Port details |
- lockdown Hardening script for FreeBSD
- 2.0.0_2 security
=13 2.0.0_2Version of this port present on the latest quarterly branch.
- FORBIDDEN: Renders system unbootable
DEPRECATED: Renders system unbootable This port expired on: 2018-09-30 IGNORE: is forbidden: Renders system unbootable
- There is no maintainer for this port.
- Any concerns regarding this port should be directed to the FreeBSD Ports mailing list via ports@FreeBSD.org
- Port Added: 2004-02-29 23:22:41
- Last Update: 2018-09-30 10:39:44
- SVN Revision: 480949
- People watching this port, also watch:: nmap, snort, sudo, pure-ftpd
- License: not specified in port
- WWW:
- http://lockdown.TruNet.dk/
- Description:
- Lockdown is a script designed to harden a FreeBSD system by editing the
system's configuration files and set permissions, flags and ownership on SUID,
GID and "information" files. However, the main goal of lockdown is to
centralize knowledge on how much you can harden the system without breaking
it.
Mirror: http://lockdown.loproc.dk/
WWW: http://lockdown.TruNet.dk/
-
cgit ¦ GitHub ¦ GitHub ¦ GitLab ¦
- Manual pages:
-
- pkg-plist: as obtained via:
make generate-plist - Dependency lines:
-
- lockdown>0:security/lockdown
- No installation instructions:
- This port has been deleted.
- PKGNAME: lockdown
- Flavors: there is no flavor information for this port.
- distinfo:
- SHA256 (lockdown-2.0.0.tar.gz) = 61663ea1f5c2596e18c7b831b8ac7e7f4477d6d9bf6af41aadb73bf7346a598f
SIZE (lockdown-2.0.0.tar.gz) = 38792
No package information for this port in our database- Sometimes this happens. Not all ports have packages. Perhaps there is a build error. Check the fallout link:
- This port has no dependencies.
- There are no ports dependent upon this port
Configuration Options:
- No options to configure
- Options name:
- N/A
- FreshPorts was unable to extract/find any pkg message
- Master Sites:
|
Commit History - (may be incomplete: for full details, see links to repositories near top of page) |
Commit | Credits | Log message |
2.0.0_2 30 Sep 2018 10:39:44 |
rene |
Remove expired ports:
2018-09-29 net/ntp-devel: Use net/ntp instead
2018-09-29 net/xrdp-devel: Use net/xrdp instead
2018-09-29 net/tigervnc-devel: Use net/tigervnc instead
2018-09-29 net/unison-devel: Use net/unison instead
2018-09-30 textproc/p5-IDNA-Punycode: Deprecated by upstream
2018-08-15 graphics/gnustep-slideshowkit: unknown license
2018-08-15 graphics/gnustep-slideshow: depends on expiring
graphics/gnustep-slideshowkit
2018-09-30 security/lockdown: Renders system unbootable
2018-09-30 devel/p5-Search-Binary: Deprecated by upstream, use
List::BinarySearch instead
2018-09-30 devel/p5-ExtUtils-Command: ExtUtils::Command has been re-incorporated
to ExtUtils-MakeMaker since 7.06, use devel/ExtUtils-MakeMaker instead
2018-09-30 editors/yui: Unmaintained upstream
2018-09-29 x11/tint-devel: Use x11/tint instead |
2.0.0_2 19 Sep 2018 21:58:23 |
antoine |
Deprecate lockdown |
2.0.0_2 19 Sep 2018 21:53:34 |
antoine |
Bump PORTREVISION for FORBIDDEN |
2.0.0_1 19 Sep 2018 14:20:53 |
emaste |
security/lockdown: mark FORBIDDEN as it renders the system unbootable
By inspection I see that the port sets the obsolete 'nodev' flag in
/etc/fstab, and it really needs careful review for use with contemporary
FreeBSD; upstream is gone.
Reported by: Jeffrey Bouquet on -current
Approved by: sbruno |
2.0.0_1 18 Sep 2018 19:20:18 |
emaste |
Bump PORTREVISION for changed CFLAGS
I adjusted CFLAGS in several ports to allow linking with lld on i386 but
missed the corresponding PORTREVISION bump.
Related commits:
r480023 r480045 r480047 r480048 r480049 r480061 r480062 r480068
Reported by: antoine
Approved by: antoine |
2.0.0 18 Sep 2018 17:45:25 |
emaste |
security/lockdown: add -fPIC on i386, to allow linking with lld
By default lld does not allow non-PIC code where PIC is required.
Other architectures already apply -fPIC; do so for i386 as well.
Approved by: portmgr (lld blanket)
Sponsored by: The FreeBSD Foundation |
2.0.0 23 May 2016 18:36:52 |
amdmi3 |
Convert tab after WWW: in pkg-descrs to single space as per PHB
Approved by: portmgr blanket |
2.0.0 19 Aug 2015 07:12:36 |
erwin |
Reset maintainer
<db@TruNet.dk>: Host or domain name not found. Name service error for
name=TruNet.dk type=AAAA: Host not found
Sponsored by: DK Hostmaster A/S |
2.0.0 09 Aug 2015 22:24:05 |
andrew |
Adds -fPIC to CFLAGS_aarch64 to a number of ports that already have it
in the amd64 CFLAGS and are failing to build.
Approved by: bapt
Differential Revision: https://reviews.freebsd.org/D3321 |
2.0.0 25 Feb 2014 11:40:22 |
ehaupt |
- Support staging
- Use CFLAGS_amd64 |
2.0.0 21 Jan 2014 23:40:23 |
bapt |
Fix properties on pkg-plist |
2.0.0 20 Sep 2013 22:55:26 |
bapt |
Add NO_STAGE all over the place in preparation for the staging support (cat:
security) |
2.0.0 24 Oct 2011 04:17:38 |
dougb |
Remove more tags from pkg-descr files fo the form:
- Name
em@i.l
or variations thereof. While I'm here also fix some whitespace and other
formatting errors, including moving WWW: to the last line in the file. |
2.0.0 03 Jul 2011 14:03:52 |
ohauer |
-remove MD5 |
2.0.0 19 Apr 2007 07:55:35 |
itetcu |
Remove 4.x support.
PR: ports/111825
Submitted by: Marcelo Araujo
Approved by: maintainer |
2.0.0 24 Jan 2006 01:03:33 |
edwin |
SHA256ify
Approved by: krion@ |
2.0.0 29 Jul 2005 17:18:17 |
vs |
Fix build on amd64 with -fPIC
PR: ports/84156
Submitted by: Hirohisa Yamaguchi
Approved by: maintainer
Note w.r.t. 4.x: The .depend-issue can be fixed through 'gmake'.
However, then it still needs a patch for a missing <sys/time.h>, and still
won't build with neither gcc-2.95, 3.4 or 4.0, so I didn't bother. |
2.0.0 13 Jul 2005 23:51:15 |
lawrance |
Mark broken on 4.x
Approved by: maintainer |
2.0.0 29 Jun 2005 10:59:40 |
lawrance |
Fix pkg-plist
Reported by: kris |
2.0.0 24 Jun 2005 17:02:18 |
lawrance |
Update to 2.0.0
PR: ports/82614
Submitted by: Daniel Blankensteiner <db@trunet.dk> (maintainer) |
1.0.1 10 May 2004 13:14:22 |
krion |
- Update to version 1.0.1
PR: ports/66458
Submitted by: maintainer |
1.0 16 Apr 2004 14:52:28 |
krion |
- Update to version 1.0
PR: ports/65618
Submitted by: maintainer |
0.1.1 28 Mar 2004 14:34:32 |
krion |
- Update to version 0.1.1
PR: ports/64841
Submitted by: maintainer |
0.1 29 Feb 2004 23:22:13 |
sergei |
Add lockdown 0.1:
Lockdown is a hardening system written in C++ for FreeBSD
and released under the BSD license.
Lockdown was designed to harden FreeBSD's base system. It does so
by editing the systems configuration files and set permissions,
flags and ownership on SUID, GID and information files.
Lockdown was meant to be run only once, so you can quickly
and without forgetting something, get a secure system running.
WWW: http://lockdown.TruNet.dk/
PR: 62714
Submitted by: Daniel Blankensteiner <db@TruNet.dk> |