History log of /netbsd-current/etc/inetd.conf
Revision (<<< Hide revision tags) (Show revision tags >>>) Date Author Comments
Revision tags: pgoyette-localcount-20161104
# 1.59 25-Oct-2016 christos

mention that -a valid does not work, requested by felix.


Revision tags: netbsd-7-0-2-RELEASE localcount-20160914 netbsd-7-nhusb-base pgoyette-localcount-20160806 pgoyette-localcount-20160726 pgoyette-localcount-base netbsd-7-0-1-RELEASE netbsd-7-0-RELEASE netbsd-7-0-RC3 netbsd-7-0-RC2 netbsd-7-0-RC1 netbsd-5-2-3-RELEASE netbsd-5-1-5-RELEASE netbsd-6-0-6-RELEASE netbsd-6-1-5-RELEASE netbsd-7-base yamt-pagecache-base9 yamt-pagecache-tag8 netbsd-6-1-4-RELEASE netbsd-6-0-5-RELEASE tls-earlyentropy-base riastradh-xf86-video-intel-2-7-1-pre-2-21-15 riastradh-drm2-base3 netbsd-6-1-3-RELEASE netbsd-6-0-4-RELEASE netbsd-5-2-2-RELEASE netbsd-5-1-4-RELEASE netbsd-6-1-2-RELEASE netbsd-6-0-3-RELEASE netbsd-5-2-1-RELEASE netbsd-5-1-3-RELEASE netbsd-6-1-1-RELEASE riastradh-drm2-base2 riastradh-drm2-base1 riastradh-drm2-base netbsd-6-0-2-RELEASE netbsd-6-1-RELEASE netbsd-6-1-RC4 netbsd-6-1-RC3 agc-symver-base netbsd-6-1-RC2 netbsd-6-1-RC1 yamt-pagecache-base8 netbsd-6-0-1-RELEASE yamt-pagecache-base7 netbsd-5-2-RELEASE netbsd-5-2-RC1 matt-nb6-plus-nbase yamt-pagecache-base6 netbsd-6-0-RELEASE netbsd-6-0-RC2 tls-maxphys-base matt-nb6-plus-base netbsd-6-0-RC1 yamt-pagecache-base5 yamt-pagecache-base4 netbsd-6-base netbsd-5-1-2-RELEASE netbsd-5-1-1-RELEASE yamt-pagecache-base3 yamt-pagecache-base2 yamt-pagecache-base cherry-xenmp-base bouyer-quota2-nbase bouyer-quota2-base matt-mips64-premerge-20101231 matt-nb5-mips64-premerge-20101231 matt-nb5-pq3-base netbsd-5-1-RELEASE netbsd-5-1-RC4 matt-nb5-mips64-k15 netbsd-5-1-RC3 netbsd-5-1-RC2 netbsd-5-1-RC1 netbsd-5-0-2-RELEASE matt-nb5-mips64-premerge-20091211 matt-premerge-20091211 matt-nb5-mips64-u2-k2-k4-k7-k8-k9 matt-nb4-mips64-k7-u2a-k9b matt-nb5-mips64-u1-k1-k5 netbsd-5-0-1-RELEASE jym-xensuspend-nbase netbsd-5-0-RELEASE netbsd-5-0-RC4 netbsd-5-0-RC3 netbsd-5-0-RC2 jym-xensuspend-base netbsd-5-0-RC1 mjf-devfs2-base2 netbsd-5-base matt-mips64-base2 wrstuden-revivesa-base-3 wrstuden-revivesa-base-2 wrstuden-revivesa-base-1 yamt-pf42-base4 yamt-pf42-base3 hpcarm-cleanup-nbase yamt-pf42-baseX yamt-pf42-base2 wrstuden-revivesa-base yamt-pf42-base mjf-devfs2-base keiichi-mipv6-base mjf-devfs-base matt-armv6-nbase cube-autoconf-base matt-armv6-base hpcarm-cleanup-base
# 1.58 15-Oct-2007 tls

branches: 1.58.56;
Add httpd to the build. Add _httpd to passwd and groups and postinstall.
Add /var/www to mtree, add example line to inetd.conf.


Revision tags: netbsd-4-0-1-RELEASE wrstuden-fixsa-newbase wrstuden-fixsa-base-1 netbsd-4-0-RELEASE netbsd-4-0-RC5 netbsd-4-0-RC4 netbsd-4-0-RC3 netbsd-4-0-RC2 netbsd-4-0-RC1 matt-mips64-base wrstuden-fixsa-base netbsd-4-base
# 1.57 11-Nov-2006 christos

branches: 1.57.8;
goodbye uucp


Revision tags: abandoned-netbsd-4-base
# 1.56 18-Sep-2005 elad

Use more sane defaults for commented out fingerd entry.
From OpenBSD and Zafer Aydogan.
PR/31341.


Revision tags: netbsd-3-1-1-RELEASE netbsd-3-0-3-RELEASE netbsd-3-1-RELEASE netbsd-3-0-2-RELEASE netbsd-3-1-RC4 netbsd-3-1-RC3 netbsd-3-1-RC2 netbsd-3-1-RC1 netbsd-3-0-1-RELEASE netbsd-3-0-RELEASE netbsd-3-0-RC6 netbsd-3-0-RC5 netbsd-3-0-RC4 netbsd-3-0-RC3 netbsd-3-0-RC2 netbsd-3-0-RC1 netbsd-3-base
# 1.55 27-Feb-2005 christos

Add -a valid for PAM.


Revision tags: netbsd-2-0-3-RELEASE netbsd-2-1-RELEASE netbsd-2-1-RC6 netbsd-2-1-RC5 netbsd-2-1-RC4 netbsd-2-1-RC3 netbsd-2-1-RC2 netbsd-2-1-RC1 netbsd-2-0-2-RELEASE netbsd-2-0-1-RELEASE netbsd-2-base netbsd-2-0-RELEASE netbsd-2-0-RC5 netbsd-2-0-RC4 netbsd-2-0-RC3 netbsd-2-0-RC2 netbsd-2-0-RC1 netbsd-2-0-base
# 1.54 31-Jan-2004 christos

new lines for identd [ipv6 support and option adjustment]


# 1.53 07-Aug-2003 wiz

Remove nntp line -- it refers to a non-existing daemon.
Closes PR 22388, from Nate Hill.


# 1.52 27-Jun-2003 christos

identd can now run as nobody.


# 1.51 02-May-2003 tron

identd(8) must run as "root" to use TCPCTL_IDENT via sysctl(3). This fixes
PR bin/21261 by myself.


# 1.50 14-Feb-2003 bouyer

Also register rquota version 2.


Revision tags: fvdl_fs64_base
# 1.49 05-Jun-2002 itojun

rexecd is IPv6 capable (not sure who will be using it though)


# 1.48 05-Jun-2002 itojun

committed by mistake


# 1.47 05-Jun-2002 itojun

uid/gid for sendmail 8.12.x.
disallow chroot priv accounts from being used for ftp.


Revision tags: netbsd-1-6-PATCH002-RELEASE netbsd-1-6-PATCH002 netbsd-1-6-PATCH002-RC4 netbsd-1-6-PATCH002-RC3 netbsd-1-6-PATCH002-RC2 netbsd-1-6-PATCH002-RC1 netbsd-1-6-PATCH001 netbsd-1-6-PATCH001-RELEASE netbsd-1-6-PATCH001-RC3 netbsd-1-6-PATCH001-RC2 netbsd-1-6-PATCH001-RC1 netbsd-1-6-RELEASE netbsd-1-6-RC3 netbsd-1-6-RC2 netbsd-1-6-RC1 netbsd-1-6-base
# 1.46 21-Nov-2001 itojun

uucpd supports IPv6


# 1.45 05-May-2001 wiz

Enable logging options for (commented out) uucpd and fingerd by default.
Addresses misc/10219 by Jim Bernard.


# 1.44 05-Apr-2001 thorpej

Cleanup formatting of the rpc services.


# 1.43 05-Apr-2001 thorpej

Add a tcp6 entry for hpropd.


# 1.42 25-Mar-2001 thorpej

kpasswd is a "wait" type service.


# 1.41 07-Mar-2001 itojun

comsat is ipv6 ready


# 1.40 30-Dec-2000 itojun

move tcp6/udp6 entries upwards so that they do not get out of sync with
IPv4 services. add kerberos-adm and internal services (like echo) on tcp/udp6.


# 1.39 13-Sep-2000 fvdl

Now that kpasswdd works from inetd, also correct the entry: kpasswdd is an
udp service, not tcp.


# 1.38 06-Aug-2000 thorpej

Add (commented out) hprop service, along with a short explanation
of when to enable it and why.


# 1.37 04-Aug-2000 thorpej

Remove the (not supported) krbupdate service, and add (commented out)
kerberos-adm.


# 1.36 22-Jun-2000 fvdl

Allow a higher count of started services for broadcast RPC services. Since
rpcbind version 3 and 4 clients will try broadcasts using both the old
and new protocol for IPv4, the double amount of packets may come in,
causing bogus "service looping" events in inetd.


Revision tags: netbsd-1-5-base
# 1.35 05-Jun-2000 sommerfeld

branches: 1.35.2;
Comment out telnet, ftp since they use cleartext passwords (discussed
recently on tech-net, no objection raised except that it doesn't go
far enough..)

Fix misc/10219 as suggested in PR: add -L to rlogind and -l to tftpd
command lines to enable logging.


# 1.34 02-Jun-2000 fvdl

* Portmap is now called rpcbind.
* Add IPv6 RPC entries to inetd.conf (commented out by default, as the others)
* Add netconfig file, needed for TI-RPC code.


Revision tags: minoura-xpg4dl-base
# 1.33 13-May-2000 lukem

branches: 1.33.2;
remove commented-out entry for mountd, since whilst support for inetd
was added to mountd in mountd.c::1.6, it was removed as part of the
4.4-lite merge in mountd.c::1.12. if the entry was uncommented your
machine might clag up after a showmount as inetd spawned lots of
mountd processes...


# 1.32 28-Feb-2000 itojun

enable IPv6 ftp and telnet by default.
it makes more sense to me as we have INET6 in kernel, and we have ftp4/telnet4
enabled by default. maybe I'm biased:-)


# 1.31 09-Feb-2000 itojun

add tcp6 lines for rshd/rlogind.


Revision tags: wrstuden-devbsize-19991221 wrstuden-devbsize-base
# 1.30 19-Dec-1999 itojun

add comment about IPv4/v6 dual stack support (enable both tcp and tcp6).


Revision tags: comdex-fall-1999-base
# 1.29 05-Nov-1999 mycroft

branches: 1.29.2;
Disable everything except ftpd and telnetd by default.


# 1.28 06-Oct-1999 ad

Use a colon to seprate user and group name pairs.


# 1.27 05-Oct-1999 ad

GENERIC kernel does not ship with IPv6, so comment out tcp6/udp6 entries.


# 1.26 12-Jul-1999 itojun

branches: 1.26.2;
IPv6 support.


# 1.25 02-Jul-1999 itojun

add telnet on tcp6.


# 1.24 02-Jul-1999 itojun

provide sample lines for IPv6 services (at this moment ftpd and fingerd)


# 1.23 18-May-1999 jwise

Modify (commented out, pre-existing) identd line to start identd `nowait'
for those who want to use tcpwrappers appropriately.

Resist temptation to add -L"something appropriate"


Revision tags: netbsd-1-4-PATCH002 netbsd-1-4-PATCH001 netbsd-1-4-RELEASE netbsd-1-4-base netbsd-1-3-PATCH003 netbsd-1-3-PATCH003-CANDIDATE2 netbsd-1-3-PATCH003-CANDIDATE1 netbsd-1-3-PATCH003-CANDIDATE0 netbsd-1-3-PATCH002 netbsd-1-3-PATCH001 netbsd-1-3-RELEASE netbsd-1-3-BETA netbsd-1-3-base
# 1.22 06-Oct-1997 mrg

branches: 1.22.4;
make these changes to the default user.group:
- internal services run as `nobody'
- rpc.rusersd and rpc.sprayd run as `nobody'
- rpc.rstatd run as `nobody.kmem'
- rpc.rwalld run as `nobody.tty'


# 1.21 04-Oct-1997 mrg

add hunt(6) entry (commented by default)


# 1.20 29-Jun-1997 christos

Run ntalkd as nobody.tty


# 1.19 03-Apr-1997 kleink

mountd was moved to /usr/sbin ; pointed out by Thorsten Frueauf.


# 1.18 15-Feb-1997 mikel

cleanup Lite-1 merge


# 1.17 19-Jan-1997 mycroft

Turn off echo, discard, and chargen by default.


# 1.16 28-Dec-1996 mrg

turn off internal udp services, and log rshd connections; ideas from openbsd.


Revision tags: netbsd-1-2-PATCH001 netbsd-1-2-RELEASE netbsd-1-2-BETA netbsd-1-2-base
# 1.15 08-May-1996 thorpej

RCS id police.


Revision tags: netbsd-1-1-PATCH001 netbsd-1-1-RELEASE netbsd-1-1-base
# 1.14 13-Sep-1995 thorpej

bootpd can run from the shell, too, and thus lives in /usr/sbin, not
/usr/libexec.


# 1.13 10-Jun-1995 mycroft

Turn off idented by default.


# 1.12 04-Jun-1995 jtc

The tftpd daemon has been changed to use setgid() & setuid() to
explicitly set the user and group IDs to non-priveleged values. This
was done because the chroot() call used when the secure (-s) option is
used can only be done by the superuser.

This change now requires tftpd to be executed by root. So the
inetd.conf entry has been changed to start it that way. I also
added -s /tftpboot arguments, so people who uncomment the tftpd
entry without realizing it's security ramifications won't open
thier whole systems to unauthorized access.


# 1.11 23-Dec-1994 cgd

disable kerberos version of rsh/rlogin, because things don't work properly
if they're enabled and the programs don't support kerberos (by default,
the NetBSD programs don't.)


Revision tags: netbsd-1-0-PATCH06 netbsd-1-0-PATCH05 netbsd-1-0-PATCH04 netbsd-1-0-PATCH03 netbsd-1-0-PATCH02 netbsd-1-0-PATCH1 netbsd-1-0-PATCH0 netbsd-1-0-RELEASE netbsd-1-0-base
# 1.10 24-Jun-1994 deraadt

sprayd & rquotad: disabled by default


# 1.9 17-Apr-1994 glass

move bootpd from othersrc to libexec. add bootptab file


# 1.8 22-Feb-1994 cgd

fix that last inetd.conf


# 1.7 24-Jan-1994 glass

remove reference to old talk protocol. will result in better failure


# 1.6 21-Nov-1993 brezak

listen for rusers/2-3; no more version 1


# 1.5 01-Sep-1993 deraadt

it is clear that mountd started from inetd does not work


# 1.4 24-Aug-1993 brezak

mountd is now started by inetd.


Revision tags: netbsd-0-9-RELEASE netbsd-0-9-BETA netbsd-0-9-ALPHA2 netbsd-0-9-ALPHA netbsd-0-9-base
# 1.3 10-Jun-1993 brezak

Add entries to start rpc services.


Revision tags: netbsd-0-8 netbsd-alpha-1
# 1.2 10-Apr-1993 glass

rexecd was on in the default installation. rexecd is not your a secure friend.
those who want it should have to turn it on explicitly


# 1.1 21-Mar-1993 cgd

branches: 1.1.1;
Initial revision


# 1.58 15-Oct-2007 tls

Add httpd to the build. Add _httpd to passwd and groups and postinstall.
Add /var/www to mtree, add example line to inetd.conf.


# 1.57 11-Nov-2006 christos

branches: 1.57.8;
goodbye uucp


# 1.56 18-Sep-2005 elad

Use more sane defaults for commented out fingerd entry.
From OpenBSD and Zafer Aydogan.
PR/31341.


# 1.55 27-Feb-2005 christos

Add -a valid for PAM.


# 1.54 31-Jan-2004 christos

new lines for identd [ipv6 support and option adjustment]


# 1.53 07-Aug-2003 wiz

Remove nntp line -- it refers to a non-existing daemon.
Closes PR 22388, from Nate Hill.


# 1.52 27-Jun-2003 christos

identd can now run as nobody.


# 1.51 02-May-2003 tron

identd(8) must run as "root" to use TCPCTL_IDENT via sysctl(3). This fixes
PR bin/21261 by myself.


# 1.50 14-Feb-2003 bouyer

Also register rquota version 2.


# 1.49 05-Jun-2002 itojun

rexecd is IPv6 capable (not sure who will be using it though)


# 1.48 05-Jun-2002 itojun

committed by mistake


# 1.47 05-Jun-2002 itojun

uid/gid for sendmail 8.12.x.
disallow chroot priv accounts from being used for ftp.


# 1.46 21-Nov-2001 itojun

uucpd supports IPv6


# 1.45 06-May-2001 wiz

Enable logging options for (commented out) uucpd and fingerd by default.
Addresses misc/10219 by Jim Bernard.


# 1.44 05-Apr-2001 thorpej

Cleanup formatting of the rpc services.


# 1.43 05-Apr-2001 thorpej

Add a tcp6 entry for hpropd.


# 1.42 25-Mar-2001 thorpej

kpasswd is a "wait" type service.


# 1.41 07-Mar-2001 itojun

comsat is ipv6 ready


# 1.40 30-Dec-2000 itojun

move tcp6/udp6 entries upwards so that they do not get out of sync with
IPv4 services. add kerberos-adm and internal services (like echo) on tcp/udp6.


# 1.39 13-Sep-2000 fvdl

Now that kpasswdd works from inetd, also correct the entry: kpasswdd is an
udp service, not tcp.


# 1.38 06-Aug-2000 thorpej

Add (commented out) hprop service, along with a short explanation
of when to enable it and why.


# 1.37 04-Aug-2000 thorpej

Remove the (not supported) krbupdate service, and add (commented out)
kerberos-adm.


# 1.36 22-Jun-2000 fvdl

Allow a higher count of started services for broadcast RPC services. Since
rpcbind version 3 and 4 clients will try broadcasts using both the old
and new protocol for IPv4, the double amount of packets may come in,
causing bogus "service looping" events in inetd.


# 1.35 06-Jun-2000 sommerfeld

branches: 1.35.2;
Comment out telnet, ftp since they use cleartext passwords (discussed
recently on tech-net, no objection raised except that it doesn't go
far enough..)

Fix misc/10219 as suggested in PR: add -L to rlogind and -l to tftpd
command lines to enable logging.


# 1.34 02-Jun-2000 fvdl

* Portmap is now called rpcbind.
* Add IPv6 RPC entries to inetd.conf (commented out by default, as the others)
* Add netconfig file, needed for TI-RPC code.


# 1.33 13-May-2000 lukem

branches: 1.33.2;
remove commented-out entry for mountd, since whilst support for inetd
was added to mountd in mountd.c::1.6, it was removed as part of the
4.4-lite merge in mountd.c::1.12. if the entry was uncommented your
machine might clag up after a showmount as inetd spawned lots of
mountd processes...


# 1.32 27-Feb-2000 itojun

enable IPv6 ftp and telnet by default.
it makes more sense to me as we have INET6 in kernel, and we have ftp4/telnet4
enabled by default. maybe I'm biased:-)


# 1.31 09-Feb-2000 itojun

add tcp6 lines for rshd/rlogind.


# 1.30 20-Dec-1999 itojun

add comment about IPv4/v6 dual stack support (enable both tcp and tcp6).


# 1.29 05-Nov-1999 mycroft

branches: 1.29.2;
Disable everything except ftpd and telnetd by default.


# 1.28 06-Oct-1999 ad

Use a colon to seprate user and group name pairs.


# 1.27 05-Oct-1999 ad

GENERIC kernel does not ship with IPv6, so comment out tcp6/udp6 entries.


# 1.26 12-Jul-1999 itojun

branches: 1.26.2;
IPv6 support.


# 1.25 02-Jul-1999 itojun

add telnet on tcp6.


# 1.24 02-Jul-1999 itojun

provide sample lines for IPv6 services (at this moment ftpd and fingerd)


# 1.23 18-May-1999 jwise

Modify (commented out, pre-existing) identd line to start identd `nowait'
for those who want to use tcpwrappers appropriately.

Resist temptation to add -L"something appropriate"


# 1.22 07-Oct-1997 mrg

branches: 1.22.4;
make these changes to the default user.group:
- internal services run as `nobody'
- rpc.rusersd and rpc.sprayd run as `nobody'
- rpc.rstatd run as `nobody.kmem'
- rpc.rwalld run as `nobody.tty'


# 1.21 04-Oct-1997 mrg

add hunt(6) entry (commented by default)


# 1.20 29-Jun-1997 christos

Run ntalkd as nobody.tty


# 1.19 03-Apr-1997 kleink

mountd was moved to /usr/sbin ; pointed out by Thorsten Frueauf.


# 1.18 15-Feb-1997 mikel

cleanup Lite-1 merge


# 1.17 19-Jan-1997 mycroft

Turn off echo, discard, and chargen by default.


# 1.16 28-Dec-1996 mrg

turn off internal udp services, and log rshd connections; ideas from openbsd.


# 1.15 08-May-1996 thorpej

RCS id police.


# 1.14 13-Sep-1995 thorpej

bootpd can run from the shell, too, and thus lives in /usr/sbin, not
/usr/libexec.


# 1.13 10-Jun-1995 mycroft

Turn off idented by default.


# 1.12 04-Jun-1995 jtc

The tftpd daemon has been changed to use setgid() & setuid() to
explicitly set the user and group IDs to non-priveleged values. This
was done because the chroot() call used when the secure (-s) option is
used can only be done by the superuser.

This change now requires tftpd to be executed by root. So the
inetd.conf entry has been changed to start it that way. I also
added -s /tftpboot arguments, so people who uncomment the tftpd
entry without realizing it's security ramifications won't open
thier whole systems to unauthorized access.


# 1.11 23-Dec-1994 cgd

disable kerberos version of rsh/rlogin, because things don't work properly
if they're enabled and the programs don't support kerberos (by default,
the NetBSD programs don't.)


# 1.10 24-Jun-1994 deraadt

sprayd & rquotad: disabled by default


# 1.9 17-Apr-1994 glass

move bootpd from othersrc to libexec. add bootptab file


# 1.8 22-Feb-1994 cgd

fix that last inetd.conf


# 1.7 24-Jan-1994 glass

remove reference to old talk protocol. will result in better failure


# 1.6 21-Nov-1993 brezak

listen for rusers/2-3; no more version 1


# 1.5 01-Sep-1993 deraadt

it is clear that mountd started from inetd does not work


# 1.4 24-Aug-1993 brezak

mountd is now started by inetd.


# 1.3 10-Jun-1993 brezak

Add entries to start rpc services.


# 1.2 10-Apr-1993 glass

rexecd was on in the default installation. rexecd is not your a secure friend.
those who want it should have to turn it on explicitly


# 1.1 21-Mar-1993 cgd

branches: 1.1.1;
Initial revision


# 1.1.1.2 14-Feb-1997 mikel

import 4.4BSD-Lite


# 1.1.1.1 21-Mar-1993 cgd

initial import of 386bsd-0.1 sources


# 1.22.4.1 01-Jun-2000 he

Pull up revision 1.29 (via patch, requested by fair):
Disable everything except ftpd and telnetd by default.
Fixes PR#9673.


# 1.26.2.1 27-Dec-1999 wrstuden

Pull up to last week's -current.


# 1.29.2.2 05-Nov-1999 mycroft

Disable everything except ftpd and telnetd by default.


# 1.29.2.1 05-Nov-1999 mycroft

file inetd.conf was added on branch comdex-fall-1999 on 1999-11-05 11:16:21 +0000


# 1.33.2.1 23-Jun-2000 minoura

Sync w/ netbsd-1-5-base.


# 1.35.2.5 05-Apr-2001 he

Apply patch (requested by thorpej):
Correct a few INET6 and Kerberos entries.
Mostly syncs with version 1.44.


# 1.35.2.4 19-Sep-2000 fvdl

Revision 1.39: the entry for kpasswdd should be dgram/udp.

(approved by thorpej)


# 1.35.2.3 06-Aug-2000 thorpej

Pull up rev. 1.38:
Add (commented out) hprop service, along with a short explanation
of when to enable it and why.


# 1.35.2.2 06-Aug-2000 thorpej

Pull up rev. 1.37:
Remove the (not supported) krbupdate service, and add (commented out)
kerberos-adm.


# 1.35.2.1 27-Jun-2000 thorpej

Pull up rev. 1.36:
Allow a higher count of started services for broadcast RPC services. Since
rpcbind version 3 and 4 clients will try broadcasts using both the old
and new protocol for IPv4, the double amount of packets may come in,
causing bogus "service looping" events in inetd.


# 1.57.8.1 06-Nov-2007 matt

sync with HEAD