Multi-User Security

Norberto Meijome freebsd at meijome.net
Mon May 17 21:41:26 PDT 2004


Richard Coleman wrote:

> Using a chroot or a jail is the way to go if possible.  If you can't use 
> that, then unix permissions or ACL's is the next bet.  Restricting 
> commands is the most fragile solution since in many cases it can be 
> subverted.

Excuse my ignorance, could you quickly tell me the difference (or point 
me to a good reference article/book) between chroot + jail?
is it that a jail is always chrooted but not the other way around?
is a jail more encompassing than chroot only?

thanks in advance,
B




More information about the freebsd-security mailing list