*BSD News Article 81101


Return to BSD News archive

Path: euryale.cc.adfa.oz.au!newshost.carno.net.au!harbinger.cc.monash.edu.au!munnari.OZ.AU!news.ecn.uoknor.edu!feed1.news.erols.com!howland.erols.net!netnews.com!udel-eecis!stimpy.eecis.udel.edu!alexandr
From: alexandr@stimpy.eecis.udel.edu (Jerry Alexandratos)
Newsgroups: comp.unix.bsd.freebsd.misc
Subject: Re: Tcp_wrappers won't work!
Date: 19 Oct 1996 13:58:40 GMT
Organization: Mos Eisley Candy Store
Lines: 37
Message-ID: <54amqg$a53@dewey.udel.edu>
References: <548avr$184@news.ox.ac.uk> <01bbbd62$271bd240$32498796@rc6855.ResComp.Arizona.EDU> <549hup$l92@dewey.udel.edu> <54a3h1$o12@news.ox.ac.uk>
NNTP-Posting-Host: stimpy.eecis.udel.edu

In article <54a3h1$o12@news.ox.ac.uk>,
Neil Long  <neil.long@materials.oxford.ac.uk> wrote:
:alexandr@stimpy.eecis.udel.edu (Jerry Alexandratos) writes:
:
:>If you built tcp_wrapper via the ports system, then the hosts.* files
:>will be located in /usr/local/etc.  Check it out, the patch is plain as
:>day.  My guess is that anything that is built with the ports system is
:>intended to be local, hence /usr/local.
:
:Well, every system I use tcp_wrappers on has the deny/allow in /etc.
:It is common to nfs mount /usr/local on many systems and putting such
:a critical system security file at the mercy of nfs mount attacks is
:not sensible IMHO.

Well every SunOS box I've ever used has ping in /etc.  It doesn't really
matter, the fact remains that no two OS's are set up exactly the same,
and there's no reason one should expect them to be.

:The packaged version needs a README or something as the man pages are
:still pointing to /etc. 

I can definitely agree with you on this one.  Chuck, are you listening?

:Don't want to be picky about this - just wanted to alert people who
:may edit the /etc files and go home without checking.

I can understand.  However, let me just go on to say that as an
administrator of a system you should probably look through the Makefile
just to be on the safe side and see exactly what's going on.  We can't
make things *too* easy on ourselves now, can we?

        --Jerry

-- 
8) Jerry Alexandratos          % - %   "Nothing inhabits my    (8 
8) alexandr@louie.udel.edu     % - %    thoughts, and oblivion (8
8) darkstar@strauss.udel.edu   % - %    drives my desires."    (8