| |
#device mountpoint fs options dump pass
/dev/ad0s2b none swap sw 0 0
/dev/ad0s2a / ufs rw 2 2
/dev/ad0s2f /usr ufs rw,nodev 2 2
/dev/ad0s2c /home ufs rw,nosuid,nodev,userquota 2 1
/dev/ad0s2e /var ufs rw,noexec,nosuid,nodev 2 2
/dev/acd0c /cdrom cd9660 ro,noauto 0
net.inet.tcp.rfc1323=1
net.inet.tcp.newreno=1
net.inet.tcp.inflight_enable=1
net.inet.tcp.inflight_min=6144
net.inet.tcp.sendspace=32768
net.inet.tcp.recvspace=65535
net.inet.tcp.log_in_vain=1
net.inet.tcp.always_keepalive=1
net.inet.tcp.blackhole=2
net.inet.tcp.delayed_ack=1
net.inet.tcp.strict_rfc1948=1
net.inet.tcp.isn_reseed_interval=1800
net.inet.tcp.syncookies=1
net.inet.tcp.syncache.hashsize=512
net.inet.tcp.syncache.cachelimit=15359
net.inet.tcp.syncache.bucketlimit=30
net.inet.tcp.syncache.rexmtlimit=3
net.inet.icmp.maskrepl=0
net.inet.icmp.bmcastecho=0
net.inet.icmp.icmplim=300
net.inet.udp.sendspace=32768
net.inet.udp.recvspace=32768
net.inet.udp.maxdgram=28672
net.inet.udp.blackhole=1
net.inet.udp.log_in_vain=1
net.inet.ip.ttl=128
net.inet.ip.forwarding=1 # ou check_interface=1
net.inet.ip.sourceroute=0
net.inet.ip.accept_sourceroute=0
net.inet.ip.rtexpire=60
net.inet.ip.rtminexpire=10
net.link.ether.inet.max_age=1200
vfs.vmiodirenable=1
kern.coredump=1
kern.corefile=%N.sexfault
kern.ps_showallprocs=0
kern.maxprocperuid=512
kern.maxfilesperproc=1024
kern.maxfiles=16384
kern.ipc.somaxconn=4096
kern.ipc.maxsockbuf=262144
# options
Defaults syslog=auth, mail_no_user, lecture, insults,
syslog_badpri=alert, rootpw, passwd_timeout=3, authenticate
Defaults:FULLTIMERS !lecture
# alias utilisateurs > root
User_Alias FULLTIMERS = eberkut
User_Alias PARTTIMERS = bindmaster,webmaster
Run_alias OP = root,named,www
# alias commandes
Cmnd_Alias DEBUG = /usr/bin/mt,/usr/sbin/dump,/usr/sbin/restore,
/usr/sbin/dd,/usr/bin/gdb,/usr/bin/ktrace,
/usr/bin/kdump,/usr/bin/file,/usr/bin/truss,
/usr/bin/ldd,/usr/bin/objdump,/usr/bin/strings,
/usr/bin/nm,/usr/bin/size,/usr/bin/kill
Cmnd_Alias KILL = /usr/sbin/shutdown,/usr/sbin/halt,/usr/sbin/reboot
Cmnd_Alias SHELLS = /usr/bin/sh,/usr/bin/csh,/usr/local/bin/zsh,
/usr/bin/ssh,/usr/X11R6/bin/startx
Cmnd_Alias USER = /usr/bin/su,/usr/sbin/adduser, /usr/sbin/rmuser,
/usr/bin/chsh
Cmnd_Alias NET = /usr/sbin/ppp,/usr/sbin/ifconfig,/usr/sbin/ipfw
Cmnd_Alias DAEMON = /usr/sbin/named,/usr/local/apache,/usr/bin/sshd
Cmnd_Alias RIGHTS = /usr/sbin/chroot,/usr/sbin/jail,/usr/sbin/chown,
/usr/bin/chmod
Cmnd_Alias CDROM = /sbin/umount /cdrom, /sbin/mount_cd9660 /dev/acd0c /cdrom
# directives
root ALL = (ALL) ALL
FULLTIMERS ALL = NOPASSWD: DEBUG, KILL, SHELLS, RIGHTS, USER, NET, DAEMON
PARTTIMERS ALL = DEBUG, NET, (OP) NOPASSWD: DAEMON
ALL ALL = NOPASSWD: CDROM
/dev/ad0s1c /home ufs rw,nosuid,userquota 2 2
Quotas for user eberkut:
/usr/home/eberkut: blocks in use: 0, limits (soft = 80, hard = 100)
inodes in use: 0, limits (soft = 40, hard = 60)
/usr/var: blocks in use: 0, limits (soft = 80, hard = 90)
inodes in use: 0, limits (soft = 60, hard = 80)
default:
:copyright=/etc/COPYRIGHT:
:welcome=/etc/motd:
:setenv=MAIL=/var/mail/$,BLOCKSIZE=K,FTP_PASSIVE_MODE=YES:
:path=/sbin /bin /usr/sbin /usr/bin /usr/games
/usr/local/sbin /usr/local/bin /usr/X11R6/bin ~/bin:
:nologin=/var/run/nologin:
:cputime=unlimited:
:datasize=unlimited:
:stacksize=unlimited:
:memorylocked=unlimited:
:memoryuse=unlimited:
:filesize=unlimited:
:coredumpsize=unlimited:
:openfiles=unlimited:
:maxproc=unlimited:
:sbsize=1048576:
:priority=0:
:umask=022:
:idletime=3600s:
:minpasswordlen=8:
:mixpasswordcase=true:
:passwd_format=blf:
:passwordtime=30d:
:warnpasswordtime=2d:
# the field Tc enables us to return a user or a group to a definite class
#. You can overwriter of the limits of default by adding them with
# new classifies. Adduser enables you to add a user to a class.
staff:
:tc=default
:password_time=unlimited
:cputime=1h30m:
:filesize=unlimited:
:datasize=20M:
:stacksize=10M:
:coredumpsize=10M:
:memoryuse=30M:
:memorylocked=10M:
:maxproc=32:
:openfiles=24:
:requirehome@:
($:~)=> mtree -s 31337 -K cksum -K sha1digest -K uname -x -c -p /your/path >
/etc/mtree/file.spec
($:~)=> mtree -s 31337 -K cksum -K sha1digest -K uname -x -c -p /bin >
/etc/mtree/bin.spec
($:~)=> mtree -s 31337 -K cksum -K sha1digest -K uname -x -c -p /sbin >
/etc/mtree/sbin.spec
($:~)=> mtree -s 31337 -K cksum -K sha1digest -K uname -x -c -p /usr/libexec
> /etc/mtree/libexec.spec
($:~)=> mtree -s 31337 -K cksum -K sha1digest -K uname -x -c -p /usr/lib >
/etc/mtree/lib.spec
($:~)=> mtree -s 31337 -K cksum -K sha1digest -K uname -x -c -p
/usr/share/lib > /etc/mtree/sharelib.spec
($:~)=> mtree -s 31337 -K cksum -K sha1digest -K uname -x -c -p /boot >
/etc/mtree/boot.spec
úÁËÌÁÄËÉ ÎÁ ÓÁÊÔÅ ðÒÏÓÌÅÄÉÔØ ÚÁ ÓÔÒÁÎÉÃÅÊ |
Created 1996-2024 by Maxim Chirkov äÏÂÁ×ÉÔØ, ðÏÄÄÅÒÖÁÔØ, ÷ÅÂÍÁÓÔÅÒÕ |