head	1.28;
access;
symbols
	netbsd-9-5-RELEASE:1.26
	netbsd-11-0-RELEASE:1.28
	netbsd-11-0-RC7:1.28
	netbsd-11-0-RC6:1.28
	netbsd-11-0-RC5:1.28
	netbsd-11-0-RC4:1.28
	netbsd-11-0-RC3:1.28
	netbsd-11-0-RC2:1.28
	netbsd-11-0-RC1:1.28
	perseant-exfatfs-base-20250801:1.28
	netbsd-11:1.28.0.10
	netbsd-11-base:1.28
	netbsd-10-1-RELEASE:1.28
	perseant-exfatfs-base-20240630:1.28
	perseant-exfatfs:1.28.0.8
	perseant-exfatfs-base:1.28
	netbsd-8-3-RELEASE:1.26
	netbsd-9-4-RELEASE:1.26
	netbsd-10-0-RELEASE:1.28
	netbsd-10-0-RC6:1.28
	netbsd-10-0-RC5:1.28
	netbsd-10-0-RC4:1.28
	netbsd-10-0-RC3:1.28
	netbsd-10-0-RC2:1.28
	netbsd-10-0-RC1:1.28
	netbsd-10:1.28.0.6
	netbsd-10-base:1.28
	netbsd-9-3-RELEASE:1.26
	cjep_sun2x-base1:1.28
	cjep_sun2x:1.28.0.4
	cjep_sun2x-base:1.28
	cjep_staticlib_x-base1:1.28
	netbsd-9-2-RELEASE:1.26
	cjep_staticlib_x:1.28.0.2
	cjep_staticlib_x-base:1.28
	netbsd-9-1-RELEASE:1.26
	phil-wifi-20200421:1.27
	phil-wifi-20200411:1.27
	is-mlppp:1.27.0.2
	is-mlppp-base:1.27
	phil-wifi-20200406:1.27
	netbsd-8-2-RELEASE:1.26
	netbsd-9-0-RELEASE:1.26
	netbsd-9-0-RC2:1.26
	netbsd-9-0-RC1:1.26
	phil-wifi-20191119:1.26
	netbsd-9:1.26.0.28
	netbsd-9-base:1.26
	phil-wifi-20190609:1.26
	netbsd-8-1-RELEASE:1.26
	netbsd-8-1-RC1:1.26
	pgoyette-compat-merge-20190127:1.26
	pgoyette-compat-20190127:1.26
	pgoyette-compat-20190118:1.26
	pgoyette-compat-1226:1.26
	pgoyette-compat-1126:1.26
	pgoyette-compat-1020:1.26
	pgoyette-compat-0930:1.26
	pgoyette-compat-0906:1.26
	netbsd-7-2-RELEASE:1.26
	pgoyette-compat-0728:1.26
	netbsd-8-0-RELEASE:1.26
	phil-wifi:1.26.0.26
	phil-wifi-base:1.26
	pgoyette-compat-0625:1.26
	netbsd-8-0-RC2:1.26
	pgoyette-compat-0521:1.26
	pgoyette-compat-0502:1.26
	pgoyette-compat-0422:1.26
	netbsd-8-0-RC1:1.26
	pgoyette-compat-0415:1.26
	pgoyette-compat-0407:1.26
	pgoyette-compat-0330:1.26
	pgoyette-compat-0322:1.26
	pgoyette-compat-0315:1.26
	netbsd-7-1-2-RELEASE:1.26
	pgoyette-compat:1.26.0.24
	pgoyette-compat-base:1.26
	netbsd-7-1-1-RELEASE:1.26
	matt-nb8-mediatek:1.26.0.22
	matt-nb8-mediatek-base:1.26
	perseant-stdc-iso10646:1.26.0.20
	perseant-stdc-iso10646-base:1.26
	netbsd-8:1.26.0.18
	netbsd-8-base:1.26
	prg-localcount2-base3:1.26
	prg-localcount2-base2:1.26
	prg-localcount2-base1:1.26
	prg-localcount2:1.26.0.16
	prg-localcount2-base:1.26
	pgoyette-localcount-20170426:1.26
	bouyer-socketcan-base1:1.26
	pgoyette-localcount-20170320:1.26
	netbsd-7-1:1.26.0.14
	netbsd-7-1-RELEASE:1.26
	netbsd-7-1-RC2:1.26
	netbsd-7-nhusb-base-20170116:1.26
	bouyer-socketcan:1.26.0.12
	bouyer-socketcan-base:1.26
	pgoyette-localcount-20170107:1.26
	netbsd-7-1-RC1:1.26
	pgoyette-localcount-20161104:1.26
	netbsd-7-0-2-RELEASE:1.26
	localcount-20160914:1.26
	netbsd-7-nhusb:1.26.0.10
	netbsd-7-nhusb-base:1.26
	pgoyette-localcount-20160806:1.26
	pgoyette-localcount-20160726:1.26
	pgoyette-localcount:1.26.0.8
	pgoyette-localcount-base:1.26
	netbsd-7-0-1-RELEASE:1.26
	netbsd-7-0:1.26.0.6
	netbsd-7-0-RELEASE:1.26
	netbsd-7-0-RC3:1.26
	netbsd-7-0-RC2:1.26
	netbsd-7-0-RC1:1.26
	netbsd-5-2-3-RELEASE:1.20
	netbsd-5-1-5-RELEASE:1.20
	netbsd-6-0-6-RELEASE:1.23
	netbsd-6-1-5-RELEASE:1.23
	netbsd-7:1.26.0.4
	netbsd-7-base:1.26
	yamt-pagecache-base9:1.26
	yamt-pagecache-tag8:1.23.6.1
	netbsd-6-1-4-RELEASE:1.23
	netbsd-6-0-5-RELEASE:1.23
	tls-earlyentropy:1.26.0.2
	tls-earlyentropy-base:1.26
	riastradh-xf86-video-intel-2-7-1-pre-2-21-15:1.26
	riastradh-drm2-base3:1.26
	netbsd-6-1-3-RELEASE:1.23
	netbsd-6-0-4-RELEASE:1.23
	netbsd-5-2-2-RELEASE:1.20
	netbsd-5-1-4-RELEASE:1.20
	netbsd-6-1-2-RELEASE:1.23
	netbsd-6-0-3-RELEASE:1.23
	netbsd-5-2-1-RELEASE:1.20
	netbsd-5-1-3-RELEASE:1.20
	netbsd-6-1-1-RELEASE:1.23
	riastradh-drm2-base2:1.25
	riastradh-drm2-base1:1.25
	riastradh-drm2:1.25.0.4
	riastradh-drm2-base:1.25
	netbsd-6-1:1.23.0.14
	netbsd-6-0-2-RELEASE:1.23
	netbsd-6-1-RELEASE:1.23
	khorben-n900:1.25.0.2
	netbsd-6-1-RC4:1.23
	netbsd-6-1-RC3:1.23
	agc-symver:1.24.0.6
	agc-symver-base:1.24
	netbsd-6-1-RC2:1.23
	netbsd-6-1-RC1:1.23
	yamt-pagecache-base8:1.24
	netbsd-5-2:1.20.0.24
	netbsd-6-0-1-RELEASE:1.23
	yamt-pagecache-base7:1.24
	netbsd-5-2-RELEASE:1.20
	netbsd-5-2-RC1:1.20
	matt-nb6-plus-nbase:1.23
	yamt-pagecache-base6:1.24
	netbsd-6-0:1.23.0.12
	netbsd-6-0-RELEASE:1.23
	netbsd-6-0-RC2:1.23
	tls-maxphys:1.24.0.2
	tls-maxphys-base:1.26
	matt-nb6-plus:1.23.0.10
	matt-nb6-plus-base:1.23
	netbsd-6-0-RC1:1.23
	yamt-pagecache-base5:1.24
	yamt-pagecache-base4:1.24
	netbsd-6:1.23.0.8
	netbsd-6-base:1.23
	netbsd-5-1-2-RELEASE:1.20
	netbsd-5-1-1-RELEASE:1.20
	yamt-pagecache-base3:1.23
	yamt-pagecache-base2:1.23
	yamt-pagecache:1.23.0.6
	yamt-pagecache-base:1.23
	cherry-xenmp:1.23.0.4
	cherry-xenmp-base:1.23
	bouyer-quota2-nbase:1.23
	bouyer-quota2:1.23.0.2
	bouyer-quota2-base:1.23
	matt-mips64-premerge-20101231:1.23
	matt-nb5-mips64-premerge-20101231:1.20
	matt-nb5-pq3:1.20.0.22
	matt-nb5-pq3-base:1.20
	netbsd-5-1:1.20.0.20
	netbsd-5-1-RELEASE:1.20
	netbsd-5-1-RC4:1.20
	matt-nb5-mips64-k15:1.20
	netbsd-5-1-RC3:1.20
	netbsd-5-1-RC2:1.20
	netbsd-5-1-RC1:1.20
	netbsd-5-0-2-RELEASE:1.20
	matt-nb5-mips64-premerge-20091211:1.20
	matt-premerge-20091211:1.21
	matt-nb5-mips64-u2-k2-k4-k7-k8-k9:1.20
	matt-nb4-mips64-k7-u2a-k9b:1.20
	matt-nb5-mips64-u1-k1-k5:1.20
	matt-nb5-mips64:1.20.0.18
	netbsd-5-0-1-RELEASE:1.20
	jym-xensuspend-nbase:1.21
	netbsd-5-0:1.20.0.16
	netbsd-5-0-RELEASE:1.20
	netbsd-5-0-RC4:1.20
	netbsd-5-0-RC3:1.20
	netbsd-5-0-RC2:1.20
	jym-xensuspend:1.21.0.2
	jym-xensuspend-base:1.21
	netbsd-5-0-RC1:1.20
	mjf-devfs2-base2:1.20
	netbsd-5:1.20.0.14
	netbsd-5-base:1.20
	matt-mips64-base2:1.20
	matt-mips64:1.19.0.4
	netbsd-4-0-1-RELEASE:1.18.4.2
	wrstuden-revivesa-base-3:1.20
	wrstuden-revivesa-base-2:1.20
	wrstuden-fixsa-newbase:1.18.4.2
	wrstuden-revivesa-base-1:1.20
	yamt-pf42-base4:1.20
	yamt-pf42-base3:1.20
	hpcarm-cleanup-nbase:1.20
	yamt-pf42-baseX:1.20
	yamt-pf42-base2:1.20
	wrstuden-revivesa:1.20.0.12
	wrstuden-revivesa-base:1.20
	yamt-pf42:1.20.0.10
	yamt-pf42-base:1.20
	mjf-devfs2:1.20.0.8
	mjf-devfs2-base:1.20
	keiichi-mipv6:1.20.0.6
	keiichi-mipv6-base:1.20
	mjf-devfs:1.20.0.4
	mjf-devfs-base:1.20
	matt-armv6-nbase:1.20
	matt-armv6-prevmlocking:1.19.2.1
	wrstuden-fixsa-base-1:1.18.4.2
	netbsd-4-0:1.18.4.2.0.2
	netbsd-4-0-RELEASE:1.18.4.2
	cube-autoconf:1.20.0.2
	cube-autoconf-base:1.20
	netbsd-4-0-RC5:1.18.4.2
	netbsd-4-0-RC4:1.18.4.2
	netbsd-4-0-RC3:1.18.4.2
	netbsd-4-0-RC2:1.18.4.2
	netbsd-4-0-RC1:1.18.4.1
	matt-armv6:1.19.0.2
	matt-armv6-base:1.20
	matt-mips64-base:1.19
	hpcarm-cleanup:1.18.0.8
	hpcarm-cleanup-base:1.20
	netbsd-3-1-1-RELEASE:1.14.2.2
	netbsd-3-0-3-RELEASE:1.14.2.1
	wrstuden-fixsa:1.18.0.6
	wrstuden-fixsa-base:1.18.4.2
	abandoned-netbsd-4-base:1.18
	abandoned-netbsd-4:1.18.0.2
	netbsd-3-1:1.14.2.2.0.2
	netbsd-3-1-RELEASE:1.14.2.2
	netbsd-3-0-2-RELEASE:1.14.2.1
	netbsd-3-1-RC4:1.14.2.2
	netbsd-3-1-RC3:1.14.2.2
	netbsd-3-1-RC2:1.14.2.2
	netbsd-3-1-RC1:1.14.2.2
	netbsd-4:1.18.0.4
	netbsd-4-base:1.18
	netbsd-3-0-1-RELEASE:1.14.2.1
	netbsd-3-0:1.14.2.1.0.2
	netbsd-3-0-RELEASE:1.14.2.1
	netbsd-3-0-RC6:1.14.2.1
	netbsd-3-0-RC5:1.14.2.1
	netbsd-3-0-RC4:1.14.2.1
	netbsd-3-0-RC3:1.14.2.1
	netbsd-3-0-RC2:1.14.2.1
	netbsd-3-0-RC1:1.14.2.1
	netbsd-2-0-3-RELEASE:1.12
	netbsd-2-1:1.12.0.6
	netbsd-2-1-RELEASE:1.12
	netbsd-2-1-RC6:1.12
	netbsd-2-1-RC5:1.12
	netbsd-2-1-RC4:1.12
	netbsd-2-1-RC3:1.12
	netbsd-2-1-RC2:1.12
	netbsd-2-1-RC1:1.12
	netbsd-2-0-2-RELEASE:1.12
	netbsd-3:1.14.0.2
	netbsd-3-base:1.14
	netbsd-2-0-1-RELEASE:1.12
	netbsd-2:1.12.0.4
	netbsd-2-base:1.12
	netbsd-2-0-RELEASE:1.12
	netbsd-2-0-RC5:1.12
	netbsd-2-0-RC4:1.12
	netbsd-2-0-RC3:1.12
	netbsd-2-0-RC2:1.12
	netbsd-2-0-RC1:1.12
	netbsd-2-0:1.12.0.2
	netbsd-2-0-base:1.12
	netbsd-1-6-PATCH002-RELEASE:1.8
	netbsd-1-6-PATCH002:1.8
	netbsd-1-6-PATCH002-RC4:1.8
	netbsd-1-6-PATCH002-RC3:1.8
	netbsd-1-6-PATCH002-RC2:1.8
	netbsd-1-6-PATCH002-RC1:1.8
	netbsd-1-6-PATCH001:1.8
	netbsd-1-6-PATCH001-RELEASE:1.8
	netbsd-1-6-PATCH001-RC3:1.8
	netbsd-1-6-PATCH001-RC2:1.8
	netbsd-1-6-PATCH001-RC1:1.8
	fvdl_fs64_base:1.8
	netbsd-1-6-RELEASE:1.8
	netbsd-1-6-RC3:1.8
	netbsd-1-6-RC2:1.8
	netbsd-1-6-RC1:1.8
	netbsd-1-6:1.8.0.2
	netbsd-1-6-base:1.8
	netbsd-1-5-PATCH003:1.1.2.3
	netbsd-1-5-PATCH002:1.1.2.3
	netbsd-1-5-PATCH001:1.1.2.2
	netbsd-1-5-RELEASE:1.1.2.2
	netbsd-1-5-BETA2:1.1.2.2
	netbsd-1-5-BETA:1.1.2.2
	netbsd-1-5:1.1.0.2;
locks; strict;
comment	@# @;


1.28
date	2021.01.10.23.24.25;	author riastradh;	state Exp;
branches;
next	1.27;
commitid	nvjdXwWVOKPFFeDC;

1.27
date	2019.12.06.14.43.29;	author riastradh;	state Exp;
branches;
next	1.26;
commitid	36hsZmlDZdRyIENB;

1.26
date	2013.11.06.19.37.05;	author spz;	state Exp;
branches
	1.26.26.1;
next	1.25;
commitid	zCe1RdRZ5dP4Ifcx;

1.25
date	2013.05.01.05.36.25;	author agc;	state Exp;
branches;
next	1.24;

1.24
date	2012.04.05.09.09.27;	author spz;	state Exp;
branches
	1.24.2.1;
next	1.23;

1.23
date	2010.02.05.16.29.02;	author jmmv;	state Exp;
branches
	1.23.6.1;
next	1.22;

1.22
date	2010.01.19.22.08.11;	author jmmv;	state Exp;
branches;
next	1.21;

1.21
date	2009.01.27.10.32.18;	author haad;	state Exp;
branches;
next	1.20;

1.20
date	2007.08.27.19.57.02;	author adrianp;	state Exp;
branches;
next	1.19;

1.19
date	2007.08.05.00.10.37;	author jnemeth;	state Exp;
branches
	1.19.2.1
	1.19.4.1;
next	1.18;

1.18
date	2006.05.25.02.38.10;	author lukem;	state Exp;
branches
	1.18.4.1
	1.18.6.1;
next	1.17;

1.17
date	2006.04.01.17.13.19;	author jdolecek;	state Exp;
branches;
next	1.16;

1.16
date	2005.08.22.14.09.23;	author perry;	state Exp;
branches;
next	1.15;

1.15
date	2005.05.12.14.02.05;	author christos;	state Exp;
branches;
next	1.14;

1.14
date	2005.02.05.15.26.37;	author jdolecek;	state Exp;
branches
	1.14.2.1;
next	1.13;

1.13
date	2004.09.28.15.03.58;	author erh;	state Exp;
branches;
next	1.12;

1.12
date	2003.11.18.03.21.40;	author jhawk;	state Exp;
branches
	1.12.2.1
	1.12.4.1
	1.12.6.1;
next	1.11;

1.11
date	2003.02.21.22.47.53;	author jhawk;	state Exp;
branches;
next	1.10;

1.10
date	2003.02.13.02.42.07;	author jhawk;	state Exp;
branches;
next	1.9;

1.9
date	2003.02.13.01.55.10;	author jhawk;	state Exp;
branches;
next	1.8;

1.8
date	2001.10.03.15.41.26;	author lukem;	state Exp;
branches;
next	1.7;

1.7
date	2001.10.01.02.21.20;	author atatat;	state Exp;
branches;
next	1.6;

1.6
date	2001.04.04.03.17.20;	author atatat;	state Exp;
branches;
next	1.5;

1.5
date	2001.03.15.02.23.48;	author hubertf;	state Exp;
branches;
next	1.4;

1.4
date	2001.02.11.09.55.09;	author jdolecek;	state Exp;
branches;
next	1.3;

1.3
date	2001.01.09.17.30.30;	author abs;	state Exp;
branches;
next	1.2;

1.2
date	2000.11.08.23.17.50;	author lukem;	state Exp;
branches;
next	1.1;

1.1
date	2000.10.01.05.46.03;	author lukem;	state Exp;
branches
	1.1.2.1;
next	;

1.26.26.1
date	2020.04.08.14.03.56;	author martin;	state Exp;
branches;
next	;
commitid	Qli2aW9E74UFuA3C;

1.24.2.1
date	2013.06.23.06.26.21;	author tls;	state Exp;
branches;
next	1.24.2.2;
commitid	OnlO1cBgtQRcIHUw;

1.24.2.2
date	2014.08.19.23.45.50;	author tls;	state Exp;
branches;
next	;
commitid	jTnpym9Qu0o4R1Nx;

1.23.6.1
date	2012.04.17.00.02.57;	author yamt;	state Exp;
branches;
next	1.23.6.2;

1.23.6.2
date	2014.05.22.11.27.19;	author yamt;	state Exp;
branches;
next	;
commitid	spVi6gj5ReXSGwBx;

1.19.2.1
date	2007.11.06.23.10.26;	author matt;	state Exp;
branches;
next	;

1.19.4.1
date	2007.08.05.00.10.37;	author jnemeth;	state dead;
branches;
next	1.19.4.2;

1.19.4.2
date	2007.08.05.00.10.38;	author jnemeth;	state Exp;
branches;
next	;

1.18.4.1
date	2007.08.21.19.44.54;	author liamjfoy;	state Exp;
branches;
next	1.18.4.2;

1.18.4.2
date	2007.09.17.20.27.16;	author bouyer;	state Exp;
branches;
next	;

1.18.6.1
date	2007.09.03.06.57.49;	author wrstuden;	state Exp;
branches;
next	1.18.6.2;

1.18.6.2
date	2007.09.24.05.12.42;	author wrstuden;	state Exp;
branches;
next	;

1.14.2.1
date	2005.05.12.15.59.21;	author tron;	state Exp;
branches
	1.14.2.1.2.1;
next	1.14.2.2;

1.14.2.2
date	2006.07.12.14.23.25;	author tron;	state Exp;
branches
	1.14.2.2.2.1;
next	1.14.2.3;

1.14.2.3
date	2007.09.17.20.05.06;	author bouyer;	state Exp;
branches;
next	;

1.14.2.1.2.1
date	2007.09.17.20.07.15;	author bouyer;	state Exp;
branches;
next	;

1.14.2.2.2.1
date	2007.09.17.20.08.21;	author bouyer;	state Exp;
branches;
next	;

1.12.2.1
date	2007.09.17.19.58.48;	author bouyer;	state Exp;
branches;
next	;

1.12.4.1
date	2007.09.17.19.57.08;	author bouyer;	state Exp;
branches;
next	;

1.12.6.1
date	2007.09.17.20.00.06;	author bouyer;	state Exp;
branches;
next	;

1.1.2.1
date	2000.10.01.05.46.03;	author lukem;	state dead;
branches;
next	1.1.2.2;

1.1.2.2
date	2000.10.02.03.13.04;	author lukem;	state Exp;
branches;
next	1.1.2.3;

1.1.2.3
date	2001.07.29.20.23.41;	author he;	state Exp;
branches;
next	;


desc
@@


1.28
log
@Various entropy integration improvements.

- New /etc/security check for entropy in daily security report.

- New /etc/rc.d/entropy script runs (after random_seed and rndctl) to
  check for entropy at boot -- in rc.conf, you can:

  . set `entropy=check' to halt multiuser boot and enter single-user
    mode if not enough entropy

  . set `entropy=wait' to make multiuser boot wait until enough entropy

  Default is to always boot without waiting -- and rely on other
  channels like security report to alert the operator if there's a
  problem.

- New man page entropy(7) discussing the higher-level concepts and
  system integration with cross-references.

- New paragraph in afterboot(8) about entropy citing entropy(7) for
  more details.

This change addresses many of the issues discussed in security/55659.
This is a first draft; happy to take improvements to the man pages and
scripted messages to improve clarity.

I considered changing motd to include an entropy warning with a
reference to the entropy(7) man page, but it's a little trickier:
- Not sure it's appropriate for all users to see at login rather than
  users who have power to affect the entropy estimate (maybe it is,
  just haven't decided).
- We only have a mechanism for changing once at boot; the message would
  remain until next boot even if an operator adds enough entropy.
- The mechanism isn't really conducive to making a message appear
  conditionally from boot to boot.
@
text
@#	$NetBSD: security.conf,v 1.27 2019/12/06 14:43:29 riastradh Exp $
#
# /etc/defaults/security.conf --
#	default configuration of /etc/security.conf
#
# see security.conf(5) for more information.
#
# DO NOT EDIT THIS FILE DIRECTLY; IT MAY BE REPLACED DURING A SYSTEM UPGRADE.
# EDIT /etc/security.conf INSTEAD.
#

check_entropy=YES
check_passwd=YES
check_group=YES
check_rootdotfiles=YES
check_ftpusers=YES
check_aliases=YES
check_rhosts=YES
check_homes=YES
check_varmail=YES
check_nfs=YES
check_devices=YES
check_mtree=YES
check_disklabels=YES
check_pkgs=YES
check_changelist=YES
check_lvm=NO
check_pkg_vulnerabilities=YES
check_pkg_signatures=YES

backup_dir=/var/backups
backup_uses_rcs=YES
diff_options=-u

check_homes_permit_usergroups=NO
check_homes_permit_other_owner=""

check_devices_ignore_fstypes="!local fdesc kernfs null procfs ptyfs ntfs msdos"
check_devices_ignore_paths=""

check_mtree_follow_symlinks=NO

check_passwd_nowarn_shells="/sbin/nologin"
check_passwd_nowarn_users=""
check_passwd_permit_dups="toor"
check_passwd_permit_star=NO
check_passwd_permit_nonalpha=NO
max_loginlen=16
max_grouplen=16

random_file=/var/db/entropy-file
@


1.27
log
@Save the entropy seed daily in /etc/security.
@
text
@d1 1
a1 1
#	$NetBSD: security.conf,v 1.26 2013/11/06 19:37:05 spz Exp $
d12 1
@


1.26
log
@Introduce a variable for security.conf, default empty, to list users
whose home is (allowed to be) owned by another user.

It's a separate variable and not just check_passwd_permit_dups so I can
make security shut up about my uucp users.

Fixes the second half of PR misc/36063
@
text
@d1 1
a1 1
#	$NetBSD: security.conf,v 1.25 2013/05/01 05:36:25 agc Exp $
d49 2
@


1.26.26.1
log
@Merge changes from current as of 20200406
@
text
@d1 1
a1 1
#	$NetBSD$
a48 2

random_file=/var/db/entropy-file
@


1.25
log
@Fix for problematic paths in /etc/daily and /etc/security reported in
PR/47645.

Add a separate file which contains the paths for the pkg_admin and
pkg_info utilities. This is called /etc/pkgpath.conf (to distinguish it
from pkg.conf).

Thanks also to Edgar Fuss for the sanity check.
@
text
@d1 1
a1 1
#	$NetBSD: security.conf,v 1.24 2012/04/05 09:09:27 spz Exp $
d35 1
@


1.24
log
@change security so that there is a configuration value for the list of
users who will not be considered for duplicate uid check.
Seed it with 'toor' in defaults/security.conf.
@
text
@d1 1
a1 1
#	$NetBSD: security.conf,v 1.23 2010/02/05 16:29:02 jmmv Exp $
a32 1
pkg_info=/usr/sbin/pkg_info
@


1.24.2.1
log
@resync from head
@
text
@d1 1
a1 1
#	$NetBSD$
d33 1
@


1.24.2.2
log
@Rebase to HEAD as of a few days ago.
@
text
@a34 1
check_homes_permit_other_owner=""
@


1.23
log
@Deprecate the pkgdb_dir settings from daily.conf and security.conf in
favor of the PKG_DBDIR variable in /etc/pkg_install.conf.  The purpose
of this is to only have to define the location of the packages database
in a single place and have all other system components pick it up.

pkgdb_dir is still honored if defined and the scripts will spit out a
warning in that case, asking the administrator to migrate to the
PKG_DBDIR setting.  We can't remove this compatibility workaround until,
at least, after NetBSD 6 is released.
@
text
@d1 1
a1 1
#	$NetBSD: security.conf,v 1.22 2010/01/19 22:08:11 jmmv Exp $
d44 1
@


1.23.6.1
log
@sync with head
@
text
@d1 1
a1 1
#	$NetBSD: security.conf,v 1.23 2010/02/05 16:29:02 jmmv Exp $
a43 1
check_passwd_permit_dups="toor"
@


1.23.6.2
log
@sync with head.

for a reference, the tree before this commit was tagged
as yamt-pagecache-tag8.

this commit was splitted into small chunks to avoid
a limitation of cvs.  ("Protocol error: too many arguments")
@
text
@d1 1
a1 1
#	$NetBSD: security.conf,v 1.23.6.1 2012/04/17 00:02:57 yamt Exp $
d33 1
a35 1
check_homes_permit_other_owner=""
@


1.22
log
@Add the fetch_pkg_vulnerabilities option to the daily script to keep the
packages vulnerability database up to date.  This will only fetch the
file from the server if it has changed since the last run.

Add the check_pkg_vulnerabilities and check_pkg_signatures options to the
security script to check that the installed packages are sane.

All of these options are enabled by default but they will only run if
there is, at least, one installed package.
@
text
@d1 1
a1 1
#	$NetBSD: security.conf,v 1.21 2009/01/27 10:32:18 haad Exp $
a32 1
pkgdb_dir=/var/db/pkg
@


1.21
log
@Add support for lvm to security script. Backup lvm configuration to /var/backup/lvm with other system backups. Disable lvm check until MKLVM is enabled by default. no objections on tech-userlevel@@.
@
text
@d1 1
a1 1
#	$NetBSD: security.conf,v 1.20 2007/08/27 19:57:02 adrianp Exp $
d27 2
@


1.20
log
@The location of the pkg_info binary can now be specified in /etc/security.conf.
The default remains as /usr/sbin/pkg_info.  This should fix PR# 36746.
@
text
@d1 1
a1 1
#	$NetBSD: security.conf,v 1.19 2007/08/05 00:10:37 jnemeth Exp $
d26 1
@


1.19
log
@PR/36732 - Jim Bernard -- delete /usr/libexec/uucp/uucico from list of shells
@
text
@d1 1
a1 1
#	$NetBSD: security.conf,v 1.18 2006/05/25 02:38:10 lukem Exp $
d31 1
@


1.19.4.1
log
@file security.conf was added on branch matt-mips64 on 2007-08-05 00:10:38 +0000
@
text
@d1 44
@


1.19.4.2
log
@PR/36732 - Jim Bernard -- delete /usr/libexec/uucp/uucico from list of shells
@
text
@a0 44
#	$NetBSD: security.conf,v 1.19 2007/08/05 00:10:37 jnemeth Exp $
#
# /etc/defaults/security.conf --
#	default configuration of /etc/security.conf
#
# see security.conf(5) for more information.
#
# DO NOT EDIT THIS FILE DIRECTLY; IT MAY BE REPLACED DURING A SYSTEM UPGRADE.
# EDIT /etc/security.conf INSTEAD.
#

check_passwd=YES
check_group=YES
check_rootdotfiles=YES
check_ftpusers=YES
check_aliases=YES
check_rhosts=YES
check_homes=YES
check_varmail=YES
check_nfs=YES
check_devices=YES
check_mtree=YES
check_disklabels=YES
check_pkgs=YES
check_changelist=YES

backup_dir=/var/backups
backup_uses_rcs=YES
diff_options=-u
pkgdb_dir=/var/db/pkg

check_homes_permit_usergroups=NO

check_devices_ignore_fstypes="!local fdesc kernfs null procfs ptyfs ntfs msdos"
check_devices_ignore_paths=""

check_mtree_follow_symlinks=NO

check_passwd_nowarn_shells="/sbin/nologin"
check_passwd_nowarn_users=""
check_passwd_permit_star=NO
check_passwd_permit_nonalpha=NO
max_loginlen=16
max_grouplen=16
@


1.19.2.1
log
@sync with HEAD
@
text
@d1 1
a1 1
#	$NetBSD: security.conf,v 1.20 2007/08/27 19:57:02 adrianp Exp $
a30 1
pkg_info=/usr/sbin/pkg_info
@


1.18
log
@Implement check_devices_ignore_paths, which is a list of paths to
avoid traversing during check_devices.
@
text
@d1 1
a1 1
#	$NetBSD: security.conf,v 1.17 2006/04/01 17:13:19 jdolecek Exp $
d39 1
a39 1
check_passwd_nowarn_shells="/sbin/nologin /usr/libexec/uucp/uucico"
@


1.18.6.1
log
@Sync w/ NetBSD-4-RC_1
@
text
@d1 1
a1 1
#	$NetBSD: security.conf,v 1.18.4.1 2007/08/21 19:44:54 liamjfoy Exp $
d39 1
a39 1
check_passwd_nowarn_shells="/sbin/nologin"
@


1.18.6.2
log
@Catch up with netbsd-4.
@
text
@d1 1
a1 1
#	$NetBSD: security.conf,v 1.18.6.1 2007/09/03 06:57:49 wrstuden Exp $
a30 1
pkg_info=/usr/sbin/pkg_info
@


1.18.4.1
log
@Pull up following revision(s) (requested by jnemeth in ticket #812):
	etc/defaults/security.conf: revision 1.19
PR/36732 - Jim Bernard -- delete /usr/libexec/uucp/uucico from list of shells
@
text
@d1 1
a1 1
#	$NetBSD$
d39 1
a39 1
check_passwd_nowarn_shells="/sbin/nologin"
@


1.18.4.2
log
@Pull up following revision(s) (requested by adrianp in ticket #883):
	etc/defaults/security.conf: revision 1.20
	etc/security: revision 1.104
The location of the pkg_info binary can now be specified in
/etc/security.conf.
The default remains as /usr/sbin/pkg_info.  This should fix PR# 36746.
@
text
@a30 1
pkg_info=/usr/sbin/pkg_info
@


1.17
log
@don't check ntfs and msdosfs for devices/set[ug]id files; neither of those
are supported on the filesystem, so no need for checking

PR: 33092 by Aleksey Cheusov
@
text
@d1 1
a1 1
#	$NetBSD: security.conf,v 1.16 2005/08/22 14:09:23 perry Exp $
d35 1
@


1.16
log
@Make max_loginlen and max_grouplen 16.

We've handled 16 character logins for quite some time, and we even
have packages that create >8 character accounts. There is no point in
pretending the limit is 8 any more by default.

Discussed (very lightly -- there was little comment) on tech-userlevel
@
text
@d1 1
a1 1
#	$NetBSD: security.conf,v 1.15 2005/05/12 14:02:05 christos Exp $
d34 1
a34 1
check_devices_ignore_fstypes="!local fdesc kernfs null procfs ptyfs"
@


1.15
log
@it makes no sense to check ptyfs for new and gone devices. From Rui Paulo,
many thanks.
@
text
@d1 1
a1 1
#	$NetBSD: security.conf,v 1.14 2005/02/05 15:26:37 jdolecek Exp $
d42 2
a43 2
max_loginlen=8
max_grouplen=8
@


1.14
log
@add a check_passwd_permin_nonalpha option, which changes the passwd
test to permit non-alphanumeric characters in login names
@
text
@d1 1
a1 1
#	$NetBSD: security.conf,v 1.13 2004/09/28 15:03:58 erh Exp $
d34 1
a34 1
check_devices_ignore_fstypes="!local fdesc kernfs null procfs"
@


1.14.2.1
log
@Pull up revision 1.15 (requested by christos in ticket #298):
it makes no sense to check ptyfs for new and gone devices. From Rui Paulo,
many thanks.
@
text
@d1 1
a1 1
#	$NetBSD$
d34 1
a34 1
check_devices_ignore_fstypes="!local fdesc kernfs null procfs ptyfs"
@


1.14.2.1.2.1
log
@Pull up following revision(s) (requested by adrianp in ticket #1841):
	etc/defaults/security.conf: revision 1.20
	etc/security: revision 1.104
The location of the pkg_info binary can now be specified in
/etc/security.conf.
The default remains as /usr/sbin/pkg_info.  This should fix PR# 36746.
@
text
@a30 1
pkg_info=/usr/sbin/pkg_info
@


1.14.2.2
log
@Pull up following revision(s) (requested by lukem in ticket #1377):
	etc/security: revision 1.98
	share/man/man5/security.conf.5: revision 1.30 by patch
	etc/defaults/security.conf: revision 1.18
Implement check_devices_ignore_paths, which is a list of paths to
avoid traversing during check_devices.
@
text
@d34 1
a34 2
check_devices_ignore_fstypes="!local fdesc kernfs null procfs ptyfs ntfs msdos"
check_devices_ignore_paths=""
@


1.14.2.2.2.1
log
@Pull up following revision(s) (requested by adrianp in ticket #1841):
	etc/defaults/security.conf: revision 1.20
	etc/security: revision 1.104
The location of the pkg_info binary can now be specified in
/etc/security.conf.
The default remains as /usr/sbin/pkg_info.  This should fix PR# 36746.
@
text
@a30 1
pkg_info=/usr/sbin/pkg_info
@


1.14.2.3
log
@Pull up following revision(s) (requested by adrianp in ticket #1841):
	etc/defaults/security.conf: revision 1.20
	etc/security: revision 1.104
The location of the pkg_info binary can now be specified in
/etc/security.conf.
The default remains as /usr/sbin/pkg_info.  This should fix PR# 36746.
@
text
@a30 1
pkg_info=/usr/sbin/pkg_info
@


1.13
log
@PR misc/7716: add configuration options find_core_ignore_fstypes and
check_devices_ignore_fstypes to allow the filesystem types that are
ignored during the daily and security runs to be adjusted.
@
text
@d1 1
a1 1
#	$NetBSD: security.conf,v 1.12 2003/11/18 03:21:40 jhawk Exp $
d41 1
@


1.12
log
@check_homes_permit_usergroups=NO
@
text
@d1 1
a1 1
#	$NetBSD: security.conf,v 1.11 2003/02/21 22:47:53 jhawk Exp $
d34 2
@


1.12.6.1
log
@Pull up following revision(s) (requested by adrianp in ticket #11367):
	etc/defaults/security.conf: revision 1.20
	etc/security: revision 1.104
The location of the pkg_info binary can now be specified in
/etc/security.conf.
The default remains as /usr/sbin/pkg_info.  This should fix PR# 36746.
@
text
@d1 1
a1 1
#	$NetBSD$
a30 1
pkg_info=/usr/sbin/pkg_info
@


1.12.2.1
log
@Pull up following revision(s) (requested by adrianp in ticket #11367):
	etc/defaults/security.conf: revision 1.20
	etc/security: revision 1.104
The location of the pkg_info binary can now be specified in
/etc/security.conf.
The default remains as /usr/sbin/pkg_info.  This should fix PR# 36746.
@
text
@d1 1
a1 1
#	$NetBSD$
a30 1
pkg_info=/usr/sbin/pkg_info
@


1.12.4.1
log
@Pull up following revision(s) (requested by adrianp in ticket #11367):
	etc/defaults/security.conf: revision 1.20
	etc/security: revision 1.104
The location of the pkg_info binary can now be specified in
/etc/security.conf.
The default remains as /usr/sbin/pkg_info.  This should fix PR# 36746.
@
text
@d1 1
a1 1
#	$NetBSD$
a30 1
pkg_info=/usr/sbin/pkg_info
@


1.11
log
@Use $diff_options when running diff in /etc/security.
Default diff_options to -u, for unified-format context diffs,
because context is essential to a useful evaluation of differences.
This represents a behavior change.

Implements change-request PR security/17247 from
Takahiro Kambe <taca@@sky.yamashina.kyoto.jp>.
@
text
@d1 1
a1 1
#	$NetBSD: security.conf,v 1.10 2003/02/13 02:42:07 jhawk Exp $
d31 2
@


1.10
log
@Under check_mtree, invoke mtree with -L if check_mtree_follow_symlinks is set.
Apparently mtree -L is imperfect, but it is far better than the lack thereof
if symlinks are involved reaching files mtree verifies.
@
text
@d1 1
a1 1
#	$NetBSD: security.conf,v 1.9 2003/02/13 01:55:10 jhawk Exp $
d29 1
@


1.9
log
@Add some flexibility to /etc/security, by way of security.conf options:
  check_passwd_nowarn_shells	Don't warn about these non-/etc/shells shells
  check_passwd_nowarn_users	Don't warn about these users
  check_passwd_permit_star	Don't warn about "*" in the $2 field
Behavior change: check_passwd_nowarn_shells defaults to /sbin/nologin and
  /usr/libexec/uucp/uucico, so that it will not warn about the default
  master.passwd.
The rationale here is that an administrator who chooses to permit these
  warnable conditions should not be warned about them day after day, yet
  should not be forced to disable check_passwd entirely.
check_passwd_permit_star is primarily of interest to sites who use *'d
  entries for Kerberos or ssh logins, despite the fact that we permit
  "*ssh" (etc.) for this purpose (legacy).
@
text
@d1 1
a1 1
#	$NetBSD: security.conf,v 1.8 2001/10/03 15:41:26 lukem Exp $
d30 2
@


1.8
log
@replace "pkg_dbdir" with "pkgdb_dir", to be consistent with "backup_dir"
@
text
@d1 1
a1 1
#	$NetBSD: security.conf,v 1.7 2001/10/01 02:21:20 atatat Exp $
d31 3
@


1.7
log
@Add a chunk of code to check the installed pkgs list by making a list
of all installed pkgs and their +CONTENTS and +REQUIRED_BY files (if
they have one) and handling this file along with all the other
CHANGELIST stuff.

Greg Woods gets points for coming up with the idea.

Luke Mewburn asked me to do it, and provided lots of criticism along
the way.
@
text
@d1 1
a1 1
#	$NetBSD: security.conf,v 1.6 2001/04/04 03:17:20 atatat Exp $
d29 1
a29 1
pkg_dbdir=/var/db/pkg
@


1.6
log
@Provide the capability of storing backups via RCS instead of just a
"current" and a "last" (which is useless if you wanna know what you
changed last week).  Set the default to on.
@
text
@d1 1
a1 1
#	$NetBSD: security.conf,v 1.5 2001/03/15 02:23:48 hubertf Exp $
d24 1
d29 1
@


1.5
log
@Run skeyaudit (only) from /etc/daily instead of /etc/security, else there's
some risk that the users don't get warned if an admin turns off running
/etc/security (by putting run_security=no into daily.conf).

Fixes PR 12267.
@
text
@d1 1
a1 1
#	$NetBSD: security.conf,v 1.4 2001/02/11 09:55:09 jdolecek Exp $
d27 1
@


1.4
log
@Introduce max_grouplen - this determines the maximum permitted length
of group names, similarily to max_loginlen
@
text
@d1 1
a1 1
#	$NetBSD: security.conf,v 1.3 2001/01/09 17:30:30 abs Exp $
a24 2

run_skeyaudit=YES
@


1.3
log
@Add a new variable 'backup_dir', which can be used to change the backup
directory from /var/backup (useful for those of us who have a separate /var
and would like to have our backup disklabels on the root filesystem).
Default behaviour unchanged. backup_dir being unset is taken as /var/backup.
@
text
@d1 1
a1 1
#	$NetBSD: security.conf,v 1.2 2000/11/08 23:17:50 lukem Exp $
d31 1
@


1.2
log
@remind people to edit /etc/*.conf instead of /etc/defaults/*.conf
@
text
@d1 1
a1 1
#	$NetBSD: security.conf,v 1.1 2000/10/01 05:46:03 lukem Exp $
d27 2
@


1.1
log
@move default config files from /etc/default -> /etc/defaults, to be
consistent with what FreeBSD uses /etc/defaults for and since SVR4
uses /etc/default for another purpose. as discussed on tech-userlevel,
and no objections were made.
@
text
@d1 1
a1 1
#	$NetBSD: security.conf,v 1.1 2000/08/21 23:00:27 lukem Exp $
d7 4
@


1.1.2.1
log
@file security.conf was added on branch netbsd-1-5 on 2000-10-02 03:13:04 +0000
@
text
@d1 24
@


1.1.2.2
log
@pull up rev 1.1 (approved by thorpej):
	move default config files from /etc/default -> /etc/defaults, to be
	consistent with what FreeBSD uses /etc/defaults for, and since SVR4
	uses /etc/default for another purpose.
	as discussed on tech-userlevel, and no objections were made.
@
text
@a0 24
#	$NetBSD: security.conf,v 1.1.2.1 2000/10/02 03:13:04 lukem Exp $
#
# /etc/defaults/security.conf --
#	default configuration of /etc/security.conf
#
# see security.conf(5) for more information.

check_passwd=YES
check_group=YES
check_rootdotfiles=YES
check_ftpusers=YES
check_aliases=YES
check_rhosts=YES
check_homes=YES
check_varmail=YES
check_nfs=YES
check_devices=YES
check_mtree=YES
check_disklabels=YES
check_changelist=YES

run_skeyaudit=YES

max_loginlen=8
@


1.1.2.3
log
@Pull up revision 1.2 (requested by he):
  Remind people to edit /etc/*.conf instead of /etc/defaults/*.conf.
@
text
@d1 1
a1 1
#	$NetBSD: security.conf,v 1.1.2.2 2001/07/29 20:23:41 he Exp $
a6 4
#
# DO NOT EDIT THIS FILE DIRECTLY; IT MAY BE REPLACED DURING A SYSTEM UPGRADE.
# EDIT /etc/security.conf INSTEAD.
#
@
