From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from sigma.offblast.org ([199.191.58.44]) by pp; Wed May 20 16:10:42 EDT 2015 Received: from 172.56.39.84 ([172.56.39.84]) by sigma; Wed May 20 16:10:36 EDT 2015 User-Agent: K-9 Mail for Android In-Reply-To: References: MIME-Version: 1.0 Content-Type: multipart/alternative; boundary="----PH4FK6MVGSZZWV9R6ACVMCC4X2XB6J" Content-Transfer-Encoding: 7bit Subject: Re: [9front] proposal: disable most of /rc/bin/services/tcp* by default From: mischief@9.offblast.org Date: Wed, 20 May 2015 13:10:31 -0700 To: 9front@9front.org,sl@9front.org Message-ID: List-ID: <9front.9front.org> X-Glyph: ➈ X-Bullshit: CMS rich-client solution ------PH4FK6MVGSZZWV9R6ACVMCC4X2XB6J Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable I am in favor of this and also putting the service directory in =2Ehgignore= =2E Creation of log files would be nice too=2E On May 20, 2015 11:16:35 AM PDT, sl@9front=2Eorg wrote: >Why are so many services enabled by default? > >I propose to disable the following in the default install by moving >them from tcp* to !tcp*=2E Functionality can be enabled by simply >copying !tcp* back to tcp* (and following whatever other procedures >were already required)=2E > >Let's turn these off: > > tcp110 # pop3 > tcp143 # imap > tcp21 # ftp > tcp23 # telnet > tcp25 # smtp > tcp53 # dns > tcp513 # rlogind > tcp993 # imap over tls > tcp995 # pop3 over tls > >In addition: Items that are left enabled by default (and really, even >the ones disabled by default) should be checked to ensure that the >installer creates the log files they attempt to write to=2E > >I volunteer to do this if no one objects=2E > >sl ------PH4FK6MVGSZZWV9R6ACVMCC4X2XB6J Content-Type: text/html; charset=utf-8 Content-Transfer-Encoding: quoted-printable I am in favor of this and also putting the service= directory in =2Ehgignore=2E Creation of log files would be nice too=2E
=
On May 20, 2015 11:16:35 AM PDT, sl@9front= =2Eorg wrote:
Why are so many services enabled by default?
I propose to disable the following in the default install by moving
them from tcp* to !tcp*=2E Functionality can be enabled by simply
c= opying !tcp* back to tcp* (and following whatever other procedures
wer= e already required)=2E

Let's turn these off:

tcp110 = # pop3
tcp143 # imap
tcp21 # ftp
tcp23 # telnet
tcp= 25 # smtp
tcp53 # dns
tcp513 # rlogind
tcp993 # imap over= tls
tcp995 # pop3 over tls

In addition: Items that are le= ft enabled by default (and really, even
the ones disabled by default) = should be checked to ensure that the
installer creates the log files t= hey attempt to write to=2E

I volunteer to do this if no one obje= cts=2E

sl

------PH4FK6MVGSZZWV9R6ACVMCC4X2XB6J--