miod
194ee296ec
Remove irrelevant devices from the ramdisk target; spotted by deraadt
10 years ago
sthen
75a71ee2cd
pass daemon_flags to nsd-control when used to check/reload/stop nsd,
the only useful option here is to specify an alternative config path,
which must be used for these operations as well as for startup.
10 years ago
tedu
11890a8cbe
don't give people bad ideas about pool_debug
10 years ago
dcoppa
9a6537b480
tedu ~/.klogin
10 years ago
okan
82176404fa
re-add _ppp for npppd here as well; ok ajacoutot
10 years ago
yasuoka
ed2d182d9e
Get back "_ppp" user and "_ppp" group. From now they will be solely
used by npppd.
ok deraadt
10 years ago
bluhm
69a1f54006
Redirecting stderr to /dev/null suppresses all errors. Instead use
the new status=none feature to make dd quiet.
OK halex@
10 years ago
tedu
296ccc2fdf
jmc spotted more ruptime tentacles
10 years ago
tedu
f6ba35880f
rm rwhod tentacles
10 years ago
aoyama
b94f030537
regen
10 years ago
aoyama
b61302dbc3
Add pcex{mem,io} entries to MAKEDEV.
ok miod@
10 years ago
ajacoutot
bc9e3c6e93
Remove krb5 bits from rc(8).
ok reyk@
10 years ago
reyk
0b6d3f347f
Remove the kerberos login methods.
ok henning@
10 years ago
reyk
43494a61b1
Remove kerberosV, it is not special anymore.
ok henning@
10 years ago
reyk
e6ebb39335
Remove kerberosV from etc/
ok deraadt@ guenther@
10 years ago
okan
7cf71550c8
remove rshd example; ok sthen
10 years ago
ajacoutot
2238e58bfc
Bye bye *hosts.equiv.
ok deraadt@
10 years ago
tedu
62fc9a56c8
hosts.equiv is a ghost from bsd past
10 years ago
henning
4548447cbb
stop "advertising" disabling pmtud and window size increasing
very rarely if ever needed any more. we should not trick people into
thinking they are impoving sth doing so, it's rather the opposite
these days.
ok claudio
10 years ago
henning
2aaf6a8706
use "!received-on any" to absolutely ensure that we're not forwarding
carp, rpc or nfs traffic in the initial ruleset active during network
startup for a short time (or a much longer time if /etc/pf.conf is
screwed up). ok phessler
10 years ago
schwarze
f3d7fdd09c
Switch to the new makewhatis(8)/apropos(1)/whatis(1) combo.
"commit the switch now" espie@ "go for it" deraadt@
See the apropos(1) manual for a description of what's new.
On machines where you want the full functionality,
run "sudo makewhatis" and put "MAKEWHATISARGS=' '" into weekly.local(8).
Otherwise, when upgrading via source, run "sudo makewhatis -Q".
10 years ago
miod
19582a6077
Move build machinery for libcrypto from libssl/crypto to libcrypto, as well
as configuration files; split manpages and .pc files between libcrypto and
libssl.
No functional change, only there to make engineering easier, and libcrypto
sources are still found in libssl/src/crypto at the moment.
ok reyk@, also discussed with deraadt@ beck@ and the usual crypto suspects.
10 years ago
miod
7d60b870ca
regen
10 years ago
miod
04aceaa3cb
Add wskbd nodes to the bsd.rd /dev posse; allows kbd -l to work as intended
in the install media. Reported by Donovan Watteau
10 years ago
millert
0d52db320e
Fix syntax error in commented out local-zone entry. OK sthen@
10 years ago
deraadt
e30606643b
increase size of iso media (try 2)
10 years ago
deraadt
64c8729c88
increase size of iso media
10 years ago
gilles
22f8f414dd
do not keep hoststat and purgestat, they are pointing to the sendmail
executable and will not serve any purpose with smtpd by default
ok jmc@ tedu@
10 years ago
tedu
f57f1925af
end experimental login.conf template support. one file per machine.
ok deraadt millert
10 years ago
sthen
ae00ab49ef
sum -> cksum, ok deraadt
10 years ago
tedu
865935a62a
okan reminds me hosts.allow lived here too
10 years ago
ajacoutot
25a5dcaa2a
Stop monitoring apache files.
ok florian@ jung@ sthen@
10 years ago
sthen
8134aa11c6
Add /var/unbound/dev/log, it isn't needed for initial startup because Unbound
opens the log before chrooting, but this handles the case where syslogd is
restarted during Unbound's runtime.
10 years ago
sthen
85309b05df
Remove commented-out module-config line, it is already set to "validator
iterator" by default. Pointed out by Patrik Lundin.
10 years ago
ajacoutot
256de60572
Add nginx default log files to the rotation.
ok jung@ stephan@
tweaks and ok sthen@
10 years ago
sthen
4dd1a5962e
Install a /var/unbound/db directory, writable by the _unbound daemon,
and use it as the default location for the DNSSEC root key. Update default
config for this location.
With this, the only step required to enable DNSSEC validation is to
uncomment these default config entries and restart:
#module-config: "validator iterator"
#auto-trust-anchor-file: "/var/unbound/db/root.key"
There is no longer a requirement to run unbound-anchor manually to
update the root key. The rc.d script will take care of updates at boot,
and Unbound will manage the file itself at runtime.
Test with "dig test.dnssec-or-not.net txt @127.0.0.1" or similar.
10 years ago
miod
8dbd387ec6
Tell the manpage machinery to not output Xr to hd(4/vax) in MAKEDEV.8, since
such a manpage does not currently exist. Requested by jmc@
10 years ago
tedu
a3382b4cd8
no rest for the wicked. increase user blf logrounds default to 8(+2).
increase root to 9(+1).
ok deraadt (and a thank you to miod for helping to reduce the set of
architectures harmed by this)
10 years ago
miod
7766679fe4
Retire hp300, mvme68k and mvme88k ports. These ports have no users, keeping
this hardware alive is becoming increasingly difficult, and I should heed the
message sent by the three disks which have died on me over the last few days.
Noone sane will mourn these ports anyway. So long, and thanks for the fish.
10 years ago
sthen
9690bbcd18
No need to keep a manually maintained list of system daemons here, ftpd can
disallow them itself. ok deraadt@ millert@, gsoares@ and aja@ like it too.
("nobody" still needs to be listed).
10 years ago
tedu
18caccfdb7
uucp cleansing
10 years ago
sthen
4160ff8632
no more _ppp user
10 years ago
sthen
733c769ec2
ppp.log was just for ppp(8)
10 years ago
deraadt
c6fc6500f7
_ppp uid/gid will come up for recycling (but please not within a year)
10 years ago
deraadt
357cb1b33e
the userland ppp(9) code goes awa. Having too much ppp choice in the
tree results in one-true-ppp not coming into existance. This code is
essentially un-audited and quite dangerous.
ok claudio sthen
10 years ago
sthen
85815eee50
add unbound.conf and (dnssec) root.key to changelist
10 years ago
sthen
216f65a4eb
Add _unbound user here too. Reminded by aja@
10 years ago
sthen
cc6c887d94
Enable Unbound in base, ok deraadt@
10 years ago
miod
423a89bb3d
Bump the cdXX image from 12MB to 13MB.
10 years ago
sthen
62f586f294
httpd_flags was still used here; remove it.
Add a log socket in /var/www/dev/log if nginx is enabled, it is needed as
the openlog() call is done after chrooting.
ok brad@ florian@ deraadt@
10 years ago