1 |
On Sun, 2002-01-20 at 15:33, Aron Griffis wrote: |
2 |
> Hello Developers, |
3 |
> |
4 |
> I'm planning to add xinetd snippets for rlogind and telnetd into the |
5 |
> netkit ebuilds. These will install into /etc/xinetd.d, similar to the |
6 |
> snippets which already install there. This seems appropriate to me for |
7 |
> a couple reasons: |
8 |
> |
9 |
> (1) xinetd has external connections disabled by default in |
10 |
> /etc/xinetd.conf. Therefore this addition doesn't open up security |
11 |
> holes by default. The system administrator still needs to change |
12 |
> /etc/xinetd.conf (or the appropriate snippet) to allow network |
13 |
> connections to these daemons. |
14 |
> |
15 |
> (2) xinetd is further disabled by default since it requires the |
16 |
> administrator to inentionally "rc-update add xinetd default". |
17 |
> |
18 |
> (3) Considering the protection inherent in the system provided by the |
19 |
> policies in (1) and (2), it seems amiss to not supply working |
20 |
> snippets in /etc/xinetd.d for these daemons. Additionally, |
21 |
> netkit-rsh and netkit-telnet don't install by default, so I think |
22 |
> all the bases are covered. |
23 |
> |
24 |
> I'll make these changes in the next 24 hours or so unless there is |
25 |
> a reasonable objection. |
26 |
> |
27 |
> Aron |
28 |
I would not like that. Since some of us may modify xinetd.conf to run |
29 |
public services and having telnet/stuff added could come as a surprise. |
30 |
How about adding them as comments, so if one wants them, all that needs |
31 |
to be done is uncommenting of a few lines. |
32 |
> _______________________________________________ |
33 |
> gentoo-dev mailing list |
34 |
> gentoo-dev@g.o |
35 |
> http://lists.gentoo.org/mailman/listinfo/gentoo-dev |