OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: Question about securelevel

robertoredix.it
Date: Wed Feb 11 2004 - 08:28:25 CST


>
> you do not need to go single user to change it. just remove the
> securelevel lines from /etc/rc.conf and reboot.
>
> greetings,
> tilo
>

As said, the root filesystem is read-only and the command "mount -uw /"
should be in disabled when securelevel==3, in my ideal kernel.

Actually the command "mount -uw /" will succeded when the securelevel==3,
but supposing should be not so difficult to change the FreeBSD kernel,
this (securelevel+readonly filesystem) could address the weakness of
securelevel+non-read-only filesystem.

Regards
Roberto

_______________________________________________
freebsd-securityfreebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribefreebsd.org"