On Sun, Nov 07, 1999 at 03:53:50AM +0900, Daniel C. Sobral wrote:
> [and, as you said, the same goes for nosuid -- and for nodev too]
>
> This doesn't enhance security. It enhances auditability. I like
> this. Add a syslog, and a sysctl to turn it on or off. It seems
> straight-forward and light-weight. Send the patches. :-)
I quickly wrote the code to do this this evening. Its almost
ready to be contributed.
What should the sysctl ndoes be named? These really implement
similar functionality to net.inet.{tcp|udp}.log_in_vain, but
obviously don't belong under net.
What about something like "kern.audit.*"?
There are probably several other areas that we could increase
the kernel's verbosity, and put the sysctls under there.
Comments? Suggestions?
- Steve
--
C. Stephen Gunn URL: http://www.waterspout.com/
WaterSpout Communications, Inc. Email: [EMAIL PROTECTED]
427 North 6th Street Phone: +1 765.742.6628
Lafayette, IN 47901 Fax: +1 765.742.0646
To Unsubscribe: send mail to [EMAIL PROTECTED]
with "unsubscribe freebsd-hackers" in the body of the message