On 11-Feb-2009, at 2:36 AM, W.C.A. Wijngaards wrote: > > In 1.2.1 I added initgroups(3), so that it drops secondary group > permissions. Thanks for that! It might be even better to use setusercontext(3) instead on those platforms which have such a function (all the BSDs at least). That way login.conf(5) could be used properly to set things like user resource limits for the process. -- Greg A. Woods <woods at planix.com> -------------- next part -------------- A non-text attachment was scrubbed... Name: PGP.sig Type: application/pgp-signature Size: 186 bytes Desc: This is a digitally signed message part URL: <http://unbound.nlnetlabs.nl/pipermail/unbound-users/attachments/20090211/e85e8d15/attachment.pgp>