Re: svn commit: r314036 - head/usr.sbin/bsdinstall/scripts

2017-02-26 Thread Joel Dahl
On Wed, Feb 22, 2017 at 06:10:04PM -0500, Allan Jude wrote: > Core is soon to announce a more formalized way to discuss and reach > consensus on these types of changes. robak@ can I ask that you back this > out for now, and we use that process to determine what the right set of > knobs to turn o

Re: svn commit: r314036 - head/usr.sbin/bsdinstall/scripts

2017-02-22 Thread Bryan Drewery
On 2/22/2017 3:10 PM, Allan Jude wrote: > On 2017-02-22 15:26, Bryan Drewery wrote: >> On 2/21/2017 11:07 PM, Joel Dahl wrote: >>> On Tue, Feb 21, 2017 at 02:40:02PM +, Alexey Dokuchaev wrote: On Tue, Feb 21, 2017 at 08:34:29AM -0600, Eric Badger wrote: > Thanks for working on making i

Re: svn commit: r314036 - head/usr.sbin/bsdinstall/scripts

2017-02-22 Thread Allan Jude
On 2017-02-22 15:26, Bryan Drewery wrote: > On 2/21/2017 11:07 PM, Joel Dahl wrote: >> On Tue, Feb 21, 2017 at 02:40:02PM +, Alexey Dokuchaev wrote: >>> On Tue, Feb 21, 2017 at 08:34:29AM -0600, Eric Badger wrote: Thanks for working on making it easier to harden FreeBSD. While default

Re: svn commit: r314036 - head/usr.sbin/bsdinstall/scripts

2017-02-22 Thread Ngie Cooper
On Wed, Feb 22, 2017 at 2:46 PM, Ngie Cooper wrote: ... > (Piggybacking on this thread) Silly question -- can all of these knobs > please default to off and have a global knob, like securelevel..? Fine > grained security is great, but it's really cumbersome tweaking > everything properly if you do

Re: svn commit: r314036 - head/usr.sbin/bsdinstall/scripts

2017-02-22 Thread Ngie Cooper
On Wed, Feb 22, 2017 at 12:26 PM, Bryan Drewery wrote: ... > I concur. > In the original review for adding this I predicted today would come, > https://reviews.freebsd.org/D6826. I still think that it is very > under-designed and under-thought out. > > I personally agree with hardening my system,

Re: svn commit: r314036 - head/usr.sbin/bsdinstall/scripts

2017-02-22 Thread Bryan Drewery
On 2/21/2017 11:07 PM, Joel Dahl wrote: > On Tue, Feb 21, 2017 at 02:40:02PM +, Alexey Dokuchaev wrote: >> On Tue, Feb 21, 2017 at 08:34:29AM -0600, Eric Badger wrote: >>> Thanks for working on making it easier to harden FreeBSD. While >>> defaulting some of these options to "on" seem pretty ha

Re: svn commit: r314036 - head/usr.sbin/bsdinstall/scripts

2017-02-22 Thread Slawa Olhovchenkov
On Wed, Feb 22, 2017 at 10:13:41AM -0800, Conrad Meyer wrote: > On Wed, Feb 22, 2017 at 10:05 AM, Slawa Olhovchenkov wrote: > > On Wed, Feb 22, 2017 at 08:11:14AM -0800, Conrad Meyer wrote: > > > >> On Wed, Feb 22, 2017 at 3:23 AM, Joel Dahl wrote: > >> > On Wed, Feb 22, 2017 at 07:56:52AM +

Re: svn commit: r314036 - head/usr.sbin/bsdinstall/scripts

2017-02-22 Thread Shawn Webb
On Wed, Feb 22, 2017 at 02:23:26PM -0500, Allan Jude wrote: > On 2017-02-22 13:13, Conrad Meyer wrote: > > On Wed, Feb 22, 2017 at 10:05 AM, Slawa Olhovchenkov > > wrote: > >> On Wed, Feb 22, 2017 at 08:11:14AM -0800, Conrad Meyer wrote: > >> > >>> On Wed, Feb 22, 2017 at 3:23 AM, Joel Dahl wrot

Re: svn commit: r314036 - head/usr.sbin/bsdinstall/scripts

2017-02-22 Thread Allan Jude
On 2017-02-22 13:13, Conrad Meyer wrote: > On Wed, Feb 22, 2017 at 10:05 AM, Slawa Olhovchenkov wrote: >> On Wed, Feb 22, 2017 at 08:11:14AM -0800, Conrad Meyer wrote: >> >>> On Wed, Feb 22, 2017 at 3:23 AM, Joel Dahl wrote: On Wed, Feb 22, 2017 at 07:56:52AM +, Bartłomiej Rutkowski wrot

Re: svn commit: r314036 - head/usr.sbin/bsdinstall/scripts

2017-02-22 Thread Conrad Meyer
On Wed, Feb 22, 2017 at 10:05 AM, Slawa Olhovchenkov wrote: > On Wed, Feb 22, 2017 at 08:11:14AM -0800, Conrad Meyer wrote: > >> On Wed, Feb 22, 2017 at 3:23 AM, Joel Dahl wrote: >> > On Wed, Feb 22, 2017 at 07:56:52AM +, Bartłomiej Rutkowski wrote: >> >> I strongly believe we should, by defa

Re: svn commit: r314036 - head/usr.sbin/bsdinstall/scripts

2017-02-22 Thread Slawa Olhovchenkov
On Wed, Feb 22, 2017 at 08:11:14AM -0800, Conrad Meyer wrote: > On Wed, Feb 22, 2017 at 3:23 AM, Joel Dahl wrote: > > On Wed, Feb 22, 2017 at 07:56:52AM +, Bartłomiej Rutkowski wrote: > >> I strongly believe we should, by default, ship as secured and hardened as > >> possible in order to impr

Re: svn commit: r314036 - head/usr.sbin/bsdinstall/scripts

2017-02-22 Thread John Baldwin
On Wednesday, February 22, 2017 07:52:45 AM Bartłomiej Rutkowski wrote: > On Tue, Feb 21, 2017 at 2:34 PM, Eric Badger wrote: > > > On 02/21/2017 03:37 AM, Bartek Rutkowski wrote: > > > >> Author: robak (ports committer) > >> Date: Tue Feb 21 09:37:33 2017 > >> New Revision: 314036 > >> URL: http

Re: svn commit: r314036 - head/usr.sbin/bsdinstall/scripts

2017-02-22 Thread Conrad Meyer
On Wed, Feb 22, 2017 at 3:23 AM, Joel Dahl wrote: > On Wed, Feb 22, 2017 at 07:56:52AM +, Bartłomiej Rutkowski wrote: >> I strongly believe we should, by default, ship as secured and hardened as >> possible in order to improve overall security of new users installations. >> Power users will an

Re: svn commit: r314036 - head/usr.sbin/bsdinstall/scripts

2017-02-22 Thread Slawa Olhovchenkov
On Tue, Feb 21, 2017 at 09:37:34AM +, Bartek Rutkowski wrote: > Author: robak (ports committer) > Date: Tue Feb 21 09:37:33 2017 > New Revision: 314036 > URL: https://svnweb.freebsd.org/changeset/base/314036 > > Log: > Enable bsdinstall hardening options by default. > > As discussed pr

Re: svn commit: r314036 - head/usr.sbin/bsdinstall/scripts

2017-02-22 Thread Joel Dahl
On Wed, Feb 22, 2017 at 07:56:52AM +, Bartłomiej Rutkowski wrote: > On Tue, Feb 21, 2017 at 2:40 PM, Alexey Dokuchaev wrote: > > > On Tue, Feb 21, 2017 at 08:34:29AM -0600, Eric Badger wrote: > > > Thanks for working on making it easier to harden FreeBSD. While > > > defaulting some of these

Re: svn commit: r314036 - head/usr.sbin/bsdinstall/scripts

2017-02-22 Thread Bartłomiej Rutkowski
On Wed, Feb 22, 2017 at 8:32 AM, Alexey Dokuchaev wrote: > On Wed, Feb 22, 2017 at 07:56:52AM +, Bart??omiej Rutkowski wrote: > > These options have been around forever, used by a lot of users (once they > > got to know those even exist) and seem to cause no issues. However, > despite > > tha

Re: svn commit: r314036 - head/usr.sbin/bsdinstall/scripts

2017-02-22 Thread Alexey Dokuchaev
On Wed, Feb 22, 2017 at 07:56:52AM +, Bart??omiej Rutkowski wrote: > These options have been around forever, used by a lot of users (once they > got to know those even exist) and seem to cause no issues. However, despite > that, and numerous discussions and mail threads over the years, we've >

Re: svn commit: r314036 - head/usr.sbin/bsdinstall/scripts

2017-02-21 Thread Bartłomiej Rutkowski
On Tue, Feb 21, 2017 at 2:40 PM, Alexey Dokuchaev wrote: > On Tue, Feb 21, 2017 at 08:34:29AM -0600, Eric Badger wrote: > > Thanks for working on making it easier to harden FreeBSD. While > > defaulting some of these options to "on" seem pretty harmless (e.g. > > random_pid), others are likely to

Re: svn commit: r314036 - head/usr.sbin/bsdinstall/scripts

2017-02-21 Thread Bartłomiej Rutkowski
On Tue, Feb 21, 2017 at 2:34 PM, Eric Badger wrote: > On 02/21/2017 03:37 AM, Bartek Rutkowski wrote: > >> Author: robak (ports committer) >> Date: Tue Feb 21 09:37:33 2017 >> New Revision: 314036 >> URL: https://svnweb.freebsd.org/changeset/base/314036 >> >> Log: >> Enable bsdinstall hardening

Re: svn commit: r314036 - head/usr.sbin/bsdinstall/scripts

2017-02-21 Thread Bartłomiej Rutkowski
On Wed, Feb 22, 2017 at 7:07 AM, Joel Dahl wrote: > On Tue, Feb 21, 2017 at 02:40:02PM +, Alexey Dokuchaev wrote: > > On Tue, Feb 21, 2017 at 08:34:29AM -0600, Eric Badger wrote: > > > Thanks for working on making it easier to harden FreeBSD. While > > > defaulting some of these options to "o

Re: svn commit: r314036 - head/usr.sbin/bsdinstall/scripts

2017-02-21 Thread Joel Dahl
On Tue, Feb 21, 2017 at 02:40:02PM +, Alexey Dokuchaev wrote: > On Tue, Feb 21, 2017 at 08:34:29AM -0600, Eric Badger wrote: > > Thanks for working on making it easier to harden FreeBSD. While > > defaulting some of these options to "on" seem pretty harmless (e.g. > > random_pid), others are li

Re: svn commit: r314036 - head/usr.sbin/bsdinstall/scripts

2017-02-21 Thread Alexey Dokuchaev
On Tue, Feb 21, 2017 at 08:34:29AM -0600, Eric Badger wrote: > Thanks for working on making it easier to harden FreeBSD. While > defaulting some of these options to "on" seem pretty harmless (e.g. > random_pid), others are likely to cause confusion for new and > experienced users alike (e.g. proc_d

Re: svn commit: r314036 - head/usr.sbin/bsdinstall/scripts

2017-02-21 Thread Eric Badger
On 02/21/2017 03:37 AM, Bartek Rutkowski wrote: Author: robak (ports committer) Date: Tue Feb 21 09:37:33 2017 New Revision: 314036 URL: https://svnweb.freebsd.org/changeset/base/314036 Log: Enable bsdinstall hardening options by default. As discussed previously, in order to introduce new O

svn commit: r314036 - head/usr.sbin/bsdinstall/scripts

2017-02-21 Thread Bartek Rutkowski
Author: robak (ports committer) Date: Tue Feb 21 09:37:33 2017 New Revision: 314036 URL: https://svnweb.freebsd.org/changeset/base/314036 Log: Enable bsdinstall hardening options by default. As discussed previously, in order to introduce new OS hardening defaults, we've added them to bsdi