OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Pekka Savola (pekkasnetcore.fi)
Date: Fri Nov 30 2001 - 08:50:22 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    On Fri, 30 Nov 2001, Matthew Kirkwood wrote:
    > Clearly wait/nowait, stream/dgram, and unix/ipv4/ipv6/raw
    > services are non-optional.

    Definitely IPv6 support.

    > I am not an big fan of rate limiting, complex access-control
    > or internal services.

    Tcpwrappers should be enough for access control. Rate limiting as
    suggested by Solar Designer (e.g. X connections in Y time per /Z netblock)
    might be nice, but definitely not a requirement.

    > Is the BSD inetd's feature set really too small for modern use?

    I'm pretty satisfied with what's in FreeBSD, basically. One thing is
    essential for administration -- the possibility to use xinetd-like
    /etc/inet.d/ directory (for easy disabling/enabling and adding/removing of
    services by package managers).

    -- 
    Pekka Savola                 "Tell me of difficulties surmounted,
    Netcore Oy                   not those you stumble over and fall"
    Systems. Networks. Security.  -- Robert Jordan: A Crown of Swords