The NetBSD Project

CVS log for src/share/man/man7/security.7

[BACK] Up to [cvs.NetBSD.org] / src / share / man / man7

Request diff between arbitrary revisions


Default branch: MAIN
Current tag: MAIN


Revision 1.16 / (download) - annotate - [select for diffs], Sun Jan 10 23:24:26 2021 UTC (9 months, 1 week ago) by riastradh
Branch: MAIN
CVS Tags: cjep_sun2x-base1, cjep_sun2x-base, cjep_sun2x, cjep_staticlib_x-base1, cjep_staticlib_x-base, cjep_staticlib_x, HEAD
Changes since 1.15: +5 -1 lines
Diff to previous 1.15 (colored)

Various entropy integration improvements.

- New /etc/security check for entropy in daily security report.

- New /etc/rc.d/entropy script runs (after random_seed and rndctl) to
  check for entropy at boot -- in rc.conf, you can:

  . set `entropy=check' to halt multiuser boot and enter single-user
    mode if not enough entropy

  . set `entropy=wait' to make multiuser boot wait until enough entropy

  Default is to always boot without waiting -- and rely on other
  channels like security report to alert the operator if there's a
  problem.

- New man page entropy(7) discussing the higher-level concepts and
  system integration with cross-references.

- New paragraph in afterboot(8) about entropy citing entropy(7) for
  more details.

This change addresses many of the issues discussed in security/55659.
This is a first draft; happy to take improvements to the man pages and
scripted messages to improve clarity.

I considered changing motd to include an entropy warning with a
reference to the entropy(7) man page, but it's a little trickier:
- Not sure it's appropriate for all users to see at login rather than
  users who have power to affect the entropy estimate (maybe it is,
  just haven't decided).
- We only have a mechanism for changing once at boot; the message would
  remain until next boot even if an operator adds enough entropy.
- The mechanism isn't really conducive to making a message appear
  conditionally from boot to boot.

Revision 1.15 / (download) - annotate - [select for diffs], Mon Jul 3 21:30:59 2017 UTC (4 years, 3 months ago) by wiz
Branch: MAIN
CVS Tags: phil-wifi-base, phil-wifi-20200421, phil-wifi-20200411, phil-wifi-20200406, phil-wifi-20191119, phil-wifi-20190609, phil-wifi, pgoyette-compat-merge-20190127, pgoyette-compat-base, pgoyette-compat-20190127, pgoyette-compat-20190118, pgoyette-compat-1226, pgoyette-compat-1126, pgoyette-compat-1020, pgoyette-compat-0930, pgoyette-compat-0906, pgoyette-compat-0728, pgoyette-compat-0625, pgoyette-compat-0521, pgoyette-compat-0502, pgoyette-compat-0422, pgoyette-compat-0415, pgoyette-compat-0407, pgoyette-compat-0330, pgoyette-compat-0322, pgoyette-compat-0315, pgoyette-compat, perseant-stdc-iso10646-base, perseant-stdc-iso10646, netbsd-9-base, netbsd-9-2-RELEASE, netbsd-9-1-RELEASE, netbsd-9-0-RELEASE, netbsd-9-0-RC2, netbsd-9-0-RC1, netbsd-9, is-mlppp-base, is-mlppp
Changes since 1.14: +2 -2 lines
Diff to previous 1.14 (colored)

Remove workaround for ancient HTML generation code.

Revision 1.14 / (download) - annotate - [select for diffs], Sat May 21 21:07:43 2016 UTC (5 years, 4 months ago) by christos
Branch: MAIN
CVS Tags: prg-localcount2-base3, prg-localcount2-base2, prg-localcount2-base1, prg-localcount2-base, prg-localcount2, pgoyette-localcount-base, pgoyette-localcount-20170426, pgoyette-localcount-20170320, pgoyette-localcount-20170107, pgoyette-localcount-20161104, pgoyette-localcount-20160806, pgoyette-localcount-20160726, pgoyette-localcount, netbsd-8-base, netbsd-8-1-RELEASE, netbsd-8-1-RC1, netbsd-8-0-RELEASE, netbsd-8-0-RC2, netbsd-8-0-RC1, matt-nb8-mediatek-base, matt-nb8-mediatek, localcount-20160914, bouyer-socketcan-base1, bouyer-socketcan-base, bouyer-socketcan
Branch point for: netbsd-8
Changes since 1.13: +19 -2 lines
Diff to previous 1.13 (colored)

Mention MPROTECT issues

Revision 1.13 / (download) - annotate - [select for diffs], Sun Jun 14 16:56:36 2015 UTC (6 years, 4 months ago) by christos
Branch: MAIN
Changes since 1.12: +2 -4 lines
Diff to previous 1.12 (colored)

the data segment is not randomized.

Revision 1.12 / (download) - annotate - [select for diffs], Wed May 13 11:36:12 2015 UTC (6 years, 5 months ago) by shm
Branch: MAIN
Changes since 1.11: +2 -3 lines
Diff to previous 1.11 (colored)

0 mappings are currently disabled on all architectures.

Revision 1.11 / (download) - annotate - [select for diffs], Tue Mar 18 18:20:40 2014 UTC (7 years, 7 months ago) by riastradh
Branch: MAIN
CVS Tags: yamt-pagecache-base9, tls-maxphys-base, tls-earlyentropy-base, tls-earlyentropy, riastradh-xf86-video-intel-2-7-1-pre-2-21-15, netbsd-7-nhusb-base-20170116, netbsd-7-nhusb-base, netbsd-7-nhusb, netbsd-7-base, netbsd-7-2-RELEASE, netbsd-7-1-RELEASE, netbsd-7-1-RC2, netbsd-7-1-RC1, netbsd-7-1-2-RELEASE, netbsd-7-1-1-RELEASE, netbsd-7-1, netbsd-7-0-RELEASE, netbsd-7-0-RC3, netbsd-7-0-RC2, netbsd-7-0-RC1, netbsd-7-0-2-RELEASE, netbsd-7-0-1-RELEASE, netbsd-7-0, netbsd-7
Changes since 1.10: +1 -1 lines
Diff to previous 1.10 (colored)

Merge riastradh-drm2 to HEAD.

Revision 1.10 / (download) - annotate - [select for diffs], Sat Jul 20 21:39:59 2013 UTC (8 years, 3 months ago) by wiz
Branch: MAIN
CVS Tags: riastradh-drm2-base3, riastradh-drm2-base2, riastradh-drm2-base1
Changes since 1.9: +2 -2 lines
Diff to previous 1.9 (colored)

Use Mt for email addresses.

Revision 1.9 / (download) - annotate - [select for diffs], Fri Mar 15 19:32:31 2013 UTC (8 years, 7 months ago) by njoly
Branch: MAIN
CVS Tags: riastradh-drm2-base, agc-symver-base, agc-symver
Branch point for: riastradh-drm2
Changes since 1.8: +2 -2 lines
Diff to previous 1.8 (colored)

Fix a few file system paths to use Pa macro.

Revision 1.8 / (download) - annotate - [select for diffs], Wed Mar 30 11:41:48 2011 UTC (10 years, 6 months ago) by jruoho
Branch: MAIN
CVS Tags: yamt-pagecache-tag8, yamt-pagecache-base8, yamt-pagecache-base7, yamt-pagecache-base6, yamt-pagecache-base5, yamt-pagecache-base4, yamt-pagecache-base3, yamt-pagecache-base2, yamt-pagecache-base, netbsd-6-base, netbsd-6-1-RELEASE, netbsd-6-1-RC4, netbsd-6-1-RC3, netbsd-6-1-RC2, netbsd-6-1-RC1, netbsd-6-1-5-RELEASE, netbsd-6-1-4-RELEASE, netbsd-6-1-3-RELEASE, netbsd-6-1-2-RELEASE, netbsd-6-1-1-RELEASE, netbsd-6-1, netbsd-6-0-RELEASE, netbsd-6-0-RC2, netbsd-6-0-RC1, netbsd-6-0-6-RELEASE, netbsd-6-0-5-RELEASE, netbsd-6-0-4-RELEASE, netbsd-6-0-3-RELEASE, netbsd-6-0-2-RELEASE, netbsd-6-0-1-RELEASE, netbsd-6-0, netbsd-6, matt-nb6-plus-nbase, matt-nb6-plus-base, matt-nb6-plus, cherry-xenmp-base, cherry-xenmp
Branch point for: yamt-pagecache, tls-maxphys
Changes since 1.7: +42 -3 lines
Diff to previous 1.7 (colored)

Add some random, but decent enough, reading material to SEE ALSO.

Revision 1.7 / (download) - annotate - [select for diffs], Sun Mar 20 13:07:38 2011 UTC (10 years, 7 months ago) by jruoho
Branch: MAIN
Changes since 1.6: +4 -3 lines
Diff to previous 1.6 (colored)

Now that this is a generic page, clarify the AUTHORS section a little.

Revision 1.6 / (download) - annotate - [select for diffs], Sat Mar 19 08:42:41 2011 UTC (10 years, 7 months ago) by wiz
Branch: MAIN
Changes since 1.5: +2 -2 lines
Diff to previous 1.5 (colored)

Remove duplicate word.

Revision 1.5 / (download) - annotate - [select for diffs], Fri Mar 18 16:14:49 2011 UTC (10 years, 7 months ago) by jruoho
Branch: MAIN
Changes since 1.4: +2 -4 lines
Diff to previous 1.4 (colored)

Remove xref to nonexistent option(4).

Revision 1.4 / (download) - annotate - [select for diffs], Fri Mar 18 16:12:26 2011 UTC (10 years, 7 months ago) by jruoho
Branch: MAIN
Changes since 1.3: +3 -1 lines
Diff to previous 1.3 (colored)

Note the previous also in the lead paragraph.

Revision 1.3 / (download) - annotate - [select for diffs], Fri Mar 18 16:11:13 2011 UTC (10 years, 7 months ago) by jruoho
Branch: MAIN
Changes since 1.2: +16 -1 lines
Diff to previous 1.2 (colored)

Note the 'fetch_pkg_vulnerabilities=YES' also here. In lack of a proper
name, put this under "administrative security".

Revision 1.2 / (download) - annotate - [select for diffs], Fri Mar 18 15:32:26 2011 UTC (10 years, 7 months ago) by jruoho
Branch: MAIN
Changes since 1.1: +5 -5 lines
Diff to previous 1.1 (colored)

Use .Ss for non-standard subtitles.

Revision 1.1 / (download) - annotate - [select for diffs], Fri Mar 18 15:21:57 2011 UTC (10 years, 7 months ago) by jruoho
Branch: MAIN

Move security(8) to the section 7. Discussed on source-changes a while back.
Should address PR # 35718 at least partially.

This form allows you to request diff's between any two revisions of a file. You may select a symbolic revision name using the selection box or you may type in a numeric name using the type-in text box.




CVSweb <webmaster@jp.NetBSD.org>