看板FB_security
标 题Re: [PATCH RFC] Disable save-entropy in jails
发信站NCTU CS FreeBSD Server (Tue Dec 24 22:36:10 2013)
转信站ptt!csnews.cs.nctu!news.cednctu!FreeBSD.cs.nctu!.POSTED!freebsd.org!ow
On Dec 24, 2013, at 12:44 PM, Xin Li <
[email protected]> wrote:
> I think we shouldn't save entropy inside jails, as the data is not going
> to be used by rc script (pjd@126744). If there is no objections, I will
> commit this changeset on January 1, 2014.
Even if it is not used by an rc script, it might be used by some userland program (running as root, of course) that knows about the directory and wants some fresh entropy for its own use.
Is there a problem with saving the directory in jails? It certainly isn't taking up much space.
--Paul Hoffman
_______________________________________________
[email protected] mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "
[email protected]"