From 8ba83fb185781acfe6bae326975df6bb00e224a0 Mon Sep 17 00:00:00 2001 From: jkh Date: Tue, 7 Nov 2000 23:05:14 +0000 Subject: [PATCH] For High security profile, set securelevel to 1 to protect /dev/*mem and mounted disks, among other things. Requested by: kirk --- release/sysinstall/config.c | 2 ++ usr.sbin/sade/config.c | 2 ++ usr.sbin/sysinstall/config.c | 2 ++ 3 files changed, 6 insertions(+) diff --git a/release/sysinstall/config.c b/release/sysinstall/config.c index 5c2e24a7203d..6199345c7e6e 100644 --- a/release/sysinstall/config.c +++ b/release/sysinstall/config.c @@ -516,6 +516,8 @@ configSecurityHigh(dialogMenuItem *self) variable_set2("sshd_enable", "YES", 1); variable_set2("portmap_enable", "NO", 1); variable_set2("nfs_server_enable", "NO", 1); + variable_set2("kern_securelevel_enable", "YES", 1); + variable_set2("kern_securelevel", "1", 1); if (self) msgConfirm("High security settings have been selected.\n\n" diff --git a/usr.sbin/sade/config.c b/usr.sbin/sade/config.c index 5c2e24a7203d..6199345c7e6e 100644 --- a/usr.sbin/sade/config.c +++ b/usr.sbin/sade/config.c @@ -516,6 +516,8 @@ configSecurityHigh(dialogMenuItem *self) variable_set2("sshd_enable", "YES", 1); variable_set2("portmap_enable", "NO", 1); variable_set2("nfs_server_enable", "NO", 1); + variable_set2("kern_securelevel_enable", "YES", 1); + variable_set2("kern_securelevel", "1", 1); if (self) msgConfirm("High security settings have been selected.\n\n" diff --git a/usr.sbin/sysinstall/config.c b/usr.sbin/sysinstall/config.c index 5c2e24a7203d..6199345c7e6e 100644 --- a/usr.sbin/sysinstall/config.c +++ b/usr.sbin/sysinstall/config.c @@ -516,6 +516,8 @@ configSecurityHigh(dialogMenuItem *self) variable_set2("sshd_enable", "YES", 1); variable_set2("portmap_enable", "NO", 1); variable_set2("nfs_server_enable", "NO", 1); + variable_set2("kern_securelevel_enable", "YES", 1); + variable_set2("kern_securelevel", "1", 1); if (self) msgConfirm("High security settings have been selected.\n\n"