Page MenuHomeFreeBSD

Add SECURITY section to loader(8)
ClosedPublic

Authored by trasz on Aug 13 2018, 12:26 PM.
Tags
None
Referenced Files
Unknown Object (File)
Mon, Apr 22, 10:43 AM
Unknown Object (File)
Mar 20 2024, 12:26 PM
Unknown Object (File)
Mar 11 2024, 12:54 PM
Unknown Object (File)
Mar 11 2024, 12:54 PM
Unknown Object (File)
Mar 11 2024, 12:54 PM
Unknown Object (File)
Mar 11 2024, 12:54 PM
Unknown Object (File)
Mar 11 2024, 12:54 PM
Unknown Object (File)
Mar 8 2024, 1:04 AM
Subscribers

Details

Summary

Add SECURITY section to loader(8).

Diff Detail

Repository
rS FreeBSD src repository - subversion
Lint
Lint Not Applicable
Unit
Tests Not Applicable

Event Timeline

Update the .Dd at the top of the file for this content change.
Thanks for working on this.

This revision is now accepted and ready to land.Aug 13 2018, 2:32 PM

This is useful, but some parts seem too specific to usage in appliances.

stand/man/loader.8
968–975 ↗(On Diff #46619)

This recommendation seems geared towards appliances and kiosk type devices; PCs and servers tend not to be secured this way (if firmware and /etc/ttys are not secured along with loader, securing loader mostly makes it harder to recover from breakage and does not improve security).

Perhaps this can be changed to just mention that setting .Va password or setting .Va autoboot_delay to -1 can prevent unauthorized access to the loader command line.

Tone it down somewhat, mention the firmware.

This revision now requires review to proceed.Aug 14 2018, 1:22 PM

Looks good. Don't forget the .Dd bump.

This revision is now accepted and ready to land.Aug 14 2018, 3:33 PM
This revision was automatically updated to reflect the committed changes.