Gentoo Archives: gentoo-security

From: 7v5w7go9ub0o <7v5w7go9ub0o@×××××.com>
To: gentoo-security@l.g.o
Cc: "gentoo-hardened@l.g.o" <gentoo-hardened@l.g.o>
Subject: Re: [gentoo-security] Re: [gentoo-hardened] Securing dhcpcd (client)
Date: Mon, 09 Oct 2006 19:57:34
Message-Id: op.tg56ozwqyguj3e@you.and.your.horse
In Reply to: Re: [gentoo-security] Re: [gentoo-hardened] Securing dhcpcd (client) by "Brian G. Peterson"
1 On Mon, 09 Oct 2006 15:06:15 -0400, Brian G. Peterson
2 <brian@×××××××××.com> wrote:
3
4 > On Monday 09 October 2006 13:37, 7v5w7go9ub0o wrote:
5 >> Given my lack of expertise, I'll work on a patch later, and in the
6 >> short   term I'll automate the momentary use of the dhcpcd client in a
7 >> hardened jail to negotiate a connection; then record that information;
8 >> then terminate dhcpcd; then use the recorded info and ifconfig or
9 >> iproute2 to create a direct connection. A script or little C program.
10 >
11 > Why not just use one of the other clients?
12 >
13 > pump drops privs
14 >
15 > udhcp drops privs
16 >
17 > it looks like dhclient can be configured to drop privs
18 >
19 > Why go throught the trouble to use dhcpcd?
20 >
21 > Regards,
22 >
23 > - Brian
24 >
25
26 Thanks for the follow up. I was following this page :
27
28 <http://www.gentoo.org/doc/en/handbook/handbook-x86.xml?style=printable&part=4&chap=3#doc_chap3>
29
30 which describes pump as "No longer maintained upstream, unreliable,
31 especially over modems, cannot get NIS servers from DHCP",
32 describes udhcp as "Unproven - no distro uses it by default, cannot define
33 a timeout beyond 3 seconds ",
34 describes dhclient as "Configuration is overly complex, software is quite
35 bloated .........",
36 and (IIUC) recommends dhcpcd ("the longtime Gentoo default") over the
37 other alternatives.
38
39 Perhaps this handbook is out of date (unfortunately, the individual Gentoo
40 handbook pages have no dates)?
41
42 Would certainly appreciate a contemporary recommendation. :-) (I'll be
43 googling about looking for info on these other clients)
44
45 Thanks!
46
47 --
48 gentoo-security@g.o mailing list