亚洲欧美第一页_禁久久精品乱码_粉嫩av一区二区三区免费野_久草精品视频

? 歡迎來到蟲蟲下載站! | ?? 資源下載 ?? 資源專輯 ?? 關于我們
? 蟲蟲下載站

?? mac-portacl.html

?? FreeBSD操作系統的詳細使用手冊
?? HTML
字號:
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN"    "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml"><head><meta name="generator" content="HTML Tidy, see www.w3.org" /><title>The MAC portacl Module</title><meta name="GENERATOR" content="Modular DocBook HTML Stylesheet Version 1.7" /><link rel="HOME" title="FreeBSD 使用手冊" href="index.html" /><link rel="UP" title="Mandatory Access Control" href="mac.html" /><link rel="PREVIOUS" title="The MAC ifoff Module" href="mac-ifoff.html" /><link rel="NEXT" title="MAC Policies with Labeling Features"href="mac-labelingpolicies.html" /><link rel="STYLESHEET" type="text/css" href="docbook.css" /><meta http-equiv="Content-Type" content="text/html; charset=GB2312" /></head><body class="SECT1" bgcolor="#FFFFFF" text="#000000" link="#0000FF" vlink="#840084"alink="#0000FF"><div class="NAVHEADER"><table summary="Header navigation table" width="100%" border="0" cellpadding="0"cellspacing="0"><tr><th colspan="3" align="center">FreeBSD 使用手冊</th></tr><tr><td width="10%" align="left" valign="bottom"><a href="mac-ifoff.html"accesskey="P">后退</a></td><td width="80%" align="center" valign="bottom">章 15. Mandatory Access Control</td><td width="10%" align="right" valign="bottom"><a href="mac-labelingpolicies.html"accesskey="N">前進</a></td></tr></table><hr align="LEFT" width="100%" /></div><div class="SECT1"><h1 class="SECT1"><a id="MAC-PORTACL" name="MAC-PORTACL">15.8. The MAC portaclModule</a></h1><p>Module name: <tt class="FILENAME">mac_portacl.ko</tt></p><p>Kernel configuration line: <var class="LITERAL">MAC_PORTACL</var></p><p>Boot option: <var class="LITERAL">mac_portacl_load="YES"</var></p><p>The <span class="CITEREFENTRY"><spanclass="REFENTRYTITLE">mac_portacl</span>(4)</span> module is used to limit binding tolocal <acronym class="ACRONYM">TCP</acronym> and <acronym class="ACRONYM">UDP</acronym>ports using a variety of <tt class="COMMAND">sysctl</tt> variables. In essence <spanclass="CITEREFENTRY"><span class="REFENTRYTITLE">mac_portacl</span>(4)</span> makes itpossible to allow non-<tt class="USERNAME">root</tt> users to bind to specifiedprivileged ports, i.e. ports fewer than 1024.</p><p>Once loaded, this module will enable the <acronym class="ACRONYM">MAC</acronym> policyon all sockets. The following tunables are available:</p><ul><li><p><var class="LITERAL">security.mac.portacl.enabled</var> will enable/disable the policycompletely.<a id="AEN22079" name="AEN22079" href="#FTN.AEN22079"><spanclass="footnote">[1]</span></a></p></li><li><p><var class="LITERAL">security.mac.portacl.port_high</var> will set the highest portnumber that <span class="CITEREFENTRY"><spanclass="REFENTRYTITLE">mac_portacl</span>(4)</span> will enable protection for.</p></li><li><p><var class="LITERAL">security.mac.portacl.suser_exempt</var> will, when set to anon-zero value, exempt the <tt class="USERNAME">root</tt> user from this policy.</p></li><li><p><var class="LITERAL">security.mac.portacl.rules</var> will specify the actualmac_portacl policy; see below.</p></li></ul><p>The actual <var class="LITERAL">mac_portacl</var> policy, as specified in the <varclass="LITERAL">security.mac.portacl.rules</var> sysctl, is a text string of the form:<var class="LITERAL">rule[,rule,...]</var> with as many rules as needed. Each rule is ofthe form: <var class="LITERAL">idtype:id:protocol:port</var>. The <varclass="PARAMETER">idtype</var> parameter can be <var class="LITERAL">uid</var> or <varclass="LITERAL">gid</var> and used to interpret the <var class="PARAMETER">id</var>parameter as either a user id or group id, respectively. The <varclass="PARAMETER">protocol</var> parameter is used to determine if the rule should applyto <acronym class="ACRONYM">TCP</acronym> or <acronym class="ACRONYM">UDP</acronym> bysetting the parameter to <var class="LITERAL">tcp</var> or <varclass="LITERAL">udp</var>. The final <var class="PARAMETER">port</var> parameter is theport number to allow the specified user or group to bind to.</p><div class="NOTE"><blockquote class="NOTE"><p><b>注:</b> Since the ruleset is interpreted directly by the kernel only numeric valuescan be used for the user ID, group ID, and port parameters. I.e. user, group, and portservice names cannot be used.</p></blockquote></div><p>By default, on <span class="TRADEMARK">UNIX</span>&reg;-like systems, ports fewer than1024 can only be used by/bound to privileged processes, i.e. those run as <ttclass="USERNAME">root</tt>. For <span class="CITEREFENTRY"><spanclass="REFENTRYTITLE">mac_portacl</span>(4)</span> to allow non-privileged processes tobind to ports below 1024 this standard <span class="TRADEMARK">UNIX</span> restrictionhas to be disabled. This can be accomplished by setting the <spanclass="CITEREFENTRY"><span class="REFENTRYTITLE">sysctl</span>(8)</span> variables <varclass="LITERAL">net.inet.ip.portrange.reservedlow</var> and <varclass="LITERAL">net.inet.ip.portrange.reservedhigh</var> to zero.</p><p>See the examples below or review the <span class="CITEREFENTRY"><spanclass="REFENTRYTITLE">mac_portacl</span>(4)</span> manual page for furtherinformation.</p><div class="SECT2"><h2 class="SECT2"><a id="AEN22129" name="AEN22129">15.8.1. Examples</a></h2><p>The following examples should illuminate the above discussion a little better:</p><pre class="SCREEN"><samp class="PROMPT">#</samp> <kbdclass="USERINPUT">sysctl security.mac.portacl.port_high=1023</kbd><samp class="PROMPT">#</samp> <kbdclass="USERINPUT">sysctl net.inet.ip.portrange.reservedlow=0 net.inet.ip.portrange.reservedhigh=0</kbd></pre><p>First we set <span class="CITEREFENTRY"><spanclass="REFENTRYTITLE">mac_portacl</span>(4)</span> to cover the standard privileged portsand disable the normal <span class="TRADEMARK">UNIX</span> bind restrictions.</p><pre class="SCREEN"><samp class="PROMPT">#</samp> <kbdclass="USERINPUT">sysctl security.mac.portacl.suser_exempt=1</kbd></pre><p>The <tt class="USERNAME">root</tt> user should not be crippled by this policy, thusset the <var class="LITERAL">security.mac.portacl.suser_exempt</var> to a non-zero value.The <span class="CITEREFENTRY"><span class="REFENTRYTITLE">mac_portacl</span>(4)</span>module has now been set up to behave the same way <spanclass="TRADEMARK">UNIX</span>-like systems behave by default.</p><pre class="SCREEN"><samp class="PROMPT">#</samp> <kbdclass="USERINPUT">sysctl security.mac.portacl.rules=uid:80:tcp:80</kbd></pre><p>Allow the user with <acronym class="ACRONYM">UID</acronym> 80 (normally the <ttclass="USERNAME">www</tt> user) to bind to port 80. This can be used to allow the <ttclass="USERNAME">www</tt> user to run a web server without ever having <ttclass="USERNAME">root</tt> privilege.</p><pre class="SCREEN"><samp class="PROMPT">#</samp> <kbdclass="USERINPUT">sysctl security.mac.portacl.rules=uid:1001:tcp:110,uid:1001:tcp:995</kbd></pre><p>Permit the user with the <acronym class="ACRONYM">UID</acronym> of 1001 to bind to the<acronym class="ACRONYM">TCP</acronym> ports 110 (``pop3'') and 995 (``pop3s''). Thiswill permit this user to start a server that accepts connections on ports 110 and995.</p></div></div><h3 class="FOOTNOTES">注</h3><table border="0" class="FOOTNOTES" width="100%"><tr><td align="LEFT" valign="TOP" width="5%"><a id="FTN.AEN22079" name="FTN.AEN22079"href="mac-portacl.html#AEN22079"><span class="footnote">[1]</span></a></td><td align="LEFT" valign="TOP" width="95%"><p>Due to a bug the <var class="LITERAL">security.mac.portacl.enabled</var> <ttclass="COMMAND">sysctl</tt> variable will not work on FreeBSD&nbsp;5.2.1 or previousreleases.</p></td></tr></table><div class="NAVFOOTER"><hr align="LEFT" width="100%" /><table summary="Footer navigation table" width="100%" border="0" cellpadding="0"cellspacing="0"><tr><td width="33%" align="left" valign="top"><a href="mac-ifoff.html"accesskey="P">后退</a></td><td width="34%" align="center" valign="top"><a href="index.html"accesskey="H">起點</a></td><td width="33%" align="right" valign="top"><a href="mac-labelingpolicies.html"accesskey="N">前進</a></td></tr><tr><td width="33%" align="left" valign="top">The MAC ifoff Module</td><td width="34%" align="center" valign="top"><a href="mac.html"accesskey="U">上一級</a></td><td width="33%" align="right" valign="top">MAC Policies with Labeling Features</td></tr></table></div></body></html>

?? 快捷鍵說明

復制代碼 Ctrl + C
搜索代碼 Ctrl + F
全屏模式 F11
切換主題 Ctrl + Shift + D
顯示快捷鍵 ?
增大字號 Ctrl + =
減小字號 Ctrl + -
亚洲欧美第一页_禁久久精品乱码_粉嫩av一区二区三区免费野_久草精品视频
成人国产精品免费观看视频| 99视频国产精品| 国产精品一区二区男女羞羞无遮挡| 成人国产精品免费观看| 日韩亚洲欧美成人一区| 国产精品国模大尺度视频| 麻豆精品国产传媒mv男同| 一本到三区不卡视频| 久久一留热品黄| 亚洲成a人在线观看| 成人午夜精品在线| 国产视频不卡一区| 免费观看91视频大全| 欧洲精品在线观看| 国产精品麻豆网站| 国产麻豆精品在线观看| 在线电影一区二区三区| 亚洲乱码中文字幕综合| av在线播放不卡| 久久久亚洲精品石原莉奈| 美腿丝袜亚洲色图| 欧美亚洲免费在线一区| 亚洲色图自拍偷拍美腿丝袜制服诱惑麻豆| 久久精品99久久久| 日韩一区二区免费电影| 人人精品人人爱| 在线成人小视频| 午夜精品久久一牛影视| 99久久综合99久久综合网站| 欧美色爱综合网| 国产日韩精品视频一区| 国产精品成人午夜| 秋霞电影网一区二区| 国产精品一区一区三区| 在线视频欧美精品| 精品国产自在久精品国产| 亚洲少妇30p| 秋霞午夜av一区二区三区| www.亚洲免费av| 日韩一区二区电影| 国产精品福利一区二区| 奇米一区二区三区av| 99久久er热在这里只有精品66| 欧美日韩视频在线第一区 | 国产麻豆精品一区二区| 色婷婷av久久久久久久| 日韩美女视频一区二区在线观看| 中文字幕永久在线不卡| 久久精品久久99精品久久| 麻豆成人av在线| 91精品视频网| 国产精品小仙女| 中文字幕一区二区三中文字幕| 成人v精品蜜桃久久一区| 亚洲日本va午夜在线影院| 日本乱码高清不卡字幕| 日韩黄色小视频| 久久久噜噜噜久噜久久综合| 99久久精品免费看| 天天综合天天做天天综合| 日韩一卡二卡三卡四卡| 国产69精品久久99不卡| 一区二区三区高清| 91精品免费在线| 成人午夜又粗又硬又大| 亚洲国产成人91porn| 久久影视一区二区| 欧洲一区二区三区在线| 韩国一区二区三区| 亚洲黄色免费网站| 久久久久久久综合日本| 欧亚洲嫩模精品一区三区| 激情综合色播激情啊| 亚洲女爱视频在线| 久久亚洲一级片| 欧美影院一区二区| 国产成人亚洲精品青草天美| 亚洲综合视频在线| 国产网站一区二区| 6080日韩午夜伦伦午夜伦| 成人一区二区在线观看| 美女免费视频一区二区| 亚洲伊人色欲综合网| 久久一区二区视频| 这里只有精品99re| 色婷婷av一区| 成人av动漫在线| 极品销魂美女一区二区三区| 亚洲国产日韩精品| 亚洲婷婷综合久久一本伊一区| 精品少妇一区二区| 欧美日本在线播放| 一本色道a无线码一区v| 国产91精品久久久久久久网曝门| 日韩精品视频网站| 亚洲自拍偷拍图区| 亚洲欧美一区二区久久| 国产精品久久久爽爽爽麻豆色哟哟| 日韩欧美国产一区二区三区| 欧美艳星brazzers| 一本色道久久综合亚洲91 | 久久久久9999亚洲精品| 7777精品伊人久久久大香线蕉的| 91丝袜美腿高跟国产极品老师 | 久久这里只有精品视频网| 欧美老人xxxx18| 欧美伊人久久久久久午夜久久久久| 成人一区二区三区视频| 国产精品中文欧美| 国产在线一区观看| 精品一区二区三区在线观看| 日韩av成人高清| 日韩精品久久理论片| 午夜欧美在线一二页| 亚洲第一成人在线| 国产在线不卡视频| 麻豆精品视频在线观看| 日本特黄久久久高潮| 日韩电影在线一区| 免费观看成人av| 精品一二三四区| 国产精品自拍av| 成人激情图片网| 色婷婷国产精品久久包臀 | 中文字幕佐山爱一区二区免费| 国产偷国产偷精品高清尤物| 国产亚洲一区二区在线观看| 国产精品午夜在线| 国产精品成人一区二区三区夜夜夜| 亚洲欧洲日韩在线| 亚洲午夜三级在线| 美腿丝袜亚洲综合| 国产黄色成人av| 91蝌蚪国产九色| 欧美日韩一区三区| 日韩三级视频在线观看| 久久久久免费观看| 亚洲欧美另类小说| 日韩专区中文字幕一区二区| 激情久久五月天| 豆国产96在线|亚洲| 91九色最新地址| 欧美一级夜夜爽| 中文字幕久久午夜不卡| 亚洲第一搞黄网站| 国产乱子伦一区二区三区国色天香| www.日韩精品| 欧美丰满美乳xxx高潮www| 国产欧美日韩精品在线| 亚洲一区二区三区影院| 国产最新精品精品你懂的| 99国产欧美久久久精品| 3751色影院一区二区三区| 国产午夜精品一区二区| 亚洲国产精品久久人人爱| 国产一区视频在线看| 欧美亚洲综合色| 欧美激情一区二区三区在线| 天天做天天摸天天爽国产一区| 国产精品资源在线看| 欧美日韩国产一区二区三区地区| 国产视频不卡一区| 亚洲成av人片在线| 波多野结衣一区二区三区| 日韩三级电影网址| 亚洲在线免费播放| 丁香天五香天堂综合| 日韩一区二区在线看| 一区二区成人在线视频| 懂色一区二区三区免费观看 | www.激情成人| 欧美变态tickle挠乳网站| 一区二区三区日韩欧美精品| 国产美女精品在线| 7777精品伊人久久久大香线蕉的| 国产精品美女一区二区三区 | 欧美理论在线播放| 亚洲四区在线观看| 国产成人精品免费网站| 日本一区二区视频在线观看| 另类小说一区二区三区| 色婷婷av一区二区三区之一色屋| 国产女主播一区| 精品亚洲国内自在自线福利| 欧美剧在线免费观看网站 | 国产婷婷色一区二区三区在线| 午夜精品视频一区| 91久久人澡人人添人人爽欧美| 中文成人av在线| 国产精品原创巨作av| 精品国精品国产| 另类人妖一区二区av| 9191精品国产综合久久久久久| 一区二区三区蜜桃| 色婷婷av一区二区三区gif| 亚洲女人小视频在线观看| 99久久精品免费精品国产| 亚洲欧美在线观看| 91丨porny丨在线| 成人欧美一区二区三区小说|