diff -rU1 -I[$]OpenBSD ./etc/inetd.conf ../52/etc/inetd.conf --- ./etc/inetd.conf Thu Feb 9 15:14:21 2012 +++ ../52/etc/inetd.conf Wed Aug 1 11:45:29 2012 @@ -16,4 +16,2 @@ ident stream tcp6 nowait _identd /usr/libexec/identd identd -el -#tftp dgram udp wait root /usr/libexec/tftpd tftpd -s /tftpboot -#tftp dgram udp6 wait root /usr/libexec/tftpd tftpd -s /tftpboot 127.0.0.1:comsat dgram udp wait root /usr/libexec/comsat comsat diff -rU1 -I[$]OpenBSD ./etc/login.conf ../52/etc/login.conf --- ./etc/login.conf Thu Feb 9 15:14:21 2012 +++ ../52/etc/login.conf Wed Aug 1 11:45:29 2012 @@ -49,3 +49,3 @@ :maxproc-cur=128:\ - :openfiles-cur=128:\ + :openfiles-cur=512:\ :stacksize-cur=4M:\ diff -rU1 -I[$]OpenBSD ./etc/mail/smtpd.conf ../52/etc/mail/smtpd.conf --- ./etc/mail/smtpd.conf Thu Feb 9 15:14:28 2012 +++ ../52/etc/mail/smtpd.conf Wed Aug 1 11:45:36 2012 @@ -7,3 +7,3 @@ -map "aliases" { source db "/etc/mail/aliases.db" } +map aliases source db "/etc/mail/aliases.db" diff -rU1 -I[$]OpenBSD ./etc/mail/spamd.conf ../52/etc/mail/spamd.conf --- ./etc/mail/spamd.conf Thu Feb 9 15:14:28 2012 +++ ../52/etc/mail/spamd.conf Wed Aug 1 11:45:36 2012 @@ -19,3 +19,3 @@ all:\ - :uatraps:nixspam:china:korea: + :uatraps:nixspam: @@ -38,18 +38,2 @@ :file=www.openbsd.org/spamd/nixspam.gz - -# Mirrored from http://www.okean.com/chinacidr.txt -china:\ - :black:\ - :msg="SPAM. Your address %A appears to be from China\n\ - See http://www.okean.com/asianspamblocks.html for more details":\ - :method=http:\ - :file=www.openbsd.org/spamd/chinacidr.txt.gz: - -# Mirrored from http://www.okean.com/koreacidr.txt -korea:\ - :black:\ - :msg="SPAM. Your address %A appears to be from Korea\n\ - See http://www.okean.com/asianspamblocks.html for more details":\ - :method=http:\ - :file=www.openbsd.org/spamd/koreacidr.txt.gz: diff -rU1 -I[$]OpenBSD ./etc/services ../52/etc/services --- ./etc/services Thu Feb 9 15:14:21 2012 +++ ../52/etc/services Wed Aug 1 11:45:29 2012 @@ -290,2 +290,6 @@ dhcpd-sync 8067/udp # dhcpd(8) synchronisation +amt-soap-http 16992/tcp # Intel AMT SOAP/HTTP +amt-soap-https 16993/tcp # Intel AMT SOAP/HTTPS +amt-redir-tcp 16994/tcp # Intel AMT Redirection/TCP +amt-redir-tls 16995/tcp # Intel AMT Redirection/TLS hunt 26740/udp # hunt(6) diff -rU1 -I[$]OpenBSD ./etc/ssh/sshd_config ../52/etc/ssh/sshd_config --- ./etc/ssh/sshd_config Thu Feb 9 15:14:23 2012 +++ ../52/etc/ssh/sshd_config Wed Aug 1 11:45:31 2012 @@ -49,2 +49,4 @@ +#AuthorizedPrincipalsFile none + # For this to work you will also need host keys in /etc/ssh/ssh_known_hosts @@ -86,3 +88,3 @@ #UseLogin no -#UsePrivilegeSeparation yes +UsePrivilegeSeparation sandbox # Default for new installations. #PermitUserEnvironment no @@ -96,2 +98,3 @@ #ChrootDirectory none +#VersionAddendum none diff -rU1 -I[$]OpenBSD ./etc/sysctl.conf ../52/etc/sysctl.conf --- ./etc/sysctl.conf Thu Feb 9 15:14:21 2012 +++ ../52/etc/sysctl.conf Wed Aug 1 11:45:29 2012 @@ -15,2 +15,4 @@ #net.inet6.ip6.accept_rtadv=1 # 1=Permit IPv6 autoconf (forwarding must be 0) +#net.inet.tcp.always_keepalive=1 # 1=Keepalives for all connections (e.g. hotel/airport NAT) +#net.inet.tcp.keepidle=100 # 100=send TCP keepalives every 50 seconds #net.inet.tcp.rfc1323=0 # 0=Disable TCP RFC1323 extensions (for if tcp is slow)