Re: /etc/rc.d/ipsec starts not in time

From: Hajimu UMEMOTO <ume_at_mahoroba.org>
Date: Sun, 16 Nov 2003 17:24:54 +0900
Hi,

>>>>> On Sat, 15 Nov 2003 15:21:34 -0800
>>>>> Terry Lambert <tlambert2_at_mindspring.com> said:

> It is not sufficient.  There is setkey(8) in /usr/sbin.  It means that
> we cannot protect NFS exported /usr by IPsec.  If there is no
> objection, I wish to move setkey(8) into /sbin like NetBSD did.

tlambert2> This type of order inversion is common.

tlambert2> Can we simply delay exportation until later in the boot process?
tlambert2> Wouldn't this have the same effect?

Oops, I should explain the situation clearly.  The client which mounts
/usr by NFS cannot use IPsec due to lack of setkey(8).

Sincerely,

--
Hajimu UMEMOTO _at_ Internet Mutual Aid Society Yokohama, Japan
ume_at_mahoroba.org  ume_at_bisd.hitachi.co.jp  ume_at_{,jp.}FreeBSD.org
http://www.imasy.org/~ume/
Received on Sat Nov 15 2003 - 23:26:42 UTC

This archive was generated by hypermail 2.4.0 : Wed May 19 2021 - 11:37:29 UTC