Post B6Qk1WGMETxfYeDyYy by Larvitz@burningboard.net
(DIR) More posts by Larvitz@burningboard.net
(DIR) Post #B6Qk1WGMETxfYeDyYy by Larvitz@burningboard.net
1 likes, 4 repeats
I’ve been replacing sudo/doas on most of my FreeBSD boxes with something much smaller: mdo(1) + mac_do(4) from base.No port. No sudoers parser. No setuid helper. Just a kernel MAC policy, a sysctl rule, and an explicit “SSH is the gate” security model.Wrote up the full walkthrough for FreeBSD 15, including rule syntax, examples, caveats, and my surrounding hardening sysctls:https://blog.hofstede.it/mdo-on-freebsd-15-base-system-privilege-delegation-with-mac_do/#FreeBSD #runbsd #mdo #mac_do #sysadmin #security
(DIR) Post #B6R07I2pbgSYStfg4u by feld@friedcheese.us
1 likes, 0 repeats
@Larvitz good post, but has an errorsysctl: security.mac.do.rules=gid=wheel>uid=0,gid=*,+gid=*: Invalid argumentyou can't use "wheel" in the rule. It has to be the actual wheel gid of 0
(DIR) Post #B6R07NBsTTfOQOwTNA by Larvitz@burningboard.net
1 likes, 0 repeats
@feld thank you for pointing that out. Article is updated with a note. I attributed you in the top of the article for the helpful feedback!