Lockdown adaX numbers to allow booting ?

Kurt Jaeger lists at opsec.eu
Thu Sep 19 17:15:36 UTC 2019


> > I've made a few more details available here:

> > https://people.freebsd.org/~pi/host/gpart.txt

> What about gpart output of the pool drives?

No gpart on the bck pool, raw drives.

> In general you would create zpools using gptids or gpt labels, not the devices, so you???re independent of device numbering. The boot loader should only be installed on drives that contain the boot pool (maybe you have old boot loaders on data drives?).

I think not, because they are used as raw drives.

Maybe that decision was an error in hindsight.

-- 
pi at opsec.eu            +49 171 3101372                    One year to go !


More information about the freebsd-current mailing list