notbugAs an Amazon Associate I earn from qualifying purchases.
Want a good read? Try FreeBSD Mastery: Jails (IT Mastery Book 15)
Want a good monitor light? See my photosAll times are UTC
Ukraine
Port details
lockdown Hardening script for FreeBSD
2.0.0_2 security Deleted on this many watch lists=13 search for ports that depend on this port Find issues related to this port Report an issue related to this port View this port on Repology. pkg-fallout 2.0.0_2Version of this port present on the latest quarterly branch.
Forbidden FORBIDDEN: Renders system unbootable
Deprecated DEPRECATED: Renders system unbootable
Expired This port expired on: 2018-09-30
Ignore IGNORE: is forbidden: Renders system unbootable
There is no maintainer for this port.
Any concerns regarding this port should be directed to the FreeBSD Ports mailing list via ports@FreeBSD.org search for ports maintained by this maintainer
Port Added: 2004-02-29 23:22:41
Last Update: 2018-09-30 10:39:44
SVN Revision: 480949
People watching this port, also watch:: nmap, snort, sudo, pure-ftpd
License: not specified in port
WWW:
http://lockdown.TruNet.dk/
Description:
Lockdown is a script designed to harden a FreeBSD system by editing the system's configuration files and set permissions, flags and ownership on SUID, GID and "information" files. However, the main goal of lockdown is to centralize knowledge on how much you can harden the system without breaking it. Mirror: http://lockdown.loproc.dk/ WWW: http://lockdown.TruNet.dk/
Homepage    cgit ¦ GitHub ¦ GitHub ¦ GitLab ¦ SVNWeb

Manual pages:
pkg-plist: as obtained via: make generate-plist
Expand this list (14 items)
Collapse this list.
  1. bin/lockdown
  2. bin/editfile
  3. bin/editfstab
  4. bin/editkernel
  5. bin/editlogin
  6. bin/editttys
  7. lib/libcppe.so
  8. man/man1/editfile.1.gz
  9. man/man1/editfstab.1.gz
  10. man/man1/editkernel.1.gz
  11. man/man1/editlogin.1.gz
  12. man/man1/editttys.1.gz
  13. @postexec /usr/sbin/service ldconfig restart > /dev/null
  14. @postunexec /usr/sbin/service ldconfig restart > /dev/null
Collapse this list.
Dependency lines:
  • lockdown>0:security/lockdown
No installation instructions:
This port has been deleted.
PKGNAME: lockdown
Flavors: there is no flavor information for this port.
distinfo:
SHA256 (lockdown-2.0.0.tar.gz) = 61663ea1f5c2596e18c7b831b8ac7e7f4477d6d9bf6af41aadb73bf7346a598f SIZE (lockdown-2.0.0.tar.gz) = 38792

No package information for this port in our database
Sometimes this happens. Not all ports have packages. Perhaps there is a build error. Check the fallout link: pkg-fallout
This port has no dependencies.
There are no ports dependent upon this port

Configuration Options:
No options to configure
Options name:
N/A
FreshPorts was unable to extract/find any pkg message
Master Sites:
Expand this list (2 items)
Collapse this list.
  1. http://lockdown.loproc.dk/
  2. http://lockdown.trunet.dk/
Collapse this list.

Number of commits found: 24

Commit History - (may be incomplete: for full details, see links to repositories near top of page)
CommitCreditsLog message
2.0.0_2
30 Sep 2018 10:39:44
Revision:480949Original commit files touched by this commit
rene search for other commits by this committer
Remove expired ports:
2018-09-29 net/ntp-devel: Use net/ntp instead
2018-09-29 net/xrdp-devel: Use net/xrdp instead
2018-09-29 net/tigervnc-devel: Use net/tigervnc instead
2018-09-29 net/unison-devel: Use net/unison instead
2018-09-30 textproc/p5-IDNA-Punycode: Deprecated by upstream
2018-08-15 graphics/gnustep-slideshowkit: unknown license
2018-08-15 graphics/gnustep-slideshow: depends on expiring
graphics/gnustep-slideshowkit
2018-09-30 security/lockdown: Renders system unbootable
2018-09-30 devel/p5-Search-Binary: Deprecated by upstream, use
List::BinarySearch instead
2018-09-30 devel/p5-ExtUtils-Command: ExtUtils::Command has been re-incorporated
to ExtUtils-MakeMaker since 7.06, use devel/ExtUtils-MakeMaker instead
2018-09-30 editors/yui: Unmaintained upstream
2018-09-29 x11/tint-devel: Use x11/tint instead
2.0.0_2
19 Sep 2018 21:58:23
Revision:480117Original commit files touched by this commit
antoine search for other commits by this committer
Deprecate lockdown
2.0.0_2
19 Sep 2018 21:53:34
Revision:480115Original commit files touched by this commit
antoine search for other commits by this committer
Bump PORTREVISION for FORBIDDEN
2.0.0_1
19 Sep 2018 14:20:53
Revision:480095Original commit files touched by this commit
emaste search for other commits by this committer
security/lockdown: mark FORBIDDEN as it renders the system unbootable

By inspection I see that the port sets the obsolete 'nodev' flag in
/etc/fstab, and it really needs careful review for use with contemporary
FreeBSD; upstream is gone.

Reported by:	Jeffrey Bouquet on -current
Approved by:	sbruno
2.0.0_1
18 Sep 2018 19:20:18
Revision:480069Original commit files touched by this commit
emaste search for other commits by this committer
Bump PORTREVISION for changed CFLAGS

I adjusted CFLAGS in several ports to allow linking with lld on i386 but
missed the corresponding PORTREVISION bump.

Related commits:
r480023 r480045 r480047 r480048 r480049 r480061 r480062 r480068

Reported by:	antoine
Approved by:	antoine
2.0.0
18 Sep 2018 17:45:25
Revision:480045Original commit files touched by this commit
emaste search for other commits by this committer
security/lockdown: add -fPIC on i386, to allow linking with lld

By default lld does not allow non-PIC code where PIC is required.
Other architectures already apply -fPIC; do so for i386 as well.

Approved by:	portmgr (lld blanket)
Sponsored by:	The FreeBSD Foundation
2.0.0
23 May 2016 18:36:52
Revision:415738Original commit files touched by this commit
amdmi3 search for other commits by this committer
Convert tab after WWW: in pkg-descrs to single space as per PHB

Approved by:	portmgr blanket
2.0.0
19 Aug 2015 07:12:36
Revision:394718Original commit files touched by this commit
erwin search for other commits by this committer
Reset maintainer

<db@TruNet.dk>: Host or domain name not found. Name service error for
    name=TruNet.dk type=AAAA: Host not found

Sponsored by:	DK Hostmaster A/S
2.0.0
09 Aug 2015 22:24:05
Revision:393831Original commit files touched by this commit
andrew search for other commits by this committer
Adds -fPIC to CFLAGS_aarch64 to a number of ports that already have it
in the amd64 CFLAGS and are failing to build.

Approved by:	bapt
Differential Revision:	https://reviews.freebsd.org/D3321
2.0.0
25 Feb 2014 11:40:22
Revision:345965Original commit files touched by this commit
ehaupt search for other commits by this committer
- Support staging
- Use CFLAGS_amd64
2.0.0
21 Jan 2014 23:40:23
Revision:340674Original commit files touched by this commit
bapt search for other commits by this committer
Fix properties on pkg-plist
2.0.0
20 Sep 2013 22:55:26
Revision:327769Original commit files touched by this commit
bapt search for other commits by this committer
Add NO_STAGE all over the place in preparation for the staging support (cat:
security)
2.0.0
24 Oct 2011 04:17:38
Original commit files touched by this commit
dougb search for other commits by this committer
Remove more tags from pkg-descr files fo the form:

- Name
em@i.l

or variations thereof. While I'm here also fix some whitespace and other
formatting errors, including moving WWW: to the last line in the file.
2.0.0
03 Jul 2011 14:03:52
Original commit files touched by this commit
ohauer search for other commits by this committer
-remove MD5
2.0.0
19 Apr 2007 07:55:35
Original commit files touched by this commit
itetcu search for other commits by this committer
Remove 4.x support.

PR:             ports/111825
Submitted by:   Marcelo Araujo
Approved by:    maintainer
2.0.0
24 Jan 2006 01:03:33
Original commit files touched by this commit
edwin search for other commits by this committer
SHA256ify

Approved by: krion@
2.0.0
29 Jul 2005 17:18:17
Original commit files touched by this commit
vs search for other commits by this committer
Fix build on amd64 with -fPIC

PR:             ports/84156
Submitted by:   Hirohisa Yamaguchi
Approved by:    maintainer

Note w.r.t. 4.x: The .depend-issue can be fixed through 'gmake'.
However, then it still needs a patch for a missing <sys/time.h>, and still
won't build with neither gcc-2.95, 3.4 or 4.0, so I didn't bother.
2.0.0
13 Jul 2005 23:51:15
Original commit files touched by this commit
lawrance search for other commits by this committer
Mark broken on 4.x

Approved by:    maintainer
2.0.0
29 Jun 2005 10:59:40
Original commit files touched by this commit
lawrance search for other commits by this committer
Fix pkg-plist

Reported by:    kris
2.0.0
24 Jun 2005 17:02:18
Original commit files touched by this commit
lawrance search for other commits by this committer
Update to 2.0.0

PR:             ports/82614
Submitted by:   Daniel Blankensteiner <db@trunet.dk> (maintainer)
1.0.1
10 May 2004 13:14:22
Original commit files touched by this commit
krion search for other commits by this committer
- Update to version 1.0.1

PR:             ports/66458
Submitted by:   maintainer
1.0
16 Apr 2004 14:52:28
Original commit files touched by this commit
krion search for other commits by this committer
- Update to version 1.0

PR:             ports/65618
Submitted by:   maintainer
0.1.1
28 Mar 2004 14:34:32
Original commit files touched by this commit
krion search for other commits by this committer
- Update to version 0.1.1

PR:             ports/64841
Submitted by:   maintainer
0.1
29 Feb 2004 23:22:13
Original commit files touched by this commit
sergei search for other commits by this committer
Add lockdown 0.1:

Lockdown is a hardening system written in C++ for FreeBSD
and released under the BSD license.

Lockdown was designed to harden FreeBSD's base system. It does so
by editing the systems configuration files and set permissions,
flags and ownership on SUID, GID and information files.
Lockdown was meant to be run only once, so you can quickly
and without forgetting something, get a secure system running.

WWW:    http://lockdown.TruNet.dk/

PR:             62714
Submitted by:   Daniel Blankensteiner <db@TruNet.dk>

Number of commits found: 24