On Sun, Nov 07, 1999 at 03:53:50AM +0900, Daniel C. Sobral wrote:

> [and, as you said, the same goes for nosuid -- and for nodev too]
> 
> This doesn't enhance security. It enhances auditability. I like
> this. Add a syslog, and a sysctl to turn it on or off. It seems
> straight-forward and light-weight. Send the patches. :-)

I quickly wrote the code to do this this evening.  Its almost
ready to be contributed.

What should the sysctl ndoes be named?  These really implement
similar functionality to net.inet.{tcp|udp}.log_in_vain, but
obviously don't belong under net.

What about something like "kern.audit.*"?

There are probably several other areas that we could increase
the kernel's verbosity, and put the sysctls under there.

Comments? Suggestions?

 - Steve

--
C. Stephen Gunn                          URL: http://www.waterspout.com/
WaterSpout Communications, Inc.        Email: [EMAIL PROTECTED]
427 North 6th Street                   Phone: +1 765.742.6628
Lafayette, IN  47901                     Fax: +1 765.742.0646


To Unsubscribe: send mail to [EMAIL PROTECTED]
with "unsubscribe freebsd-hackers" in the body of the message

Reply via email to