Change default to "restrict default kod limited nomodify nopeer noquery"

2016-12-12 Thread Hal Murray
> I like it, and learn towards saying yes. Let's see what Hal and others say. I'm happy to change the default, but I think we need some text that explains why. The old noquery was there to fix a DDoS amplification attack using the old monlist. That's not possible any more, but there

Re: Change default to "restrict default kod limited nomodify nopeer noquery"

2016-12-10 Thread Gary E. Miller
Yo Mark! On Sat, 10 Dec 2016 20:14:09 + Mark Atwood wrote: > > I'm requesting comment on the following behavior change: > > (1) Make these the default restrictions at startup, replacing none > > at all. (2) Retain current behavior if built with > > --enable-classic-mode. > > I like it, and

Change default to "restrict default kod limited nomodify nopeer noquery"

2016-12-10 Thread Mark Atwood
On Sat, Dec 10, 2016 at 11:00 AM Eric S. Raymond wrote: > > Pretty much every distribution in the universe ships a default > ntp.conf with a restriction sectio that looks like this: > [...] > I'm requesting comment on the following behavior change: > (1) Make these the default restrictions at sta