Re: OpenBSD

"Theo de Raadt" <[email protected]> Tue, 24 May 2022 19:13:47 -0600
Newsgroups gmane.os.openbsd.advocacy
Message-ID <[email protected]>
That is either a funny joke, or it shows you don't understand Unix.

It doesn't work because, root is all-powerful and will simply replace
the whole /etc directory with tar cf - | tar xf -, and look at that
the file you locked is in an irrelevant directory

justina colmena ~biz <[email protected]> wrote:

> Glad this was mentioned. You can go like this I think
> =

> [OpenBSD] # chflags schg /etc/resolv.conf
> =

> and that is irreversible until the system is rebooted to single user mod=
e. In Linux (ext2-3-4) one would use a similar command, but the system-lev=
el version is apparently not available.
> =

> [Linux] # chattr +i /etc/resolv.conf
> [OpenBSD] # chflags uchg /etc/resolv.conf
> =

> But this is really an upstream "dhclient" issue of this particular file =
being overwritten in a context of persistent hacking with a German-style l=
aw-enforcement or law-enforcement-like access which can be enabled on a wa=
rrant and of course re-enabled whenever it is shut off by the user or cons=
umer of the said Operating System.
> =

> =

> On May 23, 2022 9:36:53 PM AKDT, Richard Bostrom <bostrom.richardh@iclou=
d.com> wrote:
> >Dear sirs and ladies!May I please ask. Is there any way to force OpenDN=
S settings on a BSD installation, in such a way that the "su" cannot chang=
e the dns settings (.conf file)?Thank you.Best regards
> >Richardh Bostrom
> -- =

> Sent from my Android device with K-9 Mail. Please excuse my brevity.