installation process.
  
  While I'm at it, slightly improve commenting for inetd.conf so that
  it's more clear to users how to enable and disable services.
  Further commenting to indicate the functions of various columns would
  probably also be useful.
  
  Reviewed by:	imp, chris, jake, nate, -arch, -stable
  
  Revision  Changes    Path
  1.49      +13 -8     src/etc/inetd.conf


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe cvs-all" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?200108020219.f722Jun16596>