Hajimu UMEMOTO wrote: > >>>>> Kostyuk Oleg <cub_at_cub.org.ua> said: > > cub> Problem is in order of starting /etc/rc.d/ipsec. > cub> It must start BEFORE any network interaction, > cub> may be even before configuring interfaces. > cub> But I not sure in case with diskless mashines. > > cub> -# BEFORE: DAEMON > cub> +# BEFORE: NETWORK > > It is not sufficient. There is setkey(8) in /usr/sbin. It means that > we cannot protect NFS exported /usr by IPsec. If there is no > objection, I wish to move setkey(8) into /sbin like NetBSD did. This type of order inversion is common. Can we simply delay exportation until later in the boot process? Wouldn't this have the same effect? -- TerryReceived on Sat Nov 15 2003 - 14:22:23 UTC
This archive was generated by hypermail 2.4.0 : Wed May 19 2021 - 11:37:29 UTC